Olamilekan Abdullateef Ajani
unread,Sep 16, 2026, 11:55:43 AM (6 days ago) Sep 16Sign in to reply to author
Sign in to forward
You do not have permission to delete messages in this group
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to Wazuh | Mailing List
Hello,
Thank you for reporting this. I checked the Red Hat advisories, and this does appear to be a false-positive detection.
Red Hat addressed CVE-2026-9698 for the perl-DBI:1.641 module in 1.641-5.module+el8.10.0+24438... through RHSA-2026:38901. Your installed version, 1.641-8.module+el8.10.0+24620+2953b6e4, is a newer Red Hat build published under RHSA-2026:52772.
The CTI page currently shows an unbounded "All affected" entry and a separate fixed threshold for the non-modular package, but it does not show the fixed threshold for the modular stream. That unbounded entry is likely causing the package to remain detected as vulnerable.
I will pass this along to the team internally for review. However, could you also confirm that the vulnerability is still shown as Active in the Wazuh dashboard and share the output of the following command?
rpm -q perl-DBI --qf '%{NAME}-%{EPOCHNUM}:%{VERSION}-%{RELEASE}.%{ARCH}\nModule: %{MODULARITYLABEL}\n'
Thanks again for sharing this.