CVE-2026-10879: DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders
DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.643-4 - Upgrade
Upgrade
debian/libdbi-perlto a version that resolves this vulnerability.Fixed in 1.643-3+deb11u1Fixed in 1.643-4+deb12u1Fixed in 1.647-1+deb13u1Fixed in 1.648-1 - Upgrade
Upgrade
Perl DBIto a version that resolves this vulnerability.Fixed in 1.648
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10879?
The severity of CVE-2026-10879 is rated at 30, indicating a significant risk due to the potential for a heap overflow vulnerability.
How do I fix CVE-2026-10879?
To fix CVE-2026-10879, you should upgrade to DBI version 1.648 or later.
What software is affected by CVE-2026-10879?
CVE-2026-10879 affects the DBI module for Perl, specifically versions prior to 1.648.
What type of vulnerability is CVE-2026-10879?
CVE-2026-10879 is a heap overflow vulnerability that occurs during the preparation of SQL statements with excessive binders.
When was CVE-2026-10879 published?
CVE-2026-10879 was published on June 5, 2026.