CVE-2026-88816: DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in FetchHashKeyName
DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in FetchHashKeyName.
fetchrowhashref uses the string pointer of the FetchHashKeyName attribute as the key name without stringifying it first. When FetchHashKeyName has been set to an integer (IV) or floating-point (NV) value, that pointer is invalid, so reading the key name triggers a segmentation fault.
This can be triggered with the following code:
my $dbh = DBI->connect( "dbi:ExampleP:", "", "", { RaiseError => 0, PrintError => 0 } ); $dbh->{FetchHashKeyName} = 42;
my $sth = $dbh->prepare("select mode, size, name from ."); $sth->execute; $sth->fetchrowhashref;
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
DBI for Perlto a version that resolves this vulnerability.Fixed in 1.654
Event History
Frequently Asked Questions
What must an attacker or triggering code control to cause the crash?
The code must set the database handle's FetchHashKeyName attribute to an integer or floating-point value and then call fetchrow_hashref on an executed statement handle. The supplied example uses a numeric value of 42.
What is the practical impact of successful triggering?
Reading the invalid key-name pointer triggers a segmentation fault. The provided information describes a denial-of-service condition; it does not describe data exposure, privilege escalation, or code execution.
Which versions need to be remediated?
Perl DBI versions before 1.654 are affected. Upgrade to DBI 1.654 or later.
What mitigation is available if an upgrade cannot happen immediately?
Do not assign integer or floating-point values to FetchHashKeyName when code may call fetchrow_hashref. Ensure the attribute is a string value before fetching rows as hash references.