Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-92421.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-92421
Upstream
Published
2026-07-14T16:17:03Z
Modified
2026-08-28T17:48:12Z
Summary
CVE-2026-60082 affecting package perl-DBI for versions less than 1.651-1
Details

DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row.

When the statement handle had no fields but the source row was non-empty, the internal row-buffer helper would read from a negative array index.

This could be triggered by a caller supplying inconsistent metadata and rows to the prepare method.

References

Affected packages

Azure Linux:3 / perl-DBI

Package

Name
perl-DBI
Purl
pkg:rpm/azure-linux/perl-DBI

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.651-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-92421.json"