https://bugzilla.redhat.com/show_bug.cgi?id=2501294
Bug ID: 2501294
Summary: CVE-2026-60082 perl-DBI: perl-DBI: Denial of Service
via out-of-bounds read [fedora-all]
Product: Fedora
Version: rawhide
Status: NEW
Whiteboard: {"flaws": ["de5423b7-e019-42ed-b997-80db076e7bc9"]}
Component: perl-DBI
Keywords: Security, SecurityTracking
Severity: medium
Priority: medium
Assignee: [email protected]
Reporter: [email protected]
QA Contact: [email protected]
CC: [email protected], [email protected],
[email protected],
[email protected], [email protected]
Blocks: 2500019
Target Milestone: ---
Classification: Fedora
Disclaimer: Community trackers are created by Red Hat Product Security team on
a best effort basis. Package maintainers are required to ascertain if the flaw
indeed affects their package, before starting the update process.
DBI versions before 1.651 for Perl do not enforce statement handle consistency
with the row.
When the statement handle had no fields but the source row was non-empty, the
internal row-buffer helper would read from a negative array index.
This could be triggered by a caller supplying inconsistent metadata and rows to
the prepare method.
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2501294
Report this comment as SPAM:
https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&format=report-spam&short_desc=Report%20of%20Bug%202501294%23c0
--
_______________________________________________
perl-devel mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct:
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives:
https://lists.fedoraproject.org/archives/list/[email protected]
Do not reply to spam, report it:
https://forge.fedoraproject.org/infra/tickets/issues/new