Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-14668

Опубликовано: 13 авг. 2026
Источник: redhat
CVSS3: 8.1

Описание

Type confusion regarding input of PostgreSQL ctid data type selectivity estimator allows an object creator to view a calculation derived from the value of an arbitrary 4-byte span of memory, via a chosen non-ctid input. While the calculation loses precision, substantial memory value recovery appears possible. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.

A flaw was found in PostgreSQL. This vulnerability, stemming from a type confusion issue in the ctid data type selectivity estimator, could allow an authenticated object creator to access and potentially recover sensitive information from memory. By manipulating input, an attacker could gain unauthorized insight into system memory.

Отчет

An Important-rated information disclosure vulnerability in PostgreSQL allows an authenticated user with object creation privileges to read arbitrary memory spans. By exploiting a type confusion flaw within the ctid selectivity estimator, an attacker can view memory-derived calculations to recover sensitive data. Exploitation is limited to users possessing object creation rights

Меры по смягчению последствий

To mitigate this vulnerability, administrators should enforce the principle of least privilege by revoking CREATE permissions on all databases from untrusted users. Because exploiting this flaw strictly requires the attacker to be an object creator, removing this privilege effectively neutralizes the threat. Ensure only highly trusted administrative roles can create database objects

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10postgresql16Affected
Red Hat Enterprise Linux 10postgresql18Affected
Red Hat Enterprise Linux 6postgresqlNot affected
Red Hat Enterprise Linux 7postgresqlNot affected
Red Hat Enterprise Linux 8postgresql:12/postgresqlAffected
Red Hat Enterprise Linux 8postgresql:15/postgresqlAffected
Red Hat Enterprise Linux 8postgresql:16/postgresqlAffected
Red Hat Enterprise Linux 9postgresqlAffected
Red Hat Enterprise Linux 9postgresql:15/postgresqlAffected
Red Hat Enterprise Linux 9postgresql:16/postgresqlAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-843
https://bugzilla.redhat.com/show_bug.cgi?id=2515326postgresql: PostgreSQL: Information disclosure via type confusion in ctid selectivity estimator

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
около 1 месяца назад

Type confusion regarding input of PostgreSQL ctid data type selectivity estimator allows an object creator to view a calculation derived from the value of an arbitrary 4-byte span of memory, via a chosen non-ctid input. While the calculation loses precision, substantial memory value recovery appears possible. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

CVSS3: 8.1
nvd
около 1 месяца назад

Type confusion regarding input of PostgreSQL ctid data type selectivity estimator allows an object creator to view a calculation derived from the value of an arbitrary 4-byte span of memory, via a chosen non-ctid input. While the calculation loses precision, substantial memory value recovery appears possible. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

CVSS3: 8.1
msrc
около 1 месяца назад

PostgreSQL ctid type confusion in selectivity estimator discloses derivative of arbitrary read

CVSS3: 8.1
debian
около 1 месяца назад

Type confusion regarding input of PostgreSQL ctid data type selectivit ...

CVSS3: 8.1
github
около 1 месяца назад

Type confusion regarding input of PostgreSQL ctid data type selectivity estimator allows an object creator to view a calculation derived from the value of an arbitrary 4-byte span of memory, via a chosen non-ctid input. While the calculation loses precision, substantial memory value recovery appears possible. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.

8.1 High

CVSS3