Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
This update for perl-DBI fixes the following issues:
- CVE-2026-15392: failure to validate symbolic links during table path resolution could allow unauthorized file reads
and writes outside the configured data director (bsc#1271629).
- CVE-2026-15043: `DBI:SQL:Nano` has incorrect predicate evaluation, which allows for bypass of file-backed filters
(bsc#1271399).
- CVE-2026-60081: `DBI:ProfileData` does not limit the path index in profile parser, which enables small-file
memory-amplification DoS (bsc#1271458).
- CVE-2026-60082: out-of-bounds access in `_set_fbav` when a statement handle has zero fields but a non-empty row,
which allows for a process crash (bsc#1271459).
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-1322=1
- openSUSE Leap 16.0:
perl-DBI-1.647.0-160000.5.1
* bsc#1271399
* bsc#1271458
* bsc#1271459
* bsc#1271629
References:
* https://www.suse.com/security/cve/CVE-2026-15043.html
* https://www.suse.com/security/cve/CVE-2026-15392.html
* https://www.suse.com/security/cve/CVE-2026-60081.html
* https://www.suse.com/security/cve/CVE-2026-60082.html
Get the latest Linux and open source security news straight to your inbox.