CVE-2026-15392

NameCVE-2026-15392
DescriptionDBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location. The complete_table_name method builds the absolute table file path without checking whether the file is a symbolic link. A link inside the data directory can point to a table file at any path outside of the configured f_dir and f_dir_search directories. Callers of file-based drivers can read or write files outside of the data directory.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-4764-1, DSA-6473-1
Debian Bugs1142072

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libdbi-perl (PTS)bookworm1.643-4+deb12u1vulnerable
bookworm (security)1.643-4+deb12u2fixed
trixie (security), trixie1.652-2~deb13u1fixed
forky1.652-2fixed
sid1.653-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libdbi-perlsourcebullseye1.643-3+deb11u2DLA-4764-1
libdbi-perlsourcebookworm1.643-4+deb12u2DLA-4764-1
libdbi-perlsourcetrixie1.652-2~deb13u1DSA-6473-1
libdbi-perlsource(unstable)1.651-11142072

Notes

https://lists.security.metacpan.org/cve-announce/msg/41813967/
https://github.com/perl5-dbi/dbi/security/advisories/GHSA-mh3j-xwf4-jrqw
Fixed by: https://github.com/perl5-dbi/dbi/commit/96d62dfe4528bf56fe13f413ed323d4252531728 (1.651)

Search for package or bug name: Reporting problems