Description
DBD::Pg version 3.21.0 for Perl has a heap out-of-bounds write in quote_float.

quote_float() allocates the length of the string + 1, which is the size of the bare numeric symbol plus NULL. But for special literals NaN, Inf, +Inf, -Inf, Infinity, +Infinity, -Infinity it emits the literal surrounded by quotes plus NULL, which is length + 3 bytes. Every recognised literal (case-insensitive) overflows by 2 bytes, a single quote and a NULL.

This can be reached by the $dbh->quote method, for example

$dbh->quote( "Infinity", DBI::SQL_NUMERIC ).

This regression was introduced in 3.21.0 by the quote.c rewrite.
Published: 2026-08-23
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A heap out‑of‑bounds write occurs in the quote_float function of DBD::Pg 3.21.0, which miscalculates the buffer length for special numeric literals such as NaN and Infinity. The function allocates only the length of the literal plus a null terminator, but then emits the literal surrounded by single quotes, causing a two‑byte overflow. This overflow corrupts adjacent heap memory and can lead to memory corruption, potentially enabling arbitrary code execution or a denial of service.

Affected Systems

Perl applications that use the DBD::Pg database driver version 3.21.0. The module is distributed by the Bucardo project on GitHub and is commonly used in Perl environments that interface with PostgreSQL.

Risk and Exploitability

The CVE has a CVSS score of 9.8 and an EPSS score of < 1%, but the nature of the vulnerability—an unchecked heap write—implies high severity. The exploit is achievable via the $dbh->quote call when the application passes a numeric value like Infinity with the SQL_NUMERIC type, a scenario that can occur in both remote client code or local scripts. While no active exploit is listed in KEV, the vulnerability poses a serious risk if an attacker can supply such input to the quoting function.

Generated by OpenCVE AI on August 26, 2026 at 04:15 UTC.

Remediation

Vendor Solution

Upgrade to version 3.21.1 or later.


OpenCVE Recommended Actions

  • Upgrade the DBD::Pg module to version 3.21.1 or later, which includes the fix for the buffer allocation issue.
  • If an upgrade is not immediately possible, apply the patch found in the commits https://github.com/bucardo/dbdpg/commit/6d6f47ed2403cda55c82b1bad56e388ba7390065.patch or https://github.com/bucardo/dbdpg/commit/adacf1de872326a465e13f9e4281a674ebcd227e to correct the quote_float implementation.
  • Reduce the attack surface by disabling or sanitizing calls to $dbh->quote with the SQL_NUMERIC type for literals such as NaN, Infinity or -Infinity until a patch is applied.

Generated by OpenCVE AI on August 26, 2026 at 04:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Bucardo
Bucardo dbdpg
Vendors & Products Bucardo
Bucardo dbdpg

Sun, 23 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
References

Sun, 23 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
Description DBD::Pg version 3.21.0 for Perl has a heap out-of-bounds write in quote_float. quote_float() allocates the length of the string + 1, which is the size of the bare numeric symbol plus NULL. But for special literals NaN, Inf, +Inf, -Inf, Infinity, +Infinity, -Infinity it emits the literal surrounded by quotes plus NULL, which is length + 3 bytes. Every recognised literal (case-insensitive) overflows by 2 bytes, a single quote and a NULL. This can be reached by the $dbh->quote method, for example $dbh->quote( "Infinity", DBI::SQL_NUMERIC ). This regression was introduced in 3.21.0 by the quote.c rewrite.
Title DBD::Pg version 3.21.0 for Perl has a heap out-of-bounds write in quote_float
Weaknesses CWE-787
References

cve-icon MITRE

Status: PUBLISHED

Assigner: CPANSec

Published:

Updated: 2026-08-25T19:32:39.393Z

Reserved: 2026-08-23T16:38:31.813Z

Link: CVE-2026-78183

cve-icon Vulnrichment

Updated: 2026-08-23T23:04:55.125Z

cve-icon NVD

Status : Deferred

Published: 2026-08-23T20:16:50.550

Modified: 2026-08-26T16:51:19.490

Link: CVE-2026-78183

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T04:30:16Z

Weaknesses