Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-92208.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-92208
Upstream
Published
2026-07-07T23:16:54Z
Modified
2026-08-28T17:48:06Z
Summary
CVE-2026-14740 affecting package perl-DBI for versions less than 1.650-1
Details

DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment.

The preparse method normalises SQL and removes comments. When the SQL starts with a comment line, the deletion of that line during normalisation led to an out-of-bounds read by one byte. The result is a fault on memory-hardened builds and nondeterministic newline retention on normal builds.

References

Affected packages

Azure Linux:3 / perl-DBI

Package

Name
perl-DBI
Purl
pkg:rpm/azure-linux/perl-DBI

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.650-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-92208.json"