{"id":"MGASA-2026-0390","summary":"Updated perl-DBI packages fix security vulnerabilities","details":"DBI versions before 1.652 for Perl allow a heap out-of-bounds write on\n32-bit perl via an integer wraparound in the output buffer size computed\nby preparse.\nDBI versions before 1.652 for Perl allow a heap out-of-bounds write via\nan unvalidated numeric placeholder that sets the binder counter in\npreparse.\n","modified":"2026-09-10T00:00:03.669294576Z","published":"2026-09-09T23:52:21Z","upstream":["CVE-2026-73193","CVE-2026-73194"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2026-0390.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=36144"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2026/08/15/2"},{"type":"ADVISORY","url":"https://github.com/perl5-dbi/dbi/security/advisories/GHSA-wj3v-c3hh-mhqr"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2026/08/15/3"},{"type":"ADVISORY","url":"https://github.com/perl5-dbi/dbi/security/advisories/GHSA-623j-hfpc-mrc4"}],"affected":[{"package":{"name":"perl-DBI","ecosystem":"Mageia:10","purl":"pkg:rpm/mageia/perl-DBI?arch=source&distro=mageia-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.652.0-2.mga10"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0390.json"}},{"package":{"name":"perl-DBI","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/perl-DBI?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.652.0-1.1.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0390.json"}}],"schema_version":"1.9.0","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}