CVE-2026-9698
published 2026-06-09CVE-2026-9698: DBI versions before 1.648 for Perl saved errors in a limited-sized buffer. Error messages that were returned when RaiseError, PrintError or HandleError were…
PriorityP349critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.45%
36.5th percentile
DBI versions before 1.648 for Perl saved errors in a limited-sized buffer.
Error messages that were returned when RaiseError, PrintError or HandleError were set were written to a 200-byte buffer without a length limit.
Attackers that can influence the error text in an application can trigger a buffer overflow.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| hmbrand | dbi | < 1.648 | 1.648 |
| perl | dbi | < 1.648 | 1.648 |
| ubuntu | libdbi-perl | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
HMBRAND DBI up to 1.647 on Perl Error Message RaiseError/PrintError/HandleError out-of-bounds write (Nessus ID 320534)
vuldb·2026-06-11·CVSS 9.8
CVE-2026-9698 [CRITICAL] HMBRAND DBI up to 1.647 on Perl Error Message RaiseError/PrintError/HandleError out-of-bounds write (Nessus ID 320534)
A vulnerability categorized as critical has been discovered in HMBRAND DBI up to 1.647 on Perl. Affected by this vulnerability is an unknown functionality of the component Error Message Handler. The manipulation of the argument RaiseError/PrintError/HandleError results in out-of-bounds write.
This vulnerability was named CVE-2026-9698. The attack may be performed from remote. There is no available exploit.
It is advisable to upgrade the affected component.
GHSA
DBI versions before 1.648 for Perl saved errors in a limited-sized buffer.
ghsa_unreviewed·2026-06-09
CVE-2026-9698 [CRITICAL] CWE-787 DBI versions before 1.648 for Perl saved errors in a limited-sized buffer.
DBI versions before 1.648 for Perl saved errors in a limited-sized buffer.
Error messages that were returned when RaiseError, PrintError or HandleError were set were written to a 200-byte buffer without a length limit.
Attackers that can influence the error text in an application can trigger a buffer overflow.
Ubuntu
Perl DBI module vulnerabilities
vendor_ubuntu·2026-06-24·CVSS 9.8
CVE-2026-10879 [CRITICAL] Perl DBI module vulnerabilities
Title: Perl DBI module vulnerabilities
Summary: Several security issues were fixed in Perl DBI module.
It was discovered that the Perl DBI module incorrectly handled certain
error messages. An attacker could use this issue to cause applications
using the Perl DBI module to crash, resulting in a denial of service, or
possibly execute arbitrary code. (CVE-2026-9698)
It was discovered that the Perl DBI module incorrectly handled memory when
preparsing SQL statements that included more than nine binders. An attacker
could use this issue to cause applications using the Perl DBI module to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2026-10879)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
DBI: DBI: Buffer overflow in error handling can lead to arbitrary code execution
vendor_redhat·2026-06-09·CVSS 9.8
CVE-2026-9698 [CRITICAL] CWE-120 DBI: DBI: Buffer overflow in error handling can lead to arbitrary code execution
DBI: DBI: Buffer overflow in error handling can lead to arbitrary code execution
DBI versions before 1.648 for Perl saved errors in a limited-sized buffer.
Error messages that were returned when RaiseError, PrintError or HandleError were set were written to a 200-byte buffer without a length limit.
Attackers that can influence the error text in an application can trigger a buffer overflow.
A flaw was found in DBI, a Perl database interface. This vulnerability allows an attacker to trigger a buffer overflow by manipulating error messages within an application. When specific error handling options are active, an attacker can provide oversized error text, which may lead to arbitrary code execution or a denial of service (DoS).
Statement: Exploitation of this vulnerability requires that an
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-9698 perl-DBI: DBI: Buffer overflow in error handling can lead to arbitrary code execution [fedora-all]
bugzilla·2026-06-15·CVSS 9.8
CVE-2026-9698 [CRITICAL] CVE-2026-9698 perl-DBI: DBI: Buffer overflow in error handling can lead to arbitrary code execution [fedora-all]
CVE-2026-9698 perl-DBI: DBI: Buffer overflow in error handling can lead to arbitrary code execution [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-9698 DBI: DBI: Buffer overflow in error handling can lead to arbitrary code execution
bugzilla·2026-06-09·CVSS 9.8
CVE-2026-9698 [CRITICAL] CVE-2026-9698 DBI: DBI: Buffer overflow in error handling can lead to arbitrary code execution
CVE-2026-9698 DBI: DBI: Buffer overflow in error handling can lead to arbitrary code execution
DBI versions before 1.648 for Perl saved errors in a limited-sized buffer.
Error messages that were returned when RaiseError, PrintError or HandleError were set were written to a 200-byte buffer without a length limit.
Attackers that can influence the error text in an application can trigger a buffer overflow.
https://github.com/perl5-dbi/dbi/commit/bfe5d73c162d2d1f761a639a0aa33aad6a9eb54e.patchhttps://metacpan.org/release/HMBRAND/DBI-1.648/changeshttp://www.openwall.com/lists/oss-security/2026/06/09/9https://access.redhat.com/errata/RHSA-2026:38512https://access.redhat.com/errata/RHSA-2026:38513https://access.redhat.com/errata/RHSA-2026:38901https://access.redhat.com/security/cve/CVE-2026-9698https://bugzilla.redhat.com/show_bug.cgi?id=2486734https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-9698.json
2026-06-09
Published