CVE-2026-9698

EUVD-2026-35366
DBI versions before 1.648 for Perl saved errors in a limited-sized buffer.

Error messages that were returned when RaiseError, PrintError or HandleError were set were written to a 200-byte buffer without a length limit.

Attackers that can influence the error text in an application can trigger a buffer overflow.
Classic Buffer Overflow
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 36%
Affected Products (NVD)
VendorProductVersion
perldbi
𝑥
< 1.648
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
Red HatRed Hat Enterprise Linux 10
0:1.643-26.el10_2.1 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8
8100020260624081239.69ef70f8 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9
0:1.643-9.el9_8.1 ≤
𝑥
< *
ADP
Debian logo
Debian Releases
Debian Product
Codename
libdbi-perl
bookworm
1.643-4+deb12u1
fixed
bookworm (security)
1.643-4+deb12u1
fixed
bullseye
vulnerable
bullseye (security)
1.643-3+deb11u1
fixed
forky
1.651-1
fixed
sid
1.651-1
fixed
trixie
1.647-1+deb13u1
fixed
trixie (security)
1.647-1+deb13u1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
perl-DBI
RHEL 9
0:1.643-9.el9_8.1
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
perl-DBI
Amazon Linux 2
0:1.627-4.amzn2.0.3
fixed
Amazon Linux 2023
0:1.648-1.amzn2023.0.1
fixed
perl-DBI-debuginfo
Amazon Linux 2
0:1.627-4.amzn2.0.3
fixed
Amazon Linux 2023
0:1.648-1.amzn2023.0.1
fixed
perl-DBI-debugsource
Amazon Linux 2023
0:1.648-1.amzn2023.0.1
fixed
perl-DBI-tests
Amazon Linux 2023
0:1.648-1.amzn2023.0.1
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
perl-DBI
Azure Linux 3.0
0:1.643-5.azl3
fixed