PT-2026-7847 · Unknown+2 · Postgresql+1

·

CVE-2026-2007

·

Published

2026-01-01

·

Updated

2026-05-19

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:N/C:N/I:P/A:C
Name of the Vulnerable Software and Affected Versions PostgreSQL versions 18.0 and 18.1
Description A heap buffer overflow exists in PostgreSQL's pg trgm component. A database user can exploit this issue with a crafted input string, potentially leading to unknown impacts, including possible privilege escalation. The attacker has limited control over the data written to memory.
Recommendations Update PostgreSQL to a version beyond 18.1.

Fix

LPE

DoS

Buffer Overflow

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:19009
BDU:2026-01724
BIT-POSTGRESQL-2026-2007
CVE-2026-2007
MGASA-2026-0041
OPENSUSE-SU-2026:10197-1
OPENSUSE-SU-2026:20408-1
RHSA-2026:8756
SUSE-SU-2026:0584-1
SUSE-SU-2026:0585-1
SUSE-SU-2026:0881-1
SUSE-SU-2026:20921-1

Affected Products

Postgresql
Red Os