CVE-2026-88816
— UNSCOREDpublic exploit availablePublished 2026-09-28 · Updated 2026-09-29
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in FetchHashKeyName. fetchrow_hashref uses the string pointer of the FetchHashKeyName attribute as the key name without stringifying it first. When FetchHashKeyName has been set to an integer (IV) or floating-point (NV) value, that pointer is invalid, so reading the key name triggers a segmentation fault. This can be triggered with the following code: my $dbh = DBI->connect( "dbi:ExampleP:", "", "", { RaiseError => 0, PrintError => 0 } ); $dbh->{FetchHashKeyName} = 42; my $sth = $dbh->prepare("select mode, size, name from ."); $sth->execute; $sth->fetchrow_hashref;
Weaknesses
CWE-843
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- UNSCOREDCVE-2026-101912PoC
- HIGHCVE-2026-102299
- HIGHCVE-2026-102321
- HIGHCVE-2026-102323
- HIGHCVE-2026-102326
- HIGHCVE-2026-102328
- HIGHCVE-2026-102556
- UNSCOREDCVE-2026-102757PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.