CVE-2020-14392
Description
An untrusted pointer dereference in Perl-DBI < 1.643 allows a local attacker to cause memory corruption and denial of service via manipulated calls to dbd_db_login6_sv().
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
An untrusted pointer dereference in Perl-DBI < 1.643 allows a local attacker to cause memory corruption and denial of service via manipulated calls to dbd_db_login6_sv().
Vulnerability
An untrusted pointer dereference flaw exists in Perl-DBI versions prior to 1.643 [1]. The vulnerability occurs in the XS (eXternal Subroutine) functions when the Perl stack is reallocated, specifically within the dbd_db_login6_sv() function. A local attacker can manipulate calls to this function, leading to memory corruption [1]. The affected code path is reachable under normal operational conditions when the Perl interpreter reallocates its stack during a login operation.
Exploitation
To exploit this vulnerability, an attacker needs local access and the ability to craft or influence calls to dbd_db_login6_sv(). The attacker can trigger memory corruption by causing the Perl stack to be reallocated in a way that leaves a dangling pointer, which is then dereferenced unsafely [1]. No authentication or special privileges are required beyond local user access to execute a Perl script that uses the DBI module.
Impact
Successful exploitation leads to memory corruption, primarily affecting the availability of the service (denial of service) [1]. The vulnerability is classified as low severity by Red Hat [1]. In some configurations, an attacker might also achieve arbitrary code execution, as noted in the Ubuntu security advisory [2], but the primary impact is denial of service.
Mitigation
The vulnerability is fixed in Perl-DBI version 1.643 [1]. Red Hat has acknowledged the issue as CLOSED WONTFIX for some products, indicating that no official Red Hat patch will be provided for certain affected releases [1]. Users should update to version 1.643 or later [2]. Ubuntu provided updated packages via USN-4503-1 [2]. If updating is not possible, consider restricting local access to the system as a workaround.
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
30- Perl-DBI/Perl-DBIdescription
- Range: <1.643
- osv-coords28 versionspkg:rpm/opensuse/perl-DBI&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/perl-DBI&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/perl-DBI&distro=openSUSE%20Tumbleweedpkg:rpm/suse/perl-DBI&distro=HPE%20Helion%20OpenStack%208pkg:rpm/suse/perl-DBI&distro=SUSE%20Enterprise%20Storage%205pkg:rpm/suse/perl-DBI&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/perl-DBI&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/perl-DBI&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP1pkg:rpm/suse/perl-DBI&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP2pkg:rpm/suse/perl-DBI&distro=SUSE%20Linux%20Enterprise%20Point%20of%20Sale%2011%20SP3pkg:rpm/suse/perl-DBI&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-LTSSpkg:rpm/suse/perl-DBI&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCLpkg:rpm/suse/perl-DBI&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-LTSSpkg:rpm/suse/perl-DBI&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-BCLpkg:rpm/suse/perl-DBI&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-LTSSpkg:rpm/suse/perl-DBI&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4-LTSSpkg:rpm/suse/perl-DBI&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/perl-DBI&distro=SUSE%20Linux%20Enterprise%20Server%2015-LTSSpkg:rpm/suse/perl-DBI&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2pkg:rpm/suse/perl-DBI&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/suse/perl-DBI&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/suse/perl-DBI&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/perl-DBI&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015pkg:rpm/suse/perl-DBI&distro=SUSE%20OpenStack%20Cloud%207pkg:rpm/suse/perl-DBI&distro=SUSE%20OpenStack%20Cloud%208pkg:rpm/suse/perl-DBI&distro=SUSE%20OpenStack%20Cloud%209pkg:rpm/suse/perl-DBI&distro=SUSE%20OpenStack%20Cloud%20Crowbar%208pkg:rpm/suse/perl-DBI&distro=SUSE%20OpenStack%20Cloud%20Crowbar%209
< 1.639-lp151.3.7.1+ 27 more
- (no CPE)range: < 1.639-lp151.3.7.1
- (no CPE)range: < 1.642-lp152.2.3.1
- (no CPE)range: < 1.643-4.1
- (no CPE)range: < 1.628-5.3.1
- (no CPE)range: < 1.628-5.3.1
- (no CPE)range: < 1.639-3.8.1
- (no CPE)range: < 1.639-3.8.1
- (no CPE)range: < 1.639-3.8.1
- (no CPE)range: < 1.642-3.3.1
- (no CPE)range: < 1.607-3.3.1
- (no CPE)range: < 1.607-3.3.1
- (no CPE)range: < 1.628-5.3.1
- (no CPE)range: < 1.628-5.3.1
- (no CPE)range: < 1.628-5.3.1
- (no CPE)range: < 1.628-5.3.1
- (no CPE)range: < 1.628-5.3.1
- (no CPE)range: < 1.628-5.3.1
- (no CPE)range: < 1.639-3.8.1
- (no CPE)range: < 1.628-5.3.1
- (no CPE)range: < 1.628-5.3.1
- (no CPE)range: < 1.628-5.3.1
- (no CPE)range: < 1.628-5.3.1
- (no CPE)range: < 1.639-3.8.1
- (no CPE)range: < 1.628-5.3.1
- (no CPE)range: < 1.628-5.3.1
- (no CPE)range: < 1.628-5.3.1
- (no CPE)range: < 1.628-5.3.1
- (no CPE)range: < 1.628-5.3.1
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
7- lists.opensuse.org/opensuse-security-announce/2020-09/msg00067.htmlmitrevendor-advisoryx_refsource_SUSE
- lists.opensuse.org/opensuse-security-announce/2020-09/msg00074.htmlmitrevendor-advisoryx_refsource_SUSE
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JXLKODJ7B57GITDEZZXNSHPK4VBYXYHR/mitrevendor-advisoryx_refsource_FEDORA
- usn.ubuntu.com/4503-1/mitrevendor-advisoryx_refsource_UBUNTU
- bugzilla.redhat.com/show_bug.cgimitrex_refsource_MISC
- lists.debian.org/debian-lts-announce/2020/09/msg00026.htmlmitremailing-listx_refsource_MLIST
- metacpan.org/pod/distribution/DBI/Changesmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.