Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-60082: Perl DBI versions before 1.651 can cause data corruption

CVE-2026-60082 · published 2 months ago
Summary

Old versions of Perl's DBI library can cause data corruption when using prepared statements with inconsistent metadata and rows. This can happen when a database query is executed with incorrect information about the data it expects. To fix this, update to DBI version 1.651 or later.

What to do
  • Update bellsoft perl-dbi to version 1.651-r0.
  • Update hmbrand dbi to version 1.651 or later.
Affected software
Ecosystem VendorProductAffected versions
– hmbrand dbi < 1.651
Debian:11 debian libdbi-perl All versions
Debian:12 debian libdbi-perl All versions
Debian:13 debian libdbi-perl All versions
Debian:14 debian libdbi-perl All versions
Ubuntu:Pro:14.04:LTS canonical libdbi-perl All versions
Ubuntu:Pro:16.04:LTS canonical libdbi-perl All versions
Ubuntu:Pro:18.04:LTS canonical libdbi-perl All versions
Ubuntu:Pro:20.04:LTS canonical libdbi-perl All versions
Ubuntu:22.04:LTS canonical libdbi-perl All versions
Ubuntu:24.04:LTS canonical libdbi-perl All versions
Ubuntu:26.04:LTS canonical libdbi-perl All versions
Alpaquita:23 bellsoft perl-dbi >= 1.643-r4, < 1.651-r0
Fix: upgrade to 1.651-r0
Alpaquita:25 bellsoft perl-dbi >= 1.647-r0, < 1.651-r0
Fix: upgrade to 1.651-r0
Alpaquita:stream bellsoft perl-dbi >= 1.643-r3, < 1.651-r0
Fix: upgrade to 1.651-r0
Original advisory text
DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row. When the statement handle had no fields but the source row was non-empty, the internal row-buffer helpe...
DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row.

When the statement handle had no fields but the source row was non-empty, the internal row-buffer helper would read from a negative array index.

This could be triggered by a caller supplying inconsistent metadata and rows to the prepare method.
Severity
9.1 Critical
CVSS 3.1: 9.1 (OSV)
Exploitation
EPSS <1%
Type
CWE-125Out-of-bounds Read
Timeline
Published14 Jul 2026
Updated27 Sep 2026
First seen14 Jul 2026
Track software like this
Free during beta