A database access API for perl
Find a file
RHEL Packaging Agent 1daf04a291 CVE-2026-88815 perl-DBI: perl-DBI: Denial of Service via invalid memory read during numeric type casting
Backport fix for CVE-2026-88815: DBI::sql_type_cast used raw
SvPVX/SvCUR to access SV internals, which could cause an
invalid memory read when given numeric (IV/NV) values. The fix
uses SvPV for proper stringification. A second commit fixes
C89 compatibility by moving variable declarations to the top
of the function. Added as DBI-1.641-Fix-CVE-2026-88815.patch.

CVE: CVE-2026-88815
Upstream patches:
 - e5ad87e560.patch
 - ff4f1baf03.patch
Resolves: RHEL-271960

This commit was backported by Ymir, a Red Hat Enterprise Linux software maintenance AI agent.

Assisted-by: Ymir
2026-09-28 18:39:19 +00:00
.fmf Add tests 2026-08-12 16:59:30 +02:00
plans Add tests 2026-08-12 16:59:30 +02:00
.gitignore re-import sources as agreed with the maintainer 2023-06-30 07:35:20 +02:00
.rpmlint re-import sources as agreed with the maintainer 2023-06-30 07:35:20 +02:00
DBI-1.641-Fix-CVE-2026-9698.patch Multiple CVEs 2026-08-19 11:51:20 +02:00
DBI-1.641-Fix-CVE-2026-10879.patch Multiple CVEs 2026-08-19 11:51:20 +02:00
DBI-1.641-Fix-CVE-2026-73194.patch Fix CVE-2026-73194: force placeholder limit on :# and :p# too 2026-09-09 15:10:59 +00:00
DBI-1.641-Fix-CVE-2026-88815.patch CVE-2026-88815 perl-DBI: perl-DBI: Denial of Service via invalid memory read during numeric type casting 2026-09-28 18:39:19 +00:00
DBI-1.643-Fix-CVE-2026-14380.patch Multiple CVEs 2026-08-19 11:51:20 +02:00
DBI-1.643-Fix-CVE-2026-14739.patch Multiple CVEs 2026-08-19 11:51:20 +02:00
gating.yaml Add tests 2026-08-12 16:59:30 +02:00
perl-DBI.spec CVE-2026-88815 perl-DBI: perl-DBI: Denial of Service via invalid memory read during numeric type casting 2026-09-28 18:39:19 +00:00
sources Auto sync2gitlab import of perl-DBI-1.641-1.el8.src.rpm 2022-05-26 12:52:36 -04:00