AZL-105212

See a problem?
Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105212.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-105212
Upstream
Published
2026-09-28T17:17:52Z
Modified
2026-10-03T05:35:10Z
Summary
CVE-2026-88815 affecting package perl-DBI 1.652-1
Details

DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in sql_type_cast_svpv.

When casting to SQL_NUMERIC, sql_type_cast_svpv passes the string pointer and length of the SV to grok_number without stringifying it first. An integer (IV) or floating-point (NV) value has no valid string pointer, so grok_number reads from an invalid address, triggering a segmentation fault.

This is reachable in Perl using the sql_type_cast function:

my $num = 42; DBI::sql_type_cast( $num, DBI::SQL_NUMERIC, 0 );

References

Affected packages

Azure Linux:3 / perl-DBI

Package

Name
perl-DBI
Purl
pkg:rpm/azure-linux/perl-DBI

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
1.652-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105212.json"