{"cvss":9.8,"datePublished":"2026-06-09T08:16:29.190","dateUpdated":"2026-09-03T13:06:25.563","description":"DBI versions before 1.648 for Perl saved errors in a limited-sized buffer.\n\nError messages that were returned when RaiseError, PrintError or HandleError were set were written to a 200-byte buffer without a length limit.\n\nAttackers that can influence the error text in an application can trigger a buffer overflow.","id":"CVE-2026-9698","raw":{"affected":[{"affectedData":[{"collectionURL":"https://cpan.org/modules","defaultStatus":"unaffected","packageName":"DBI","product":"DBI","programFiles":["DBI.xs"],"repo":"https://github.com/perl5-dbi/dbi","vendor":"HMBRAND","versions":[{"lessThan":"1.648","status":"affected","version":"0","versionType":"custom"}]}],"source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"affectedData":[{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/o:redhat:enterprise_linux:10.2"],"defaultStatus":"affected","packageName":"perl-DBI","product":"Red Hat Enterprise Linux 10","vendor":"Red Hat","versions":[{"lessThan":"*","status":"unaffected","version":"0:1.643-26.el10_2.1","versionType":"rpm"}]},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:enterprise_linux:8"],"defaultStatus":"affected","packageName":"perl-DBI:1.641","product":"Red Hat Enterprise Linux 8","vendor":"Red Hat","versions":[{"lessThan":"*","status":"unaffected","version":"8100020260624081239.69ef70f8","versionType":"rpm"}]},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:enterprise_linux:9"],"defaultStatus":"affected","packageName":"perl-DBI","product":"Red Hat Enterprise Linux 9","vendor":"Red Hat","versions":[{"lessThan":"*","status":"unaffected","version":"0:1.643-9.el9_8.1","versionType":"rpm"}]},{"collectionURL":"https://catalog.redhat.com/software/containers/","cpes":["cpe:/a:redhat:insights_proxy:1.5::el9"],"defaultStatus":"affected","packageName":"insights-proxy/insights-proxy-container-rhel9","product":"Red Hat Insights proxy 1.5","vendor":"Red Hat","versions":[{"lessThan":"*","status":"unaffected","version":"1786433656","versionType":"rpm"}]},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/o:redhat:enterprise_linux:6"],"defaultStatus":"unknown","packageName":"perl-DBI","product":"Red Hat Enterprise Linux 6","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/o:redhat:enterprise_linux:7"],"defaultStatus":"affected","packageName":"perl-DBI","product":"Red Hat Enterprise Linux 7","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/o:redhat:enterprise_linux:8"],"defaultStatus":"affected","packageName":"perl-DBI","product":"Red Hat Enterprise Linux 8","vendor":"Red Hat"}],"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"configurations":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:a:perl:dbi:*:*:*:*:*:*:*:*","matchCriteriaId":"5C23D2D0-3FFA-4C49-952A-FD8FE4684AF5","versionEndExcluding":"1.648","vulnerable":true}],"negate":false,"operator":"OR"}]}],"cveTags":[],"descriptions":[{"lang":"en","value":"DBI versions before 1.648 for Perl saved errors in a limited-sized buffer.\n\nError messages that were returned when RaiseError, PrintError or HandleError were set were written to a 200-byte buffer without a length limit.\n\nAttackers that can influence the error text in an application can trigger a buffer overflow."},{"lang":"es","value":"Las versiones de DBI anteriores a la 1.648 para Perl guardaban errores en un búfer de tamaño limitado.\n\nLos mensajes de error que se devolvían cuando RaiseError, PrintError o HandleError estaban configurados se escribían en un búfer de 200 bytes sin un límite de longitud.\n\nLos atacantes que pueden influir en el texto de error en una aplicación pueden desencadenar un desbordamiento de búfer."}],"id":"CVE-2026-9698","lastModified":"2026-09-03T13:06:25.563","metrics":{"cvssMetricV31":[{"cvssData":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"exploitabilityScore":3.9,"impactScore":5.9,"source":"nvd@nist.gov","type":"Primary"},{"cvssData":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"exploitabilityScore":3.9,"impactScore":3.6,"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cvssData":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.2,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","version":"3.1"},"exploitabilityScore":3.9,"impactScore":4.2,"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"id":"CVE-2026-9698","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-06-09T15:44:04.195929Z","version":"2.0.3"}}]},"published":"2026-06-09T08:16:29.190","references":[{"source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","tags":["Patch"],"url":"https://github.com/perl5-dbi/dbi/commit/bfe5d73c162d2d1f761a639a0aa33aad6a9eb54e.patch"},{"source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","tags":["Release Notes"],"url":"https://metacpan.org/release/HMBRAND/DBI-1.648/changes"},{"source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"url":"http://www.openwall.com/lists/oss-security/2026/06/09/9"},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","url":"https://access.redhat.com/errata/RHSA-2026:38512"},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","url":"https://access.redhat.com/errata/RHSA-2026:38513"},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","url":"https://access.redhat.com/errata/RHSA-2026:38901"},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","url":"https://access.redhat.com/errata/RHSA-2026:53371"},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","url":"https://access.redhat.com/errata/RHSA-2026:62667"},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","url":"https://access.redhat.com/security/cve/CVE-2026-9698"},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2486734"},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-9698.json"}],"sourceIdentifier":"9b29abf9-4ab0-4765-b253-1875cd9b441e","vulnStatus":"Modified","weaknesses":[{"description":[{"lang":"en","value":"CWE-787"}],"source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"description":[{"lang":"en","value":"CWE-120"}],"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]},"severity":"CRITICAL","source":"nvd","title":"DBI versions before 1.648 for Perl saved errors in a limited-sized buffer.\n\nError messages that were returned when Ra..."}