CVE-2026-88815
Received Received - Intake

Segmentation Fault in Perl DBI Due to Invalid String Pointer

Vulnerability report for CVE-2026-88815, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: CPANSec

Description

DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in sql_type_cast_svpv. When casting to SQL_NUMERIC, sql_type_cast_svpv passes the string pointer and length of the SV to grok_number without stringifying it first. An integer (IV) or floating-point (NV) value has no valid string pointer, so grok_number reads from an invalid address, triggering a segmentation fault. This is reachable in Perl using the sql_type_cast function: my $num = 42; DBI::sql_type_cast( $num, DBI::SQL_NUMERIC, 0 );

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
dbi dbi to 1.654 (exc)
perl dbi to 1.654 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-843 The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects DBI versions before 1.654 for Perl. It occurs when numeric values (integers or floats) are incorrectly treated as strings in the sql_type_cast_svpv function. When casting to SQL_NUMERIC, the function passes an invalid string pointer to grok_number, causing a segmentation fault due to reading from an uninitialized memory address.

Detection Guidance

To detect this vulnerability, check the installed DBI version on your system. Run: perl -MDBI -e 'print $DBI::VERSION' If the version is below 1.654, the system is vulnerable. You can also test for crashes by running: perl -MDBI -e 'my $x=42; DBI::sql_type_cast($x, DBI::SQL_NUMERIC(), 0)' A crash indicates the vulnerability is present.

Additionally, review Perl applications using DBI that pass numeric values to sql_type_cast or similar functions. Check for segmentation faults in logs or application crashes.

Impact Analysis

This vulnerability can cause Perl programs using DBI to crash unexpectedly when passing pure numeric values (like integers or floats) to functions that expect string inputs. This leads to segmentation faults and program termination, potentially disrupting applications relying on DBI for database operations.

Compliance Impact

This vulnerability causes segmentation faults in Perl applications using DBI versions before 1.654 when processing numeric values as SQL_NUMERIC. It does not directly impact data privacy or security controls required by GDPR or HIPAA, but may lead to application crashes affecting availability of systems handling regulated data.

Mitigation Strategies

Upgrade DBI to version 1.654 or later immediately. Use your package manager or CPAN to update: cpan DBI or via your system's package manager. After updating, test applications to ensure they function correctly with the new version.

Review Perl code using DBI::sql_type_cast or similar functions. Replace direct numeric inputs with string literals or ensure scalars are properly stringified before passing to sql_type_cast.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-88815. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart