Skip to content

GHSA-ww49-w4mv-jrr4 on CTRL-OS 26.05

Aliases: GHSA-ww49-w4mv-jrr4, CVE-2026-60081

Packages: perlPackages.DBI

Status: Plausible

Advisory Information

DBI::ProfileData parses a profile-dump file line by line. A + N key line supplies the path slot N, which is trusted directly into $#path = $index at ProfileData.pm:290 with no upper bound. A single line such as + 100000000 x expands @path into a giant sparse array, which the next data line then materialises via join("\0", @path) (:317) and copies with push(@$nodes, [ @data, @path ]) (:326) — a tiny input to a large-memory/large-logging primitive (CWE-400).

The parser input is a file path. dbiprof passes its command-line arguments straight into DBI::ProfileData->new(Files => ...) (dbiprof.PL:64), so any workflow that runs the profile parser over a dump crossing a trust boundary — support bundles, CI/observability pipelines, hosted profile-report tooling — is exposed.

Impact is denial of service against the parsing process: a 137-byte profile with + 10000000 exits under a 128 MB cgroup; a smaller + 100000 produces ~99,998 warnings and ~99 MB RSS growth from a few bytes. No RCE and not a normal database-input path, hence low severity.

Fix: reject a zero/negative or implausibly large index before mutating @path (a generous MAX_PATH_DEPTH with a malformed-profile croak). One-line guard at ProfileData.pm:290.

Updates

2026-07-14 17:14 CEST

Metadata changes:

  • Status for package perlPackages.DBI: “Plausible

(Amended on: 2026-07-14 17:15 CEST)

2026-07-14 16:15 CEST

Metadata changes:

  • Status for package perlPackages.DBI: “New