{"id":"CVE-2026-88816","summary":"DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in FetchHashKeyName","details":"DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in FetchHashKeyName.\n\nfetchrow_hashref uses the string pointer of the FetchHashKeyName attribute as the key name without stringifying it first. When FetchHashKeyName has been set to an integer (IV) or floating-point (NV) value, that pointer is invalid, so reading the key name triggers a segmentation fault.\n\nThis can be triggered with the following code:\n\n   my $dbh = DBI-\u003econnect( \"dbi:ExampleP:\", \"\", \"\",\n       { RaiseError =\u003e 0, PrintError =\u003e 0 } );\n   $dbh-\u003e{FetchHashKeyName} = 42;\n\n   my $sth = $dbh-\u003eprepare(\"select mode, size, name from .\");\n   $sth-\u003eexecute;\n   $sth-\u003efetchrow_hashref;","aliases":["GHSA-f4qx-mr9m-q2hq"],"modified":"2026-09-30T03:47:27.766615946Z","published":"2026-09-28T16:04:40.458Z","database_specific":{"cna_assigner":"CPANSec","cwe_ids":["CWE-843"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/88xxx/CVE-2026-88816.json"},"references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/09/28/13"},{"type":"WEB","url":"https://cpan.org/modules"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/88xxx/CVE-2026-88816.json"},{"type":"ADVISORY","url":"https://github.com/perl5-dbi/dbi/security/advisories/GHSA-f4qx-mr9m-q2hq"},{"type":"ADVISORY","url":"https://metacpan.org/release/HMBRAND/DBI-1.654/changes"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-88816"},{"type":"FIX","url":"https://github.com/perl5-dbi/dbi/commit/70962570212dc60a5428098cf2a0462ad5945851.patch"},{"type":"PACKAGE","url":"https://github.com/perl5-dbi/dbi"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/perl5-dbi/dbi","events":[{"introduced":"0"},{"fixed":"4e9aa3345770a3afd3cd37b305f15c97e3cd70bc"},{"fixed":"70962570212dc60a5428098cf2a0462ad5945851"}],"database_specific":{"source":["DESCRIPTION","REFERENCES"],"extracted_events":[{"introduced":"0"},{"fixed":"1.654"}]}}],"versions":["1.653","1.652","1.651","1.650","1.649","1.648","1.647","1.646","1.645","1.644","1.643_02","1.643_01","1.643","1.642","1.641","1.640","1.639","1.638","1.637","1.636","1.635","1.634","1.633_92","1.633_91","1.633_90","1.633","1.632_90","1.632","1.631","1.630","1.628","1.627","1.626","1.625","1.624","1.622","1.619","1.618","1.615","1.614_90","1.613_93","1.613_92","1.613_91","1.613_90","1.613_71","1.613_70","1.611_94","1.611_93","1.611_92","1.611_91","1.611_90","1.607","1.602","DBI-1.58","DBI-1.57","DBI-1.51","DBI-1.47"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-88816.json"}}],"schema_version":"1.9.0"}