Debian Patches
Status for libdbi-perl/1.643-4+deb12u3
| Patch | Description | Author | Forwarded | Bugs | Origin | Last update |
|---|---|---|---|---|---|---|
| CVE-2026-15392/06-7415786b.patch | Tighten symlink outside of f_dir (CVE-2026-15392) check (reported by Raj) Still think this needs tests |
"H.Merijn Brand - Tux" <linux@tux.freedom.nl> | yes | debian upstream | https://github.com/perl5-dbi/dbi/commit/7415786b8bf58b1498e9e4f3c8faac7787a057bb | 2026-08-28 |
| CVE-2026-60082.patch | Fix out-of-bounds access in _set_fbav (CVE-2026-60082) This fixes an out-of-bounds access in _set_fbav (DBI.xs) when a statement handle has zero fields but a non-empty row. |
Robert Rothenberg <perl@rhizomnic.com> | yes | debian upstream | https://github.com/perl5-dbi/dbi/commit/397868704291bbf0989b97e2c0661189890653e2 | 2026-07-10 |
| CVE-2026-15392/05-96d62df.patch | Ensure the file is not a symlink outside of f_dir (CVE-2026-15392) This completes the DBD::File fixes for CVE-2014-10401 and CVE-2014-10402 by checking that the table file is not a symlink outside of f_dir. |
Robert Rothenberg <perl@rhizomnic.com> | yes | debian upstream | https://github.com/perl5-dbi/dbi/commit/96d62dfe4528bf56fe13f413ed323d4252531728 | 2026-07-10 |
| CVE-2026-73194/03-9ffafab2.patch | Detect atoi() integer overflow. A nasty feature of atoi() is its missing overflow detection. As we expect integer between 0 and 99999, the number of the input digits can be restricted to 5. Then integer overflow is not possible. |
Alexander Bluhm <alexander.bluhm@gmx.net> | yes | debian upstream | https://github.com/perl5-dbi/dbi/commit/9ffafab2369d7214f88967645feb3beadb900712 | 2026-08-17 |
| CVE-2026-73193/01-c751ae5a.patch | Limit statements to 292 Mb in preparse | "H.Merijn Brand - Tux" <linux@tux.freedom.nl> | yes | debian upstream | https://github.com/perl5-dbi/dbi/commit/c751ae5a5a6f56c2f8284f37c1f4d43500352ef1 | 2026-08-11 |
| CVE-2026-73193/02-afba6751.patch | Fix integer overflow after strlen(). In preparse() the integer variable sln is used the store the return value of strlen(). By that the real length is truncated to 32 bit and made signed. This way the overflow check sln > 306783375 can be circumvented. Make sln of type STRLEN. |
Alexander Bluhm <alexander.bluhm@gmx.net> | yes | debian upstream | https://github.com/perl5-dbi/dbi/commit/afba6751f2acbc1f55ad55aac9f0b58d4f511308 | 2026-08-17 |
| CVE-2026-78030.patch | Load serializer class using Module::Load (CVE-2026-78030) This replaces calls to require with Module::Load, and adds specific checks that arguments are module names instead of filenames. Instead of using our own regex matcher, we attempt to use the Params::Util _CLASS function. The style of trying to import it or adding our own is based on similar code in DBD::File. (This uses SPDX annotations to indicate where the code comes from.) This also adds a suggestion for Params::Util in Makefile.PL. Note that code of the form $INC{"$tie_type.pm"} or require "$tie_type.pm" is redundant, since require checks %INC. See also the similar vulnerability to the DBI::Profile vulnerability CVE-2026-14380 in commit b73d5d9901767fc1d16b6661ef08fbed4532e259. |
Robert Rothenberg <perl@rhizomnic.com> | no | https://github.com/perl5-dbi/dbi/commit/315c6ce703b8b3cbe9188062d9ec80730293554a | 2026-08-22 | |
| CVE-2026-88815.patch | Fix DBI::sql_type_cast on IV/NV (reported by Raj) | "H.Merijn Brand - Tux" <linux@tux.freedom.nl> | no | https://github.com/perl5-dbi/dbi/commit/e5ad87e5602da995d28b4d65df222368b58d6702 | 2026-09-10 | |
| CVE-2026-88816.patch | Fix FetchHashKeyName on IV/NV (CVE-2026-88816) (reported by Raj) | "H.Merijn Brand - Tux" <linux@tux.freedom.nl> | no | https://github.com/perl5-dbi/dbi/commit/70962570212dc60a5428098cf2a0462ad5945851 | 2026-09-10 | |
| CVE-2026-60081.patch | Add a bound to the path index for the profile parser (CVE-2026-60081) An untrusted profile dump file can cause a significant memory amplication. The workaround creates a $MAX_PATH_DEPTH variable that can be changed to override the default limit, if it is too small. |
Robert Rothenberg <perl@rhizomnic.com> | yes | debian upstream | https://github.com/perl5-dbi/dbi/commit/6764e755e83ee1ebb1b40760e5b53eb50960bd7a | 2026-07-10 |
| CVE-2026-73194/01-29b72ae.patch | Force placeholder limit on :# and :p# too | "H.Merijn Brand - Tux" <linux@tux.freedom.nl> | yes | debian upstream | https://github.com/perl5-dbi/dbi/commit/29b72ae7d2a8114a734a55840bf1c45b89207809 | 2026-08-11 |
| CVE-2026-73194/02-acc903d.patch | Fix test for 32bit-perl | "H.Merijn Brand - Tux" <linux@tux.freedom.nl> | yes | debian upstream | https://github.com/perl5-dbi/dbi/commit/acc903db3086a737936643a5dbbc0e22f9d5c421#diff-d16060c2c1bb1df5eff8b8cb493bb8d9c96f5110cad360517fd988137bae0ad0 | 2026-08-17 |
| CVE-2026-15392/03-605a1fe.patch | $searchdir is always set, and the fail is on *use* Tested with new test case in DBD::CSV |
"H.Merijn Brand - Tux" <linux@tux.freedom.nl> | yes | debian upstream | https://github.com/perl5-dbi/dbi/commit/605a1fe6f80802437c4d8a404f88f51cc46ad0fb | 2026-05-28 |
| CVE-2026-15392/04-d9bac9a.patch | Extra Cwd::abs_path required for Windows | "H.Merijn Brand - Tux" <linux@tux.freedom.nl> | yes | debian upstream | https://github.com/perl5-dbi/dbi/commit/d9bac9ad451ee80066905fcd521c51d652143388 | 2026-06-05 |
| CVE-2026-15043/01-e9742ef.patch | Fix inverted SQL comparisons for strings (CVE-2026-15043) The <= operator used `ge` and the >= operator used `le`. Note that this bug has existed since DBI::SQL::Nano was added in DBI 1.42. |
Robert Rothenberg <perl@rhizomnic.com> | yes | debian upstream | https://github.com/perl5-dbi/dbi/commit/e9742ef85a75867cbd696860e3bf3e32b681f98d | 2026-07-10 |
| CVE-2026-15043/02-44b6b2c.patch | Document that DBI::SQL::Nano matches IS NULL against empty strings | Robert Rothenberg <perl@rhizomnic.com> | yes | debian upstream | https://github.com/perl5-dbi/dbi/commit/44b6b2c4af6993cce19557102656c12e828add54 | 2026-07-10 |
| lib-DBD-File.pm-fix-CVE-2014-10401.patch | [2/2] lib/DBD/File.pm: fix CVE-2014-10401 Dig into the root cause of RT#99508 - which resulted in CVE-2014-10401 - and figure out that DBI->parse_dsn is the wrong helper to parse our attributes in DSN, since in DBD::dr::connect only the "dbname" remains from DSN which causes parse_dsn to bailout. Parsing on our own similar to parse_dsn shows the way out. |
Jens Rehsack <sno@netbsd.org> | yes | debian upstream | https://github.com/perl5-dbi/dbi/commit/19d0fb169eed475e1c053e99036b8668625cfa94 | 2020-10-06 |
| Fix-possible-stack-overflow-old-issue-already-noted-.patch | Fix possible stack overflow (old issue already noted by Tim) | "H.Merijn Brand - Tux" <linux@tux.freedom.nl> | no | https://github.com/perl5-dbi/dbi/commit/bfe5d73c162d2d1f761a639a0aa33aad6a9eb54e | 2026-05-27 | |
| Replacing-with-p-in-preparse-with-more-than-9-causes.patch | Replacing `?` with `:p#` in `preparse ()` with more than 9 `?` causes buffer overflow `:p1` is length 3, `?` just 1, but `:p1003` is length 6! |
"H.Merijn Brand - Tux" <linux@tux.freedom.nl> | no | https://github.com/perl5-dbi/dbi/commit/af79036c07aa9a457971c0f4136e37c85dc20978 | 2026-05-28 | |
| CVE-2026-14739.patch | Set a hard limit of 99999 on '?' placeholders | "H.Merijn Brand - Tux" <linux@tux.freedom.nl> | yes | debian upstream | https://github.com/perl5-dbi/dbi/commit/2b77c88b655e9539a592c71a61fb965fc0075395 | 2026-07-04 |
| CVE-2026-15392/01-3f0dae8.patch | Do not allow table source locations outside explicit given folders | "H.Merijn Brand - Tux" <linux@tux.freedom.nl> | yes | debian upstream | https://github.com/perl5-dbi/dbi/commit/3f0dae81b8a96018f20bdb7a6069427ad9dc8d31 | 2026-05-27 |
| CVE-2026-14740.patch | Fix out-of-bounds read in preparse when an initial comment is deleted This fixes CVE-2026-14740 |
Robert Rothenberg <perl@rhizomnic.com> | yes | debian upstream | https://github.com/perl5-dbi/dbi/commit/fc16f9e8b3dd5c65caf1867781ab2bfe2fadcc01 | 2026-07-04 |
| CVE-2026-14380/01-b73d5d9.patch | Load profile packages using Module::Load | Robert Rothenberg <perl@rhizomnic.com> | yes | debian upstream | https://github.com/perl5-dbi/dbi/commit/b73d5d9901767fc1d16b6661ef08fbed4532e259 | 2026-07-01 |
| CVE-2026-14380/02-d982411.patch | Add tests for CVE-2026-14380 | Robert Rothenberg <perl@rhizomnic.com> | yes | debian upstream | https://github.com/perl5-dbi/dbi/commit/d982411aec73b3acfc4e9e465358bca9eb7fede8 | 2026-07-01 |
| CVE-2026-14380/03-f94685f.patch | t/40profile.t increase number of tests in the plan | Robert Rothenberg <perl@rhizomnic.com> | yes | debian upstream | https://github.com/perl5-dbi/dbi/commit/f94685f415b08ea4b1f183d48430c4583c1c07d0 | 2026-07-04 |
| CVE-2026-14380/04-31d2e90.patch | Module::Load is required No known CVE's in that Installs fine on perl-5.8.0, CORE since 5.9.4 |
"H.Merijn Brand - Tux" <linux@tux.freedom.nl> | yes | debian upstream | https://github.com/perl5-dbi/dbi/commit/31d2e90d26db09f47aff4812e65e103cfc2eb3e7 | 2026-07-05 |
| CVE-2026-15392/02-e2b803b.patch | Matching abs_path on relative is bound to fail | "H.Merijn Brand - Tux" <linux@tux.freedom.nl> | yes | debian upstream | https://github.com/perl5-dbi/dbi/commit/e2b803bd8309825719b3577d20dc8dc5ac46e059 | 2026-05-28 |
| CVE-2026-14380/05-afa872d.patch | Set minimum version of Module::Load to 0.22 This fixes a security issue that allowed code outside of @INC to be loaded. |
Robert Rothenberg <perl@rhizomnic.com> | yes | debian upstream | https://github.com/perl5-dbi/dbi/commit/afa872d6cae8a9226779b35a44aeaf6b9b662ec0 | 2026-07-05 |
| CVE-2026-14380/06-7949e55.patch | Improve CVE-2026-14380 tests for Profile | Robert Rothenberg <perl@rhizomnic.com> | yes | debian upstream | https://github.com/perl5-dbi/dbi/commit/7949e551b3c7a8854926b6de84f6cc2ceafb2200 | 2026-07-06 |
| CVE-2026-14380/07-b638c17.patch | Add plan to subtests | Robert Rothenberg <perl@rhizomnic.com> | yes | debian upstream | https://github.com/perl5-dbi/dbi/commit/b638c17320ef10ec939ee50a4e2b144702249bd4 | 2026-07-06 |
| CVE-2026-14380/08-c22067f.patch | Require Test::More 0.96 (tests will otherwise fail on pristine perl-5.12) | "H.Merijn Brand - Tux" <linux@tux.freedom.nl> | yes | debian upstream | https://github.com/perl5-dbi/dbi/commit/c22067f642aad085f345f0370bffb7e2fef01f6b | 2026-07-06 |
| t__06attrs.t__localefix.patch | Fix LC_ALL to C in tests Fix LC_ALL to C for the error messages in the statement handle tests | Damyan Ivanov <dmn@debian.org> | not-needed | 2013-05-03 | ||
| t__40profile.t__NTP.patch | A NTP clock adjustment of -0.00967s lead to FTBFS. | gregor hermann <gregoa@debian.org> | not-needed | 2010-10-07 | ||
| t__80proxy.t___syslogd.patch | syslogd isn't necessarily on the buildds | Nicholas Bamber <nicholas@periapt.co.uk> | no | 2010-10-07 | ||
| spelling.patch | fix spelling mistakes in the POD | gregor herrmann <gregoa@debian.org> | yes | upstream | vendor | 2020-02-08 |
| t-51dbm_file.t-add-test-from-RT-99508.patch | [1/2] t/51dbm_file.t: add test from RT#99508 Add test with f_dir="something-not-existing" as reported in RT#99508 to verify when it's fixed for real. |
Jens Rehsack <sno@netbsd.org> | yes | debian upstream | https://github.com/perl5-dbi/dbi/commit/27b10b5c3aacabc091046beaba478e671bb6111c | 2020-10-06 |
All known versions for source package 'libdbi-perl'
- 1.654-1 (sid, forky)
- 1.652-2~deb13u1 (trixie, trixie-security)
- 1.643-4+deb12u3 (bookworm-security)
- 1.643-4+deb12u1 (bookworm)
