{"id":"CVE-2026-78183","aliases":["GHSA-785p-fw3v-r822"],"url":"https://o3.security/vulnerability/CVE-2026-78183","summary":"DBD::Pg version 3.21.0 for Perl has a heap out-of-bounds write in quote_float","details":"DBD::Pg version 3.21.0 for Perl has a heap out-of-bounds write in quote_float.\n\nquote_float() allocates the length of the string + 1, which is the size of the bare numeric symbol plus NULL.  But for special literals NaN, Inf, +Inf, -Inf, Infinity, +Infinity, -Infinity it emits the literal surrounded by quotes plus NULL, which is length + 3 bytes. Every recognised literal (case-insensitive) overflows by 2 bytes, a single quote and a NULL.\n\nThis can be reached by the $dbh->quote method, for example\n\n    $dbh->quote( \"Infinity\", DBI::SQL_NUMERIC ).\n\nThis regression was introduced in 3.21.0 by the quote.c rewrite.","published":"2026-08-23T19:53:18.185Z","modified":"2026-08-26T01:42:11.746683Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/bucardo/dbdpg/commit/6d6f47ed2403cda55c82b1bad56e388ba7390065.patch","label":"bucardo/dbdpg@6d6f47e"},"references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/08/23/5"},{"type":"WEB","url":"https://cpan.org/modules"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/78xxx/CVE-2026-78183.json"},{"type":"ADVISORY","url":"https://github.com/bucardo/dbdpg/security/advisories/GHSA-785p-fw3v-r822"},{"type":"ADVISORY","url":"https://metacpan.org/release/TURNSTEP/DBD-Pg-3.21.1/source/Changes"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-78183"},{"type":"FIX","url":"https://github.com/bucardo/dbdpg/commit/6d6f47ed2403cda55c82b1bad56e388ba7390065.patch"},{"type":"FIX","url":"https://github.com/bucardo/dbdpg/commit/adacf1de872326a465e13f9e4281a674ebcd227e"},{"type":"PACKAGE","url":"https://github.com/bucardo/dbdpg"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-26T01:42:11.746683Z"}}