{"id":"DEBIAN-CVE-2026-88816","details":"DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in FetchHashKeyName.  fetchrow_hashref uses the string pointer of the FetchHashKeyName attribute as the key name without stringifying it first. When FetchHashKeyName has been set to an integer (IV) or floating-point (NV) value, that pointer is invalid, so reading the key name triggers a segmentation fault.  This can be triggered with the following code:     my $dbh = DBI-\u003econnect( \"dbi:ExampleP:\", \"\", \"\",        { RaiseError =\u003e 0, PrintError =\u003e 0 } );    $dbh-\u003e{FetchHashKeyName} = 42;     my $sth = $dbh-\u003eprepare(\"select mode, size, name from .\");    $sth-\u003eexecute;    $sth-\u003efetchrow_hashref;","modified":"2026-09-29T05:00:36.881276991Z","published":"2026-09-28T17:17:52.203Z","upstream":["CVE-2026-88816"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2026-88816"}],"affected":[{"package":{"name":"libdbi-perl","ecosystem":"Debian:12","purl":"pkg:deb/debian/libdbi-perl?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.643-4+deb12u3"}]}],"versions":["1.643-4","1.643-4+deb12u1","1.643-4+deb12u2"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-88816.json"}},{"package":{"name":"libdbi-perl","ecosystem":"Debian:13","purl":"pkg:deb/debian/libdbi-perl?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.647-1","1.647-1+deb13u1","1.648-1","1.649-1","1.650-1","1.651-1","1.652-1","1.652-2","1.652-2~deb13u1","1.653-1","1.654-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-88816.json"}},{"package":{"name":"libdbi-perl","ecosystem":"Debian:14","purl":"pkg:deb/debian/libdbi-perl?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.647-1","1.648-1","1.649-1","1.650-1","1.651-1","1.652-1","1.652-2","1.652-2~deb13u1","1.653-1","1.654-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-88816.json"}}],"schema_version":"1.9.0"}