quote_float() allocates the length of the string + 1, which is the size of the bare numeric symbol plus NULL. But for special literals NaN, Inf, +Inf, -Inf, Infinity, +Infinity, -Infinity it emits the literal surrounded by quotes plus NULL, which is length + 3 bytes. Every recognised literal (case-insensitive) overflows by 2 bytes, a single quote and a NULL.
This can be reached by the $dbh->quote method, for example
$dbh->quote( "Infinity", DBI::SQL_NUMERIC ).
This regression was introduced in 3.21.0 by the quote.c rewrite.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade to version 3.21.1 or later.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 25 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 24 Aug 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Bucardo
Bucardo dbdpg |
|
| Vendors & Products |
Bucardo
Bucardo dbdpg |
Sun, 23 Aug 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Sun, 23 Aug 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | DBD::Pg version 3.21.0 for Perl has a heap out-of-bounds write in quote_float. quote_float() allocates the length of the string + 1, which is the size of the bare numeric symbol plus NULL. But for special literals NaN, Inf, +Inf, -Inf, Infinity, +Infinity, -Infinity it emits the literal surrounded by quotes plus NULL, which is length + 3 bytes. Every recognised literal (case-insensitive) overflows by 2 bytes, a single quote and a NULL. This can be reached by the $dbh->quote method, for example $dbh->quote( "Infinity", DBI::SQL_NUMERIC ). This regression was introduced in 3.21.0 by the quote.c rewrite. | |
| Title | DBD::Pg version 3.21.0 for Perl has a heap out-of-bounds write in quote_float | |
| Weaknesses | CWE-787 | |
| References |
|
|
Status: PUBLISHED
Assigner: CPANSec
Published:
Updated: 2026-08-25T19:32:39.393Z
Reserved: 2026-08-23T16:38:31.813Z
Link: CVE-2026-78183
Updated: 2026-08-23T23:04:55.125Z
Status : Deferred
Published: 2026-08-23T20:16:50.550
Modified: 2026-08-26T16:51:19.490
Link: CVE-2026-78183
No data.
OpenCVE Enrichment
Updated: 2026-08-26T04:30:16Z