Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-14676

Опубликовано: 13 авг. 2026
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

Heap buffer overflow in PostgreSQL pg_stat_statements allows the query author to execute arbitrary code as the operating system user running the database, via crafted queries containing array constants. Within major version 18, minor versions before PostgreSQL 18.5 are affected. Versions before PostgreSQL 18 are unaffected.

A flaw was found in PostgreSQL pg_stat_statements. A local attacker, specifically a query author, could exploit a heap buffer overflow vulnerability by crafting special queries containing array constants. This could allow the attacker to execute arbitrary code as the operating system user running the database, leading to a complete compromise of the database system.

Отчет

An Important heap buffer overflow flaw was identified in the PostgreSQL pg_stat_statements extension. This vulnerability allows an authenticated database user to execute arbitrary code as the database's operating system user by submitting specially crafted SQL queries. The pg_stat_statements extension must be loaded (via shared_preload_libraries) for the vulnerability to be exploitable.

Меры по смягчению последствий

If upgrading to PostgreSQL 18.5 or later is not immediately possible, the pg_stat_statements extension can be disabled as a workaround. Remove 'pg_stat_statements' from the shared_preload_libraries parameter in postgresql.conf and restart the PostgreSQL service. This disables query statistics tracking but fully eliminates the attack surface for this vulnerability, as the heap buffer overflow exists exclusively within the pg_stat_statements query-normalization code path and is not reachable when the extension is not loaded. Additionally, limiting database access to trusted, vetted users reduces exposure, though it does not eliminate the risk for any authenticated user who can submit arbitrary queries.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10postgresql16Not affected
Red Hat Enterprise Linux 10postgresql18Affected
Red Hat Enterprise Linux 6postgresqlNot affected
Red Hat Enterprise Linux 7postgresqlNot affected
Red Hat Enterprise Linux 8postgresql:12/postgresqlNot affected
Red Hat Enterprise Linux 8postgresql:15/postgresqlNot affected
Red Hat Enterprise Linux 8postgresql:16/postgresqlNot affected
Red Hat Enterprise Linux 9postgresqlNot affected
Red Hat Enterprise Linux 9postgresql:15/postgresqlNot affected
Red Hat Enterprise Linux 9postgresql:16/postgresqlNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2515324postgresql: PostgreSQL pg_stat_statements: Arbitrary code execution via heap buffer overflow

EPSS

Процентиль: 36%
0.00427
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 1 месяца назад

Heap buffer overflow in PostgreSQL pg_stat_statements allows the query author to execute arbitrary code as the operating system user running the database, via crafted queries containing array constants. Within major version 18, minor versions before PostgreSQL 18.6 are affected. Versions before PostgreSQL 18 are unaffected.

CVSS3: 8.8
nvd
около 1 месяца назад

Heap buffer overflow in PostgreSQL pg_stat_statements allows the query author to execute arbitrary code as the operating system user running the database, via crafted queries containing array constants. Within major version 18, minor versions before PostgreSQL 18.6 are affected. Versions before PostgreSQL 18 are unaffected.

CVSS3: 8.8
debian
около 1 месяца назад

Heap buffer overflow in PostgreSQL pg_stat_statements allows the query ...

CVSS3: 8.8
github
около 1 месяца назад

Heap buffer overflow in PostgreSQL pg_stat_statements allows the query author to execute arbitrary code as the operating system user running the database, via crafted queries containing array constants. Within major version 18, minor versions before PostgreSQL 18.5 are affected. Versions before PostgreSQL 18 are unaffected.

CVSS3: 8.8
fstec
около 1 месяца назад

Уязвимость расширения pg_stat_statements системы управления базами данных PostgreSQL, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 36%
0.00427
Низкий

8.8 High

CVSS3