{"id":"CVE-2026-9698","summary":"DBI versions before 1.648 for Perl saved errors in a limited-sized buffer","details":"DBI versions before 1.648 for Perl saved errors in a limited-sized buffer.\n\nError messages that were returned when RaiseError, PrintError or HandleError were set were written to a 200-byte buffer without a length limit.\n\nAttackers that can influence the error text in an application can trigger a buffer overflow.","modified":"2026-09-05T03:30:22.118333448Z","published":"2026-06-09T07:22:25.892Z","related":["ALSA-2026:38512","ALSA-2026:38513","ALSA-2026:38901","ALSA-2026:62667","SUSE-SU-2026:22257-1","SUSE-SU-2026:22330-1","SUSE-SU-2026:2748-1","SUSE-SU-2026:2749-1","SUSE-SU-2026:2750-1","openSUSE-SU-2026:10986-1","openSUSE-SU-2026:21029-1"],"database_specific":{"cna_assigner":"CPANSec","cwe_ids":["CWE-787"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/9xxx/CVE-2026-9698.json"},"references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/06/09/9"},{"type":"WEB","url":"https://cpan.org/modules"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-9698.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:38512"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:38513"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:38901"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:53371"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:62667"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2026-9698"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/9xxx/CVE-2026-9698.json"},{"type":"ADVISORY","url":"https://metacpan.org/release/HMBRAND/DBI-1.648/changes"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-9698"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2486734"},{"type":"FIX","url":"https://github.com/perl5-dbi/dbi/commit/bfe5d73c162d2d1f761a639a0aa33aad6a9eb54e.patch"},{"type":"PACKAGE","url":"https://github.com/perl5-dbi/dbi"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/perl5-dbi/dbi","events":[{"introduced":"0"},{"fixed":"77c5de11da879ec6a869c4c89bc0ff8bf6e2921f"},{"fixed":"bfe5d73c162d2d1f761a639a0aa33aad6a9eb54e"}],"database_specific":{"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:perl:dbi:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.648"}]}}],"versions":["1.647","1.646","1.645","1.644","1.643_02","1.643_01","1.643","1.642","1.641","1.640","1.639","1.638","1.637","1.636","1.635","1.634","1.633_92","1.633_91","1.633_90","1.633","1.632_90","1.632","1.631","1.630","1.628","1.627","1.626","1.625","1.624","1.622","1.619","1.618","1.615","1.614_90","1.613_93","1.613_92","1.613_91","1.613_90","1.613_71","1.613_70","1.611_94","1.611_93","1.611_92","1.611_91","1.611_90","1.607","1.602","DBI-1.58","DBI-1.57","DBI-1.51","DBI-1.47"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-9698.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}