DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row.

When the statement handle had no fields but the source row was non-empty, the internal row-buffer helper would read from a negative array index.

This could be triggered by a caller supplying inconsistent metadata and rows to the prepare method.

Project Subscriptions

Vendors Products
Hmbrand Subscribe
Advisories

No advisories yet.

Fixes

Solution

Upgrade to version 1.651 or later.


Workaround

No workaround given by the vendor.

History

Fri, 17 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Wed, 15 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Hmbrand
Hmbrand dbi
Vendors & Products Hmbrand
Hmbrand dbi

Tue, 14 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row. When the statement handle had no fields but the source row was non-empty, the internal row-buffer helper would read from a negative array index. This could be triggered by a caller supplying inconsistent metadata and rows to the prepare method.
Title DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row
Weaknesses CWE-125
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: CPANSec

Published:

Updated: 2026-07-15T14:08:02.262Z

Reserved: 2026-07-08T11:45:04.838Z

Link: CVE-2026-60082

cve-icon Vulnrichment

Updated: 2026-07-14T18:23:08.729Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-14T15:35:00Z

Links: CVE-2026-60082 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-07-24T07:15:03Z

Weaknesses