Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-60082: Perl DBI versions before 1.651 can cause data corruption
CVE-2026-60082 · published 2 months ago
Summary
Old versions of Perl's DBI library can cause data corruption when using prepared statements with inconsistent metadata and rows. This can happen when a database query is executed with incorrect information about the data it expects. To fix this, update to DBI version 1.651 or later.
What to do
- Update bellsoft perl-dbi to version 1.651-r0.
- Update hmbrand dbi to version 1.651 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | hmbrand | dbi | < 1.651 |
| Debian:11 | debian | libdbi-perl | All versions |
| Debian:12 | debian | libdbi-perl | All versions |
| Debian:13 | debian | libdbi-perl | All versions |
| Debian:14 | debian | libdbi-perl | All versions |
| Ubuntu:Pro:14.04:LTS | canonical | libdbi-perl | All versions |
| Ubuntu:Pro:16.04:LTS | canonical | libdbi-perl | All versions |
| Ubuntu:Pro:18.04:LTS | canonical | libdbi-perl | All versions |
| Ubuntu:Pro:20.04:LTS | canonical | libdbi-perl | All versions |
| Ubuntu:22.04:LTS | canonical | libdbi-perl | All versions |
| Ubuntu:24.04:LTS | canonical | libdbi-perl | All versions |
| Ubuntu:26.04:LTS | canonical | libdbi-perl | All versions |
| Alpaquita:23 | bellsoft | perl-dbi |
>= 1.643-r4, < 1.651-r0 Fix: upgrade to 1.651-r0
|
| Alpaquita:25 | bellsoft | perl-dbi |
>= 1.647-r0, < 1.651-r0 Fix: upgrade to 1.651-r0
|
| Alpaquita:stream | bellsoft | perl-dbi |
>= 1.643-r3, < 1.651-r0 Fix: upgrade to 1.651-r0
|
Original advisory text
DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row.
When the statement handle had no fields but the source row was non-empty, the internal row-buffer helpe...
DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row.
When the statement handle had no fields but the source row was non-empty, the internal row-buffer helper would read from a negative array index.
This could be triggered by a caller supplying inconsistent metadata and rows to the prepare method.
When the statement handle had no fields but the source row was non-empty, the internal row-buffer helper would read from a negative array index.
This could be triggered by a caller supplying inconsistent metadata and rows to the prepare method.
References
- https://github.com/perl5-dbi/dbi/security/advisories/GHSA-rwhc-hhmv-cjvg vendor-advisory
- https://metacpan.org/release/HMBRAND/DBI-1.651/changes release-notes
- https://github.com/perl5-dbi/dbi/commit/397868704291bbf0989b97e2c0661189890653e2... patch
- http://www.openwall.com/lists/oss-security/2026/07/14/13
- https://security-tracker.debian.org/tracker/CVE-2026-60082 Vendor Advisory
- https://ubuntu.com/security/CVE-2026-60082 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-60082 Third Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-60082 Vendor Advisory
- https://cpan.org/modules URL
- https://github.com/perl5-dbi/dbi Product
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/60xxx/CVE-2026-60082... Vendor Advisory
- https://docs.bell-sw.com/security/cves/CVE-2026-60082 Vendor Advisory
- https://lists.security.metacpan.org/cve-announce/msg/41813803/ Third Party Advisory
Severity
9.1
Critical
CVSS 3.1: 9.1 (OSV)
Exploitation
EPSS <1%
Type
CWE-125Out-of-bounds Read
Timeline
Published14 Jul 2026
Updated27 Sep 2026
First seen14 Jul 2026
Sources
CVE-2026-60082 · NVD
CVE-2026-60082 · MITRE
DEBIAN-CVE-2026-60082 · OSV
UBUNTU-CVE-2026-60082 · OSV
GHSA-rwhc-hhmv-cjvg · GHSA
BELL-CVE-2026-60082 · OSV
CVE-2026-60082 · OSV
Track software like this
Free during beta