- Package:
- src:libdbi-perl
- Source:
- src:libdbi-perl
- Submitter:
- Salvatore Bonaccorso
- Date:
- 2026-08-31 13:49:08 UTC
- Severity:
- normal
- Tags:
Hi, The following vulnerability was published for libdbi-perl. CVE-2026-73193[0]: | DBI versions before 1.652 for Perl allow a heap out-of-bounds write | on 32-bit perl via an integer wraparound in the output buffer size | computed by preparse. preparse reserves its output buffer with | `newSV(strlen(statement) * 7 + 16)`, budgeting seven output bytes | per input byte for the longest ':p99999' expansion. The product is | computed in STRLEN, which is 32 bits wide on a 32-bit perl build, so | a statement of 613,566,757 bytes multiplies to 4,294,967,299, wraps | modulo 2^32 to 3, and reserves 19 bytes. The parser then copies the | statement out through a raw pointer with no capacity check, writing | the whole 585 MB input past the end of the allocation. The 99,999 | placeholder limit does not bound this path, which is reached by | ordinary non-placeholder content. Any caller that passes an | untrusted statement of that length to preparse on a 32-bit perl gets | a heap out-of-bounds write of attacker controlled bytes. Builds with | a 64-bit STRLEN are not affected, since the wrap there needs a | statement of about 2.3 exabytes. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-73193 https://www.cve.org/CVERecord?id=CVE-2026-73193 [1] https://lists.security.metacpan.org/cve-announce/msg/42707360/ Please adjust the affected versions in the BTS as needed. Regards, Salvatore
We believe that the bug you reported is fixed in the latest version of
libdbi-perl, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1144470@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
gregor herrmann <gregoa@debian.org> (supplier of updated libdbi-perl package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sat, 15 Aug 2026 17:13:20 +0200
Source: libdbi-perl
Architecture: source
Version: 1.652-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Perl Group <pkg-perl-maintainers@lists.alioth.debian.org>
Changed-By: gregor herrmann <gregoa@debian.org>
Closes: 1144470 1144471
Changes:
libdbi-perl (1.652-1) unstable; urgency=medium
.
* Import upstream version 1.652.
+ Limit statements to 292 Mb in preparse (CVE-2026-73193)
(Closes: #1144470)
+ Force placeholder limit on :# and :p# too (CVE-2026-73194)
(Closes: #1144471)
* Install new SECURITY.md file.
* Refresh t__40profile.t__NTP.patch (offset).
Checksums-Sha1:
afe645f1ed2bd90bee84753dab018c1114bbec90 2458 libdbi-perl_1.652-1.dsc
5fc073e859390f07b06ddd0a26020ef52d02e78e 734177 libdbi-perl_1.652.orig.tar.gz
ab4329abcf3475c7051e89d9513f9c843a9be2e3 13600 libdbi-perl_1.652-1.debian.tar.xz
19296839b4b89f8029ed28ca43667832b55455fd 1370372 libdbi-perl_1.652-1.git.tar.xz
0a9450f83cc3fb6c050ffaa991190b2c00d78c18 17568 libdbi-perl_1.652-1_source.buildinfo
Checksums-Sha256:
294b298b89839fa1602b270ca3ee2f0e22201b2759cde1096d99982f4feb3ea3 2458 libdbi-perl_1.652-1.dsc
e7981833696d15414bb76c43817d48f9fc3879e1421433116374fbc63e8e78ad 734177 libdbi-perl_1.652.orig.tar.gz
5297bd51fe4c61444f3ef5218ac24498e89b9be7f759d933282fb404f4835319 13600 libdbi-perl_1.652-1.debian.tar.xz
916aaffd282bd4b7bc77afbcee89bec9424bed4fe905084af7f5d171f1ade1e6 1370372 libdbi-perl_1.652-1.git.tar.xz
4753c62af9c98800fe309003326a0c690cdf58812c97046713dd049feb04b169 17568 libdbi-perl_1.652-1_source.buildinfo
Files:
b7e9b0cc06ca6c002adf34437b1f56e2 2458 perl optional libdbi-perl_1.652-1.dsc
0d511887cb8b8d2a86c5ef78395b0438 734177 perl optional libdbi-perl_1.652.orig.tar.gz
664c8d75ce2d77abbb5187f9690a08f7 13600 perl optional libdbi-perl_1.652-1.debian.tar.xz
bcfdd2094afa2fe67dc5720e50561da2 1370372 perl None libdbi-perl_1.652-1.git.tar.xz
0d7ddcee6267bfaf2a305e67272c973b 17568 perl optional libdbi-perl_1.652-1_source.buildinfo
Git-Tag-Info: tag=f7c427d0b058284f51bf3866709ca4c443188e0c fp=d1e1316e93a760a8104d85fabb3a68018649aa06
Git-Tag-Tagger: gregor herrmann <gregoa@debian.org>
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEN02M5NuW6cvUwJcqYG0ITkaDwHkFAmqAg1kACgkQYG0ITkaD
wHnvAhAAw+bJ3hCPeNF2TpMVyEpEDWkCdrdsFTAbbFoRDk2OtJwIm/ImtoVio9h1
i1ZoESMQlkVx6O82QO612yY+TWh4n8Lw87ZajvknnkBzJiaA3wInfVtTcODMDHMI
gmfLXb6B+/NuRPoZ6OsXriju/Kb409IytnZFHXQxGc9t15JDenolE6vcIIDhBHIH
SZ26TlrCY1PHeIPv0P0EM3qjCWed8r32jGJoFSRt5nOjwXhb7Wt9kkQRWvGHKZDJ
ecA5vAYW2OQJGRCOANZ2z2GYf1kOn+NwamPAlIKtD57qAqT7G29ZFYxWwgQAUkQX
H+42krL6XEMJuCc3aDh2854GEHUq4s3GasLTfBjvYtXPJPGDN9W+2EdRMGbdgLUg
d5E+1MwOun4a33kUKOdnnDYyketKK9+6nxze2UaNjFMGZ8FQMDF+kPwKqETMhh/m
M/Gyc/2wngefKwZ/NtDH/Q+hFD1WJJ/M+bCVkP522R1l4wrWwus514STr/U3eQEt
Cw7RffLqOu5rhKj29l13lAKMGkbeP75ncNSPWQvVLOtGK03MPB49Ldfh44UpLB+J
IMB1L6CLc9oK9X8EoDipFFt3LcxYZTiLRKbnFIrjyug3wY5jpCUqCghFr2vPFEox
WksKAGRb3ML0vzCHw19MlbXs5XbdVbjO9XYO3ya2CAWwcVPnQ6E=
=iq2b
-----END PGP SIGNATURE-----
We believe that the bug you reported is fixed in the latest version of
libdbi-perl, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1144470@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Salvatore Bonaccorso <carnil@debian.org> (supplier of updated libdbi-perl package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sat, 22 Aug 2026 22:43:46 +0200
Source: libdbi-perl
Architecture: source
Version: 1.652-2~deb13u1
Distribution: trixie-security
Urgency: high
Maintainer: Debian Perl Group <pkg-perl-maintainers@lists.alioth.debian.org>
Changed-By: Salvatore Bonaccorso <carnil@debian.org>
Closes: 1141667 1142072 1144470 1144471 1144851
Changes:
libdbi-perl (1.652-2~deb13u1) trixie-security; urgency=high
.
* Team upload.
* Rebuild for trixie-security
* Revert "Remove «Priority: optional», which is the current default."
* Revert "Remove «Rules-Requires-Root: no», which is the current default."
* Revert "Declare compliance with Debian Policy 4.7.4."
* Revert "Reformat debian/control."
.
libdbi-perl (1.652-2) unstable; urgency=medium
.
* Add patch from upstream Git to fix 32bit test failure.
Thanks to Adrian Bunk for the bug report. (Closes: #1144851)
.
libdbi-perl (1.652-1) unstable; urgency=medium
.
* Import upstream version 1.652.
+ Limit statements to 292 Mb in preparse (CVE-2026-73193)
(Closes: #1144470)
+ Force placeholder limit on :# and :p# too (CVE-2026-73194)
(Closes: #1144471)
* Install new SECURITY.md file.
* Refresh t__40profile.t__NTP.patch (offset).
.
libdbi-perl (1.651-1) unstable; urgency=medium
.
* Import upstream version 1.651.
- Fix inverted comparisons for strings in DBI::SQL::Nano
(CVE-2026-15043)
- Fix DBD::File to ensure that the table is not a symlink outside of f_dir
(CVE-2026-15392)
- Fix an out-of-bounds error when a statement handle has no fields but the
source row is not empty (CVE-2026-60082)
- Add an overridable upper bound $MAX_PATH_DEPTH for DBI::ProfileData
(CVE-2026-60081)
Closes: #1142072
.
libdbi-perl (1.650-1) unstable; urgency=medium
.
* Import upstream version 1.650.
- Set a hard limit of 99999 on '?' placeholders
(CVE-2026-14739)
- Fix out-of-bounds read in preparse of SQL that starts with a comment
(CVE-2026-14740)
- Fix code injection via Profile DSN attribute or DBI_PROFILE variable
(CVE-2026-14380)
Closes: #1141667
* Install new upstream document.
.
libdbi-perl (1.649-1) unstable; urgency=medium
.
* Import upstream version 1.649.
.
libdbi-perl (1.648-1) unstable; urgency=medium
.
* Import upstream version 1.648.
Fixes CVE-2026-9698 and CVE-2026-10879.
* Update years of upstream and packaging copyright.
* Declare compliance with Debian Policy 4.7.4.
* Remove «Rules-Requires-Root: no», which is the current default.
* Remove «Priority: optional», which is the current default.
Checksums-Sha1:
e84a20877081f9a4158d67ef2b30ee72751105e0 2373 libdbi-perl_1.652-2~deb13u1.dsc
5fc073e859390f07b06ddd0a26020ef52d02e78e 734177 libdbi-perl_1.652.orig.tar.gz
45c0c4a18716c4de2562d7f643e7a3c69e2f3333 15296 libdbi-perl_1.652-2~deb13u1.debian.tar.xz
Checksums-Sha256:
9820de2e2b5767d80492b7dba575ed8df10edfa71bce3a04b35fdf41a20822ce 2373 libdbi-perl_1.652-2~deb13u1.dsc
e7981833696d15414bb76c43817d48f9fc3879e1421433116374fbc63e8e78ad 734177 libdbi-perl_1.652.orig.tar.gz
3f344c1491c4435e60ec6bc678655c52f34ccc41f3d6813d076b9d128a92f4f6 15296 libdbi-perl_1.652-2~deb13u1.debian.tar.xz
Files:
1b5efbf7f19090e721285a56c15446df 2373 perl optional libdbi-perl_1.652-2~deb13u1.dsc
0d511887cb8b8d2a86c5ef78395b0438 734177 perl optional libdbi-perl_1.652.orig.tar.gz
2076444e9f06e4253a2ac5319207092a 15296 perl optional libdbi-perl_1.652-2~deb13u1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----
iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmqK4yhfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk
ZWJpYW4ub3JnAAoJEAVMuPMTQ89ExQsP/3v9e8Ao38M6fr2xECDCeZ31cQVkBPk+
v/aYS3fAdS04QBVDiEWkYSh96+pfEUm2Dq6Ha28DnoAxnyNBo182pYZXA6ToilD/
iFMCY7oZSR+1AekbCstbzHMtkvI42BEAzOeO7NEUsNSjoYdIBfiO/crCObxlemAK
xEKp2yIxBgPrlLwxzajBv+EE4rgD8z+ZWQAWnI+fG86B9jbocAP6Wp/oaH65+cj+
hYgZOadv9HhZdOu8rbAujI2kEJn/w35AUcGd5JH4b2dUv61hJab6AZ8QMDme4qlv
DlShVfgRw89SqTeLiEDOkUKPQHxWVVxUI98m9eH1YCRB1NxTSxB1DP1re+fl6Nlm
4/NKP02V9tpzgUeTTRWtTaPm4Kv8SSMfs61oE4Azj3TjIGdr6cfvYWBwyqJKk2+U
rhtEM2fi2EUKhobMyfI24G3VFp3nzWCAojWxQZbi6JuFSY5a2fOpEzO5UhEcfevK
aDPUwIsbRvfYr83EGyceppvQCTIle7HT298jh1eCDjnszC7Pbw1oa0k6dVgaE+4U
kifJDuj8bYu3dM/+qVMlnfDaVokQjeOQ+FSeUE32B6GCs58dstoqHGjawWPVTUn8
DtRZgCuXS9oyXLSHyOl117aWn3OTlwa0uWuhw9ZTt2fmL0EAOvmZOJ7hgPYKfRvz
SbGu2jKWe9fx
=wnr0
-----END PGP SIGNATURE-----