{"id":"AZL-105212","summary":"CVE-2026-88815 affecting package perl-DBI 1.652-1","details":"DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in sql_type_cast_svpv.\n\nWhen casting to SQL_NUMERIC, sql_type_cast_svpv passes the string pointer and length of the SV to grok_number without stringifying it first. An integer (IV) or floating-point (NV) value has no valid string pointer, so grok_number reads from an invalid address, triggering a segmentation fault.\n\nThis is reachable in Perl using the sql_type_cast function:\n\n  my $num = 42;\n  DBI::sql_type_cast( $num, DBI::SQL_NUMERIC, 0 );","modified":"2026-10-03T05:35:10Z","published":"2026-09-28T17:17:52Z","upstream":["CVE-2026-88815"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-88815"}],"affected":[{"package":{"name":"perl-DBI","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/perl-DBI"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.652-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105212.json"}}],"schema_version":"1.9.0"}