ELA-1834-1 libdbi-perl security update

multiple vulnerabilities

2026-09-29
Packagelibdbi-perl
Version1.636-1+deb9u5 (stretch), 1.642-1+deb10u5 (buster), 1.643-3+deb11u3 (bullseye)
Related CVEs CVE-2026-78030 CVE-2026-88815 CVE-2026-88816


CVE-2026-78030

Harsh Raj Singhania discovered that an attacker able to choose DSN fragments or request parameter can trigger arbitrary module load due to the lack of connect attribute validation.

CVE-2026-88815

Harsh Raj Singhania discovered that sql_type_cast_svpv() incorrectly treats numeric values as strings, which may lead to application crash.

CVE-2026-88816

Harsh Raj Singhania discovered that FetchHashKeyName incorrectly treats numeric values as strings, which may lead to application crash.



For Debian 10 buster, these problems have been fixed in version 1.642-1+deb10u5.

For Debian 11 bullseye, these problems have been fixed in version 1.643-3+deb11u3.

For Debian 9 stretch, these problems have been fixed in version 1.636-1+deb9u5.

We recommend that you upgrade your libdbi-perl packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.