Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-88815— DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in sql_type_cast_svpv

Quick assessment

Affected
CVE-2026-88815
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

DBI 1.654 之前的 Perl 版本在 函数中错误地将数值类型当作字符串处理。 具体而言,在将值转换为 类型时, 会将 SV(标量值)的字符串指针和长度直接传递给 ,而在此之前并未先将该值字符串化。对于整型(IV)或浮点型(NV)值,它们本身没有有效的字符串指针,因此 会从无效的内存地址读取数据,从而触发段错误(segmentation fault)。 该漏洞可通过 Perl 中的 函数触发,示例代码如下:

AI Predicted 5.3 Difficulty: Easy

Possible ATT&CK Techniques 1 AI

T1203 · Exploitation for Client Execution

Affected Version Matrix 1

VendorProduct Version RangeStatus
None None < 1.654 affected

I. Basic Information for CVE-2026-88815

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in sql_type_cast_svpv
Source: CVE Program / CVE List V5
Vulnerability Description
DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in sql_type_cast_svpv. When casting to SQL_NUMERIC, sql_type_cast_svpv passes the string pointer and length of the SV to grok_number without stringifying it first. An integer (IV) or floating-point (NV) value has no valid string pointer, so grok_number reads from an invalid address, triggering a segmentation fault. This is reachable in Perl using the sql_type_cast function: my $num = 42; DBI::sql_type_cast( $num, DBI::SQL_NUMERIC, 0 );
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
使用不兼容类型访问资源(类型混淆)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
- - 0 ~ 1.654 -

II. Public POCs for CVE-2026-88815

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-88815

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-88815 (1)

Vendor Advisories for CVE-2026-88815 (1)

Other References for CVE-2026-88815 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-88815

No comments yet


Leave a comment