MGASA-2026-0390
Advisory lineage Upstream: 2 Downstream: 0
Upstream
Published: 09 Sept 2026, 23:52
Last modified:10 Sept 2026, 00:00
Vulnerability Summary
Overall Risk (default)
minimal
0/100 CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
09 Sept 2026, 23:52
Published
Vulnerability first disclosed
10 Sept 2026, 00:00
Last Modified
Vulnerability information updated
Description
Updated perl-DBI packages fix security vulnerabilities DBI versions before 1.652 for Perl allow a heap out-of-bounds write on 32-bit perl via an integer wraparound in the output buffer size computed by preparse. DBI versions before 1.652 for Perl allow a heap out-of-bounds write via an unvalidated numeric placeholder that sets the binder counter in preparse.
Affected Systems
- mageia•perl-DBI
< 1.652.0-2.mga10
- mageia•perl-DBI
< 1.652.0-1.1.mga9
References (6)
- https://advisories.mageia.org/MGASA-2026-0390.html
- https://bugs.mageia.org/show_bug.cgi?id=36144
- https://www.openwall.com/lists/oss-security/2026/08/15/2
- https://github.com/perl5-dbi/dbi/security/advisories/GHSA-wj3v-c3hh-mhqr
- https://www.openwall.com/lists/oss-security/2026/08/15/3
- https://github.com/perl5-dbi/dbi/security/advisories/GHSA-623j-hfpc-mrc4