Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-92424.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-92424
Upstream
Published
2026-07-14T16:16:45Z
Modified
2026-08-28T17:48:12Z
Summary
CVE-2026-15392 affecting package perl-DBI for versions less than 1.651-1
Details

DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location.

The complete_table_name method builds the absolute table file path without checking whether the file is a symbolic link. A link inside the data directory can point to a table file at any path outside of the configured f_dir and f_dir_search directories.

Callers of file-based drivers can read or write files outside of the data directory.

References

Affected packages

Azure Linux:3 / perl-DBI

Package

Name
perl-DBI
Purl
pkg:rpm/azure-linux/perl-DBI

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.651-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-92424.json"