PT-2026-40918 · Postgresql Global Development Group+4 · Postgresql+3

·

CVE-2026-6473

·

Published

2026-05-14

·

Updated

2026-07-06

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PostgreSQL versions prior to 18.4 PostgreSQL versions prior to 17.10 PostgreSQL versions prior to 16.14 PostgreSQL versions prior to 15.18 PostgreSQL versions prior to 14.23
Description Integer wraparound in multiple server features allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds. This can lead to arbitrary code execution as the operating system user running the database. In applications that pass gigabyte-scale user inputs to the relevant database functions, the input provider may cause a segmentation fault, which is an error occurring when a program attempts to access a memory location that it is not allowed to access.
Recommendations Update to version 18.4 or later. Update to version 17.10 or later. Update to version 16.14 or later. Update to version 15.18 or later. Update to version 14.23 or later.

Fix

DoS

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:26181
ALSA-2026:26203
ALSA-2026:26204
ALSA-2026:27738
ALSA-2026:27741
ALSA-2026:27743
ALSA-2026:28037
ALSA-2026:28143
ALSA-2026:28999
BDU:2026-07102
BIT-POSTGRESQL-2026-6473
CVE-2026-6473
ECHO-A6F1-A1C7-A609
JLSEC-2026-601
OESA-2026-2381
OESA-2026-2382
OESA-2026-2413
OESA-2026-2414
OESA-2026-2479
OPENSUSE-SU-2026:10806-1
OPENSUSE-SU-2026:10807-1
OPENSUSE-SU-2026:10808-1
OPENSUSE-SU-2026:10809-1
OPENSUSE-SU-2026:10828-1
OPENSUSE-SU-2026:20970-1
OPENSUSE-SU-2026:21102-1
OPENSUSE-SU-2026:21103-1
OPENSUSE-SU-2026:21104-1
RHSA-2026:22878
RHSA-2026:26181
RHSA-2026:26203
RHSA-2026:26204
RHSA-2026:26524
RHSA-2026:26525
RHSA-2026:26561
RHSA-2026:27718
RHSA-2026:27738
RHSA-2026:27741
RHSA-2026:27742
RHSA-2026:27743
RHSA-2026:28037
RHSA-2026:28143
RHSA-2026:28208
RHSA-2026:28999
RHSA-2026:29212
RHSA-2026:29815
RHSA-2026:29904
RHSA-2026:29953
RHSA-2026:32983
RHSA-2026:32994
RHSA-2026:33441
RHSA-2026:33497
RHSA-2026:34043
RHSA-2026:34362
RHSA-2026:34363
RHSA-2026:35880
SUSE-SU-2026:22077-1
SUSE-SU-2026:22149-1
SUSE-SU-2026:22177-1
SUSE-SU-2026:22183-1
SUSE-SU-2026:22184-1
USN-8294-1

Affected Products

Linuxmint
Postgresql
Rocky Linux
Ubuntu