Source: libdbi-perl Version: 1.651-1 Severity: important Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerability was published for libdbi-perl. CVE-2026-73193[0]: | DBI versions before 1.652 for Perl allow a heap out-of-bounds write | on 32-bit perl via an integer wraparound in the output buffer size | computed by preparse. preparse reserves its output buffer with | `newSV(strlen(statement) * 7 + 16)`, budgeting seven output bytes | per input byte for the longest ':p99999' expansion. The product is | computed in STRLEN, which is 32 bits wide on a 32-bit perl build, so | a statement of 613,566,757 bytes multiplies to 4,294,967,299, wraps | modulo 2^32 to 3, and reserves 19 bytes. The parser then copies the | statement out through a raw pointer with no capacity check, writing | the whole 585 MB input past the end of the allocation. The 99,999 | placeholder limit does not bound this path, which is reached by | ordinary non-placeholder content. Any caller that passes an | untrusted statement of that length to preparse on a 32-bit perl gets | a heap out-of-bounds write of attacker controlled bytes. Builds with | a 64-bit STRLEN are not affected, since the wrap there needs a | statement of about 2.3 exabytes. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-73193 https://www.cve.org/CVERecord?id=CVE-2026-73193 [1] https://lists.security.metacpan.org/cve-announce/msg/42707360/ Please adjust the affected versions in the BTS as needed. Regards, Salvatore

