{"id":"AZL-92208","summary":"CVE-2026-14740 affecting package perl-DBI for versions less than 1.650-1","details":"DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment.\n\nThe preparse method normalises SQL and removes comments. When the SQL starts with a comment line, the deletion of that line during normalisation led to an out-of-bounds read by one byte. The result is a fault on memory-hardened builds and nondeterministic newline retention on normal builds.","modified":"2026-08-28T17:48:06.705985265Z","published":"2026-07-07T23:16:54Z","upstream":["CVE-2026-14740"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-14740"}],"affected":[{"package":{"name":"perl-DBI","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/perl-DBI"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.650-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-92208.json"}}],"schema_version":"1.9.0"}