Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-14669

Опубликовано: 13 авг. 2026
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosing the timezone to execute arbitrary code as the operating system user running the database, via a long POSIX timezone abbreviation. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.

A heap buffer overflow flaw was found in the PostgreSQL to_char(timestamptz) function. An attacker can exploit this by supplying an overly long POSIX timezone abbreviation to execute arbitrary code as the database's operating system user, potentially resulting in complete system compromise.

Отчет

A heap buffer overflow in PostgreSQL's to_char(timestamptz) function allows an attacker to execute arbitrary code as the database system user by supplying a long POSIX timezone abbreviation. This risk is highest where untrusted users can modify timezone settings.

Меры по смягчению последствий

To reduce the risk of exploitation, ensure that only trusted users have privileges to modify timezone settings within the PostgreSQL database. Additionally, restrict network access to the PostgreSQL server to only trusted clients and applications through firewall rules, limiting the attack surface for remote exploitation.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10postgresql16Affected
Red Hat Enterprise Linux 10postgresql18Affected
Red Hat Enterprise Linux 6postgresqlOut of support scope
Red Hat Enterprise Linux 7postgresqlAffected
Red Hat Enterprise Linux 8postgresql:12/postgresqlAffected
Red Hat Enterprise Linux 8postgresql:15/postgresqlAffected
Red Hat Enterprise Linux 8postgresql:16/postgresqlAffected
Red Hat Enterprise Linux 9postgresqlAffected
Red Hat Enterprise Linux 9postgresql:15/postgresqlAffected
Red Hat Enterprise Linux 9postgresql:16/postgresqlAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=2515317postgresql: PostgreSQL: Arbitrary code execution via long POSIX timezone abbreviation

EPSS

Процентиль: 50%
0.00676
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 1 месяца назад

Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosing the timezone to execute arbitrary code as the operating system user running the database, via a long POSIX timezone abbreviation. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

CVSS3: 8.8
nvd
около 1 месяца назад

Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosing the timezone to execute arbitrary code as the operating system user running the database, via a long POSIX timezone abbreviation. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

CVSS3: 8.8
debian
около 1 месяца назад

Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the par ...

CVSS3: 8.8
github
около 1 месяца назад

Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosing the timezone to execute arbitrary code as the operating system user running the database, via a long POSIX timezone abbreviation. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.

CVSS3: 8.8
fstec
около 1 месяца назад

Уязвимость функции to_char(timestamptz) системы управления базами данных PostgreSQL, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 50%
0.00676
Низкий

8.8 High

CVSS3