databases/p5-DBI: update 1.648 -> 1.654
Changelog: https://metacpan.org/dist/DBI/changes
Major changes for 1.650:
- Set a hard limit of 99999 on '?' placeholders (CVE-2026-14739)
- Fix out-of-bounds read in preparse of SQL that starts with a comment (CVE-2026-14740)
- Fix code injection via Profile DSN attribute or DBI_PROFILE variable (CVE-2026-14380)
Major changes for 1.651:
- Fix inverted comparisons for strings in DBI::SQL::Nano (CVE-2026-15043)
- Fix DBD::File to ensure that the table is not a symlink outside of f_dir (CVE-2026-15392)
- Fix an out-of-bounds error when a statement handle has no fields but the source row is not empty (CVE-2026-60082)
- Add an overridable upper bound $MAX_PATH_DEPTH for DBI::ProfileData (CVE-2026-60081)
Major changes for 1.652:
- require perl >= 5.12
- Force placeholder limit on :# and :p# too (CVE-2026-73194)
- Limit statements to 292 Mb in preparse (CVE-2026-73193)
- Add a security policy (issue#174)
Major changes for 1.653:
- Fix arbitrary module and file loading via dbm_type/dbm_mldbm (CVE-2026-78030)
- Tighten symlink outside of f_dir (CVE-2026-15392) check (reported by Raj)
Major changes for 1.654:
- Fix DBI::sql_type_cast on IV/NV (CVE-2026-88815) (reported by Raj)
- Fix FetchHashKeyName on IV/NV (CVE-2026-88816) (reported by Raj)
Security: CVE-2026-14380
Security: CVE-2026-14739
Security: CVE-2026-14740
Security: CVE-2026-15043
Security: CVE-2026-15392
Security: CVE-2026-15392
Security: CVE-2026-60081
Security: CVE-2026-60082
Security: CVE-2026-73193
Security: CVE-2026-73194
Security: CVE-2026-78030
Security: CVE-2026-88815
Security: CVE-2026-88816