Back

CRITICAL

DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment

Published Jul 7, 2026

Description

DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment.

The preparse method normalises SQL and removes comments. When the SQL starts with a comment line, the deletion of that line during normalisation led to an out-of-bounds read by one byte. The result is a fault on memory-hardened builds and nondeterministic newline retention on normal builds.

Affected products

Remediation

Vendor solution

Upgrade to DBI version 1.650 or later.

References (9)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner CPANSec
Published Jul 7, 2026
Updated Jul 8, 2026
Reserved Jul 4, 2026

CISA Vulnrichment

Updated Jul 8, 2026

NVD

Status Analyzed
Modified Jul 10, 2026

Red Hat

Severity Moderate
Public date Jul 7, 2026
Bugzilla 2497905

ENISA EUVD

Assigner CPANSec
Published Jul 7, 2026
Updated Jul 8, 2026

GitHub

No data