Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-ph64-qjwg-mxwq

Опубликовано: 13 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

Type confusion regarding input of PostgreSQL ctid data type selectivity estimator allows an object creator to view a calculation derived from the value of an arbitrary 4-byte span of memory, via a chosen non-ctid input. While the calculation loses precision, substantial memory value recovery appears possible. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.

Type confusion regarding input of PostgreSQL ctid data type selectivity estimator allows an object creator to view a calculation derived from the value of an arbitrary 4-byte span of memory, via a chosen non-ctid input. While the calculation loses precision, substantial memory value recovery appears possible. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.

EPSS

Процентиль: 39%
0.00464
Низкий

8.1 High

CVSS3

Дефекты

CWE-843

Связанные уязвимости

CVSS3: 8.1
ubuntu
11 дней назад

Type confusion regarding input of PostgreSQL ctid data type selectivity estimator allows an object creator to view a calculation derived from the value of an arbitrary 4-byte span of memory, via a chosen non-ctid input. While the calculation loses precision, substantial memory value recovery appears possible. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.

CVSS3: 8.1
nvd
11 дней назад

Type confusion regarding input of PostgreSQL ctid data type selectivity estimator allows an object creator to view a calculation derived from the value of an arbitrary 4-byte span of memory, via a chosen non-ctid input. While the calculation loses precision, substantial memory value recovery appears possible. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.

msrc
9 дней назад

PostgreSQL ctid type confusion in selectivity estimator discloses derivative of arbitrary read

CVSS3: 8.1
debian
11 дней назад

Type confusion regarding input of PostgreSQL ctid data type selectivit ...

CVSS3: 8.1
fstec
11 дней назад

Уязвимость оценщика селективности типа данных ctid системы управления базами данных PostgreSQL, связанная с неверным сроком действия сеанса, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 39%
0.00464
Низкий

8.1 High

CVSS3

Дефекты

CWE-843