DBD::Pg version 3.21.0 for Perl has a heap out-of-bounds write in quote_float.

quote_float() allocates the length of the string + 1, which is the size of the bare numeric symbol plus NULL. But for special literals NaN, Inf, +Inf, -Inf, Infinity, +Infinity, -Infinity it emits the literal surrounded by quotes plus NULL, which is length + 3 bytes. Every recognised literal (case-insensitive) overflows by 2 bytes, a single quote and a NULL.

This can be reached by the $dbh->quote method, for example

$dbh->quote( "Infinity", DBI::SQL_NUMERIC ).

This regression was introduced in 3.21.0 by the quote.c rewrite.
Advisories

No advisories yet.

Fixes

Solution

Upgrade to version 3.21.1 or later.


Workaround

No workaround given by the vendor.

History

Sun, 23 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
Description DBD::Pg version 3.21.0 for Perl has a heap out-of-bounds write in quote_float. quote_float() allocates the length of the string + 1, which is the size of the bare numeric symbol plus NULL. But for special literals NaN, Inf, +Inf, -Inf, Infinity, +Infinity, -Infinity it emits the literal surrounded by quotes plus NULL, which is length + 3 bytes. Every recognised literal (case-insensitive) overflows by 2 bytes, a single quote and a NULL. This can be reached by the $dbh->quote method, for example $dbh->quote( "Infinity", DBI::SQL_NUMERIC ). This regression was introduced in 3.21.0 by the quote.c rewrite.
Title DBD::Pg version 3.21.0 for Perl has a heap out-of-bounds write in quote_float
Weaknesses CWE-787
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: CPANSec

Published:

Updated: 2026-08-23T19:53:18.185Z

Reserved: 2026-08-23T16:38:31.813Z

Link: CVE-2026-78183

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-23T20:16:50.550

Modified: 2026-08-23T20:16:50.550

Link: CVE-2026-78183

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses