High severity7.7NVD Advisory· Published Jul 14, 2026· Updated Jul 15, 2026
CVE-2026-15392
CVE-2026-15392
Description
DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location.
The complete_table_name method builds the absolute table file path without checking whether the file is a symbolic link. A link inside the data directory can point to a table file at any path outside of the configured f_dir and f_dir_search directories.
Callers of file-based drivers can read or write files outside of the data directory.
Affected products
2- osv-coords2 versionspkg:rpm/opensuse/perl-DBI&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/perl-DBI&distro=openSUSE%20Tumbleweed
< 1.647.0-160000.5.1+ 1 more
- (no CPE)range: < 1.647.0-160000.5.1
- (no CPE)range: < 1.651.0-1.1
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.