{"id":"DEBIAN-CVE-2026-15043","details":"DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted \u003c= and \u003e= SQL operators on text.  DBI::SQL::Nano, DBI's built-in mini-SQL engine, evaluated WHERE predicates incorrectly in some cases. In the non-numeric string branch of the is_matched method, \u003c= was evaluated using Perl's ge operator, and \u003e= was evaluated using Perl's le operator.  SQL::Nano is the fallback query engine for DBI's file-backed drivers (DBD::File, DBD::DBM, CSV-style drivers) whenever SQL::Statement is not installed, and is forced whenever DBI_SQL_NANO=1. Queries over such tables use these predicates directly.  The impact depends on the context. Where an application relies on a WHERE clause to filter file-backed data for policy or authorization, an inverted \u003c=/\u003e= comparison silently returns the wrong rows.","modified":"2026-09-01T16:06:30.322947587Z","published":"2026-07-14T10:16:31.253Z","upstream":["CVE-2026-15043"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2026-15043"}],"affected":[{"package":{"name":"libdbi-perl","ecosystem":"Debian:12","purl":"pkg:deb/debian/libdbi-perl?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.643-4+deb12u2"}]}],"versions":["1.643-4","1.643-4+deb12u1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-15043.json"}},{"package":{"name":"libdbi-perl","ecosystem":"Debian:13","purl":"pkg:deb/debian/libdbi-perl?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.652-2~deb13u1"}]}],"versions":["1.647-1","1.647-1+deb13u1","1.648-1","1.649-1","1.650-1","1.651-1","1.652-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-15043.json"}},{"package":{"name":"libdbi-perl","ecosystem":"Debian:14","purl":"pkg:deb/debian/libdbi-perl?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.651-1"}]}],"versions":["1.647-1","1.648-1","1.649-1","1.650-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-15043.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}