CVE-2026-78183

EUVD-2026-64665
DBD::Pg version 3.21.0 for Perl has a heap out-of-bounds write in quote_float.

quote_float() allocates the length of the string + 1, which is the size of the bare numeric symbol plus NULL.  But for special literals NaN, Inf, +Inf, -Inf, Infinity, +Infinity, -Infinity it emits the literal surrounded by quotes plus NULL, which is length + 3 bytes. Every recognised literal (case-insensitive) overflows by 2 bytes, a single quote and a NULL.

This can be reached by the $dbh->quote method, for example

    $dbh->quote( "Infinity", DBI::SQL_NUMERIC ).

This regression was introduced in 3.21.0 by the quote.c rewrite.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 50.4%
Debian logo
Debian Releases
Debian Product
Codename
libdbd-pg-perl
bookworm
3.16.0-2
fixed
forky
3.21.2-1
fixed
sid
3.21.2-1
fixed
trixie
3.18.0-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libdbd-pg-perl
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
resolute
needs-triage
xenial
needs-triage