- Package:
- src:libdbi-perl
- Source:
- src:libdbi-perl
- Submitter:
- Salvatore Bonaccorso
- Date:
- 2026-07-15 15:53:02 UTC
- Severity:
- normal
- Tags:
Hi, The following vulnerabilities were published for libdbi-perl. CVE-2026-15043[0]: | DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have | inverted <= and >= SQL operators on text. DBI::SQL::Nano, DBI's | built-in mini-SQL engine, evaluated WHERE predicates incorrectly in | some cases. In the non-numeric string branch of the is_matched | method, <= was evaluated using Perl's ge operator, and >= was | evaluated using Perl's le operator. SQL::Nano is the fallback query | engine for DBI's file-backed drivers (DBD::File, DBD::DBM, CSV-style | drivers) whenever SQL::Statement is not installed, and is forced | whenever DBI_SQL_NANO=1. Queries over such tables use these | predicates directly. The impact depends on the context. Where an | application relies on a WHERE clause to filter file-backed data for | policy or authorization, an inverted <=/>= comparison silently | returns the wrong rows. CVE-2026-15392[1]: | DBD::File versions before 1.651 for Perl do not ensure the table | file is not a symlink to an untrusted location. The | complete_table_name method builds the absolute table file path | without checking whether the file is a symbolic link. A link inside | the data directory can point to a table file at any path outside of | the configured f_dir and f_dir_search directories. Callers of file- | based drivers can read or write files outside of the data directory. CVE-2026-60081[2]: | DBI::ProfileData versions before 1.651 for Perl do not limit the | path index. The path index column of profile dump files is used to | allocate an array of data for the parser. An unbounded value allows | an attacker to specify a large index and consume available memory. CVE-2026-60082[3]: | DBI versions before 1.651 for Perl do not enforce statement handle | consistency with the row. When the statement handle had no fields | but the source row was non-empty, the internal row-buffer helper | would read from a negative array index. This could be triggered by | a caller supplying inconsistent metadata and rows to the prepare | method. If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-15043 https://www.cve.org/CVERecord?id=CVE-2026-15043 [1] https://security-tracker.debian.org/tracker/CVE-2026-15392 https://www.cve.org/CVERecord?id=CVE-2026-15392 [2] https://security-tracker.debian.org/tracker/CVE-2026-60081 https://www.cve.org/CVERecord?id=CVE-2026-60081 [3] https://security-tracker.debian.org/tracker/CVE-2026-60082 https://www.cve.org/CVERecord?id=CVE-2026-60082 Regards, Salvatore
We believe that the bug you reported is fixed in the latest version of
libdbi-perl, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1142072@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
gregor herrmann <gregoa@debian.org> (supplier of updated libdbi-perl package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Wed, 15 Jul 2026 17:29:24 +0200
Source: libdbi-perl
Architecture: source
Version: 1.651-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Perl Group <pkg-perl-maintainers@lists.alioth.debian.org>
Changed-By: gregor herrmann <gregoa@debian.org>
Closes: 1142072
Changes:
libdbi-perl (1.651-1) unstable; urgency=medium
.
* Import upstream version 1.651.
- Fix inverted comparisons for strings in DBI::SQL::Nano
(CVE-2026-15043)
- Fix DBD::File to ensure that the table is not a symlink outside of f_dir
(CVE-2026-15392)
- Fix an out-of-bounds error when a statement handle has no fields but the
source row is not empty (CVE-2026-60082)
- Add an overridable upper bound $MAX_PATH_DEPTH for DBI::ProfileData
(CVE-2026-60081)
Closes: #1142072
Checksums-Sha1:
082eab018eb5b906157e12cc306b9f7630bd4b43 2433 libdbi-perl_1.651-1.dsc
81bd07f114e84df26efa9276bb85b4c9c04a91d7 735244 libdbi-perl_1.651.orig.tar.gz
cd29db03e9abc9ebddedffd1660c1ee6dd0c72be 13512 libdbi-perl_1.651-1.debian.tar.xz
Checksums-Sha256:
01766a557bee4ae15e5bfe7db154f4f20bcae558ab088b3f618d8f5e3e4000b0 2433 libdbi-perl_1.651-1.dsc
da621a23fa68e1e04fac824cfd3d41e8ffbab2ab3eba642a12499242e8be5253 735244 libdbi-perl_1.651.orig.tar.gz
a3d411a381d8ceb5ce2faa7cd5df6cf373bedc5c8f9742bc39e257c59cb0cad7 13512 libdbi-perl_1.651-1.debian.tar.xz
Files:
1b6e0e39a0eb9f30afc5cff3d93fa04b 2433 perl optional libdbi-perl_1.651-1.dsc
916a567021c09bcaf7d808156d1991f4 735244 perl optional libdbi-perl_1.651.orig.tar.gz
932021080df39fe453947af51971e683 13512 perl optional libdbi-perl_1.651-1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----
iQKTBAEBCgB9FiEE0eExbpOnYKgQTYX6uzpoAYZJqgYFAmpXqDpfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEQx
RTEzMTZFOTNBNzYwQTgxMDREODVGQUJCM0E2ODAxODY0OUFBMDYACgkQuzpoAYZJ
qgZMSg//YbZUORx6KTME01HogBWEYQ8u/Gp4PDGXmtVMMjn6hsKh1GfJW+/wpvZp
jVUozQuodBpmksZh8vGtLcSWmxNUQQLXtb+zJ0Netl28HdZSk9icbO0GqXQaiotv
JZ15SOqbkE7GEJeJho3DLJVNHFX3TGESPRtP5+9AOjyL4PmPvqMdI9clgZvPps9E
p0wfRou3DzeVzRhn17QXnOYz2tOK9SehHcgKR1gD+P/KzRT+pHdFrnn2ao2t8Uii
PLQH27eM38Fx2e48DHfr0gpelyszrwI+fp3qVT3TaT0GO9BTMksASGB6Zdj7sVYB
JrIsfP8GDBaVbLtHC2IxluhwE3JOR/xOYPaGpACBvusTnM6eFI4po1QRoZa1pM8h
ROeRGDTWQIRwg7HWKJ2JTS4nVctcAWZzPY3sBe8FYWTVMGaFLiUffJiZ/D8TtRfb
pz0NhGd1nCBXdiZsL4vyWfpY6Btjh2o4ywSICrNjA/NAU7VwhlcNEYGgo84JaUcW
IkMVCr5E6U65ZMcolhwmj2NN0CNtyjMeSe5MZPvfPB+u65AhFabxA1jQI16e44QJ
QPE/hn6QTSQRsq/X9AZBlMskBOPefFqYrA236aDm/cFt5L992jsyoVlYmIdjAePZ
Ws1tTRLrpC1zFleRCCU8/vyoAVSJEgmu6MGfk+HKgROMfoAMivQ=
=/JS5
-----END PGP SIGNATURE-----