Description
DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in sql_type_cast_svpv.

When casting to SQL_NUMERIC, sql_type_cast_svpv passes the string pointer and length of the SV to grok_number without stringifying it first. An integer (IV) or floating-point (NV) value has no valid string pointer, so grok_number reads from an invalid address, triggering a segmentation fault.

This is reachable in Perl using the sql_type_cast function:

my $num = 42;
DBI::sql_type_cast( $num, DBI::SQL_NUMERIC, 0 );
Published: 2026-09-28
Score: n/a
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The bug occurs when a numeric Perl scalar is passed to DBI::sql_type_cast with the target type SQL_NUMERIC. Internally, sql_type_cast_svpv forwards the scalar’s string pointer and length to the function grok_number without first converting the value to a string. Numeric scalars such as integers or floating‑point numbers have no valid string pointer, so grok_number dereferences an invalid address, triggering a segmentation fault. The result is an immediate crash of the process that called DBI, causing a denial of service for that application instance.

Affected Systems

All installations of the DBI Perl module prior to version 1.654 are affected. The issue was fixed in the 1.654 release; updating to that version or later removes the vulnerability.

Risk and Exploitability

No CVSS score or EPSS data are available, and the vulnerability is not listed in the CISA KEV catalog. The attack surface requires an attacker who can cause the application to invoke DBI::sql_type_cast with a numeric value. In many scripts and web applications that use DBI, such a call is already present, so exploitation can be achieved by injecting a numeric parameter that drives the cast. The inferred attack vector is therefore a local code path that may be leveraged remotely when the application accepts untrusted input. Exploitation results in a segmentation fault, terminating the process and disrupting service, but does not directly expose arbitrary code execution.

Generated by OpenCVE AI on September 28, 2026 at 17:35 UTC.

Remediation

Vendor Solution

Upgrade to DBI 1.654 or later.


OpenCVE Recommended Actions

  • Upgrade the DBI module to version 1.654 or later to apply the vendor fix.
  • Audit application code to locate any explicit calls to DBI::sql_type_cast, especially with numeric values, and remove or replace those calls with safer handling or type checks.
  • Restart affected services after the upgrade to ensure the new library is loaded and to clear any residual crashes.

Generated by OpenCVE AI on September 28, 2026 at 17:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Perl5-dbi
Perl5-dbi dbi
Vendors & Products Perl5-dbi
Perl5-dbi dbi

Mon, 28 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
References

Mon, 28 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in sql_type_cast_svpv. When casting to SQL_NUMERIC, sql_type_cast_svpv passes the string pointer and length of the SV to grok_number without stringifying it first. An integer (IV) or floating-point (NV) value has no valid string pointer, so grok_number reads from an invalid address, triggering a segmentation fault. This is reachable in Perl using the sql_type_cast function: my $num = 42; DBI::sql_type_cast( $num, DBI::SQL_NUMERIC, 0 );
Title DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in sql_type_cast_svpv
Weaknesses CWE-843
References

cve-icon MITRE

Status: PUBLISHED

Assigner: CPANSec

Published:

Updated: 2026-09-28T18:10:34.583Z

Reserved: 2026-09-10T08:47:49.901Z

Link: CVE-2026-88815

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-28T17:17:52.070

Modified: 2026-09-28T19:16:50.483

Link: CVE-2026-88815

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T19:47:50Z

Weaknesses
  • CWE-843

    Access of Resource Using Incompatible Type ('Type Confusion')