Critical severity9.8NVD Advisory· Published Jun 9, 2026· Updated Jun 9, 2026
CVE-2026-9698
CVE-2026-9698
Description
DBI versions before 1.648 for Perl saved errors in a limited-sized buffer.
Error messages that were returned when RaiseError, PrintError or HandleError were set were written to a 200-byte buffer without a length limit.
Attackers that can influence the error text in an application can trigger a buffer overflow.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5(expand)+ 2 more
- (no CPE)
- cpe:2.3:a:perl:dbi:*:*:*:*:*:*:*:*range: <1.648
- (no CPE)range: <1.648
- osv-coords2 versions
< 1.643-9.el9_8.1+ 1 more
- (no CPE)range: < 1.643-9.el9_8.1
- (no CPE)range: < 1.648.0-1.1
Patches
Vulnerability mechanics
References
3- github.com/perl5-dbi/dbi/commit/bfe5d73c162d2d1f761a639a0aa33aad6a9eb54e.patchnvdPatch
- www.openwall.com/lists/oss-security/2026/06/09/9nvdMailing ListThird Party Advisory
- metacpan.org/release/HMBRAND/DBI-1.648/changesnvdRelease Notes
News mentions
0No linked articles in our index yet.