Executive brief
The Perl DBI module, a standard database interface for the Perl programming language, contains a minor flaw in how it processes SQL queries. When a query starts with a specific type of comment, the system may read a single byte of memory it shouldn't. In most cases, this results in minor formatting inconsistencies, but on systems with strict security hardening, it could cause the application to crash.
Technical details
An out-of-bounds read exists in the XS preparse() method of the Perl DBI module. When the preparse method normalizes SQL and encounters a deletable line comment (starting with '--' or '#') at the very beginning of the input string, it attempts to inspect the previously emitted byte to determine newline retention. Because no bytes have been emitted yet, the pointer logic reads one byte before the start of the newly allocated output buffer. This results in a heap-buffer-overflow READ of size 1. On memory-hardened builds or those using AddressSanitizer (ASAN), this causes an application crash; on standard builds, it leads to nondeterministic newline retention. The issue is fixed in version 1.650 by adding a bounds check to ensure the destination pointer has advanced before inspecting the previous byte.
Affected products
- Perl DBI < 1.650
Timeline
- 2026-07-04: patched: Fix committed to repository
- 2026-07-06: advisory: Version 1.650 released with fix
- 2026-07-07: disclosed: CVE published