DBD::Pg version 3.21.0 for Perl has a heap out-of-bounds write in quote_float
Summary
| CVE | CVE-2026-78183 |
|---|---|
| State | PUBLISHED |
| Assigner | CPANSec |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-23 20:16:50 UTC |
| Updated | 2026-08-23 20:16:50 UTC |
| Description | DBD::Pg version 3.21.0 for Perl has a heap out-of-bounds write in quote_float. quote_float() allocates the length of the string + 1, which is the size of the bare numeric symbol plus NULL. But for special literals NaN, Inf, +Inf, -Inf, Infinity, +Infinity, -Infinity it emits the literal surrounded by quotes plus NULL, which is length + 3 bytes. Every recognised literal (case-insensitive) overflows by 2 bytes, a single quote and a NULL. This can be reached by the $dbh->quote method, for example $dbh->quote( "Infinity", DBI::SQL_NUMERIC ). This regression was introduced in 3.21.0 by the quote.c rewrite. |
Risk And Classification
Problem Types: CWE-787 | CWE-787 CWE-787 Out-of-bounds Write
There are no known software configurations currently associated with this CVE in NVD or the CVE Program record.
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| github.com/bucardo/dbdpg/security/advisories/GHSA-785p-fw3v-r822 | 9b29abf9-4ab0-4765-b253-1875cd9b441e | github.com | |
| metacpan.org/release/TURNSTEP/DBD-Pg-3.21.1/source/Changes | 9b29abf9-4ab0-4765-b253-1875cd9b441e | metacpan.org | |
| github.com/bucardo/dbdpg/commit/6d6f47ed2403cda55c82b1bad56e388ba7390065... | 9b29abf9-4ab0-4765-b253-1875cd9b441e | github.com | |
| github.com/bucardo/dbdpg/commit/adacf1de872326a465e13f9e4281a674ebcd227e | 9b29abf9-4ab0-4765-b253-1875cd9b441e | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
Solutions
CNA: Upgrade to version 3.21.1 or later.
There are currently no legacy QID mappings associated with this CVE.