CVE-2026-14740
EUVD-2026-4212507.07.2026, 23:16
DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment. The preparse method normalises SQL and removes comments. When the SQL starts with a comment line, the deletion of that line during normalisation led to an out-of-bounds read by one byte. The result is a fault on memory-hardened builds and nondeterministic newline retention on normal builds.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| perl | dbi | 𝑥 < 1.650 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Amazon Linux Releases
Amazon Package | |||||
|---|---|---|---|---|---|
| perl-DBI |
| ||||
| perl-DBI-debuginfo |
| ||||
| perl-DBI-debugsource |
| ||||
| perl-DBI-tests |
|
Common Weakness Enumeration