CVE-2026-88816: DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in FetchHashKeyName

Published Sep 28, 2026
·
Updated

DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in FetchHashKeyName.

fetchrowhashref uses the string pointer of the FetchHashKeyName attribute as the key name without stringifying it first. When FetchHashKeyName has been set to an integer (IV) or floating-point (NV) value, that pointer is invalid, so reading the key name triggers a segmentation fault.

This can be triggered with the following code:

my $dbh = DBI->connect( "dbi:ExampleP:", "", "", { RaiseError => 0, PrintError => 0 } ); $dbh->{FetchHashKeyName} = 42;

my $sth = $dbh->prepare("select mode, size, name from ."); $sth->execute; $sth->fetchrowhashref;

Affected Software

1 affected component
cpan/DBI<1.654

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade DBI for Perl to a version that resolves this vulnerability.

    Fixed in 1.654

Event History

Sep 28, 2026
CVE Published
via MITRE·04:04 PM
Data Sourced
via MITRE·04:04 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·05:17 PM
DescriptionWeakness

Frequently Asked Questions

1

What must an attacker or triggering code control to cause the crash?

The code must set the database handle's FetchHashKeyName attribute to an integer or floating-point value and then call fetchrow_hashref on an executed statement handle. The supplied example uses a numeric value of 42.

2

What is the practical impact of successful triggering?

Reading the invalid key-name pointer triggers a segmentation fault. The provided information describes a denial-of-service condition; it does not describe data exposure, privilege escalation, or code execution.

3

Which versions need to be remediated?

Perl DBI versions before 1.654 are affected. Upgrade to DBI 1.654 or later.

4

What mitigation is available if an upgrade cannot happen immediately?

Do not assign integer or floating-point values to FetchHashKeyName when code may call fetchrow_hashref. Ensure the attribute is a string value before fetching rows as hash references.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203