DSA-6473-1 libdbi-perl - security update
Several vulnerabilities were discovered in libdbi-perl, a Perl framework that provides a common interface to access various backend databases in a uniform manner, which could result in denial of service, path traversal, bypass of file-backed filters or the execution of arbitrary code. https://security-tracker.debian.org/tracker/DSA-6473-1
CSIRTS triage
- What
- Multiple vulnerabilities in libdbi-perl allow denial of service, path traversal, filter bypass, and arbitrary code execution.
- Who is affected
- All systems using libdbi-perl for database access are affected.
- Urgency
- High urgency due to potential arbitrary code execution capability.
- Action
- Apply the security update DSA-6473-1 from Debian.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch libdbi-perl
Get an email when a new libdbi-perl advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://lists.debian.org/debian-security-announce/2026/msg00384.html
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-143800.52% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 42% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-147390.41% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 35% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-147400.39% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 32% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-150430.39% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 32% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-153920.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-600810.36% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 30% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-600820.39% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 32% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-731930.48% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 40% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-731940.49% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 41% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-14380 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-14739 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-14740 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-15043 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-15392 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-60081 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-60082 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-73193 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-73194 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[UPDATE] [hoch] Red Hat Enterprise Linux (DBI, perl-GD): Mehrere Schwachstellencert-bund
- highexploited[UPDATE] [hoch] IBM QRadar SIEM: Mehrere Schwachstellencert-bund
- unknownexploitedMultiples vulnérabilités dans les produits IBM (28 août 2026)cert-fr-avis
- criticalCVE-2026-73194: DBI versions before 1.652 for Perl allow a heap out-of-bounds write via an unvalidated numeric…nvd
- criticalCVE-2026-73193: DBI versions before 1.652 for Perl allow a heap out-of-bounds write on 32-bit perl via an inte…nvd
- criticalCVE-2026-73194: DBI versions before 1.652 for Perl allow a heap out-of-bounds write via an unvalidated numeric…msrc
- unknownMultiple vulnerabilities in Microsoft Azure Linux (July 15, 2026)cert-fr-avis
- criticalCVE-2026-60082: DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row. W…nvd
- highCVE-2026-60081: DBI::ProfileData versions before 1.651 for Perl do not limit the path index. The path index co…nvd
- highCVE-2026-15392: DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an u…nvd
- criticalCVE-2026-15043: DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted = SQL operators on text.…nvd
- highCVE-2026-15392: DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an u…msrc
More from Debian Security Advisories
- highDSA-6496-1 nginx - security update2026-09-12
- unknownDSA-6497-1 xorg-server - security update2026-09-12
- unknownDSA-6495-1 spip - security update2026-09-11
- unknownDSA-6494-1 kamailio - security update2026-09-11
- unknownDSA-6493-1 libevent - security update2026-09-11