Critical severity9.8NVD Advisory· Published Jun 9, 2026· Updated Sep 3, 2026
CVE-2026-9698
CVE-2026-9698
Description
DBI versions before 1.648 for Perl saved errors in a limited-sized buffer.
Error messages that were returned when RaiseError, PrintError or HandleError were set were written to a 200-byte buffer without a length limit.
Attackers that can influence the error text in an application can trigger a buffer overflow.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6(expand)+ 2 more
- (no CPE)
- cpe:2.3:a:perl:dbi:*:*:*:*:*:*:*:*range: <1.648
- (no CPE)range: <1.648
- osv-coords3 versionspkg:rpm/almalinux/perl-DBIpkg:rpm/opensuse/perl-DBI&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/perl-DBI&distro=openSUSE%20Tumbleweed
< 1.643-9.el9_8.1+ 2 more
- (no CPE)range: < 1.643-9.el9_8.1
- (no CPE)range: < 1.647.0-160000.3.1
- (no CPE)range: < 1.648.0-1.1
Patches
Vulnerability mechanics
References
11- github.com/perl5-dbi/dbi/commit/bfe5d73c162d2d1f761a639a0aa33aad6a9eb54e.patchnvdPatch
- www.openwall.com/lists/oss-security/2026/06/09/9nvdMailing ListThird Party Advisory
- metacpan.org/release/HMBRAND/DBI-1.648/changesnvdRelease Notes
- access.redhat.com/errata/RHSA-2026:38512nvd
- access.redhat.com/errata/RHSA-2026:38513nvd
- access.redhat.com/errata/RHSA-2026:38901nvd
- access.redhat.com/errata/RHSA-2026:53371nvd
- access.redhat.com/errata/RHSA-2026:62667nvd
- access.redhat.com/security/cve/CVE-2026-9698nvd
- bugzilla.redhat.com/show_bug.cginvd
- security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-9698.jsonnvd
News mentions
0No linked articles in our index yet.