CVE-2026-88815

Published: Set 28, 2026 Last Modified: Set 28, 2026
ExploitDB:
Other exploit source:
Google Dorks:

Description

AI Translation Available

DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in sql_type_cast_svpv.

When casting to SQL_NUMERIC, sql_type_cast_svpv passes the string pointer and length of the SV to grok_number without stringifying it first. An integer (IV) or floating-point (NV) value has no valid string pointer, so grok_number reads from an invalid address, triggering a segmentation fault.

This is reachable in Perl using the sql_type_cast function:

my $num = 42;
DBI::sql_type_cast( $num, DBI::SQL_NUMERIC, 0 );

843

Access of Resource Using Incompatible Type ('Type Confusion')

Incomplete
Common Consequences
Security Scopes Affected:
Availability Integrity Confidentiality
Potential Impacts:
Read Memory Modify Memory Execute Unauthorized Code Or Commands Dos: Crash, Exit, Or Restart
Applicable Platforms
Languages: C, C++
View CWE Details
https://github.com/perl5-dbi/dbi/commit/e5ad87e5602da995d28b4d65df222368b58d670…
https://github.com/perl5-dbi/dbi/security/advisories/GHSA-c8vq-w3wr-6979
https://metacpan.org/release/HMBRAND/DBI-1.654/changes
http://www.openwall.com/lists/oss-security/2026/09/28/12