Source: libdbi-perl Version: 1.651-1 Severity: important Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerability was published for libdbi-perl. CVE-2026-73194[0]: | DBI versions before 1.652 for Perl allow a heap out-of-bounds write | via an unvalidated numeric placeholder that sets the binder counter | in preparse. preparse reserves seven output bytes per input byte, | the width of the longest ':p99999' expansion. The ':N' branch parses | the number with `atoi(src)` and assigns it to the binder counter | with no range check, so a statement containing ':2147483648' leaves | the counter negative (-2147483648 with glibc, where atoi wraps). | Each following '?' then expands through `sprintf(start, ":p%d", | idx++)` to ':p-2147483648', 14 bytes with the terminating NUL where | the buffer budgets 7. The placeholder limit added in 1.650 tests the | counter against 99,999, which a negative counter passes. Any caller | that preparses an untrusted statement into ':pN' style placeholders | gets a heap out-of-bounds write that grows with the number of '?' | marks following the poisoned placeholder. The '?' and '%s' return | styles compare the parsed number against the expected sequence and | error out, and are unaffected. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-73194 https://www.cve.org/CVERecord?id=CVE-2026-73194 [1] https://lists.security.metacpan.org/cve-announce/msg/42707363/ Please adjust the affected versions in the BTS as needed. Regards, Salvatore

