Описание
Heap buffer overflow in PostgreSQL pg_stat_statements allows the query author to execute arbitrary code as the operating system user running the database, via crafted queries containing array constants. Within major version 18, minor versions before PostgreSQL 18.5 are affected. Versions before PostgreSQL 18 are unaffected.
A flaw was found in PostgreSQL pg_stat_statements. A local attacker, specifically a query author, could exploit a heap buffer overflow vulnerability by crafting special queries containing array constants. This could allow the attacker to execute arbitrary code as the operating system user running the database, leading to a complete compromise of the database system.
Отчет
An Important heap buffer overflow flaw was identified in the PostgreSQL pg_stat_statements extension. This vulnerability allows an authenticated database user to execute arbitrary code as the database's operating system user by submitting specially crafted SQL queries. The pg_stat_statements extension must be loaded (via shared_preload_libraries) for the vulnerability to be exploitable.
Меры по смягчению последствий
If upgrading to PostgreSQL 18.5 or later is not immediately possible, the pg_stat_statements extension can be disabled as a workaround. Remove 'pg_stat_statements' from the shared_preload_libraries parameter in postgresql.conf and restart the PostgreSQL service. This disables query statistics tracking but fully eliminates the attack surface for this vulnerability, as the heap buffer overflow exists exclusively within the pg_stat_statements query-normalization code path and is not reachable when the extension is not loaded. Additionally, limiting database access to trusted, vetted users reduces exposure, though it does not eliminate the risk for any authenticated user who can submit arbitrary queries.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | postgresql16 | Not affected | ||
| Red Hat Enterprise Linux 10 | postgresql18 | Affected | ||
| Red Hat Enterprise Linux 6 | postgresql | Not affected | ||
| Red Hat Enterprise Linux 7 | postgresql | Not affected | ||
| Red Hat Enterprise Linux 8 | postgresql:12/postgresql | Not affected | ||
| Red Hat Enterprise Linux 8 | postgresql:15/postgresql | Not affected | ||
| Red Hat Enterprise Linux 8 | postgresql:16/postgresql | Not affected | ||
| Red Hat Enterprise Linux 9 | postgresql | Not affected | ||
| Red Hat Enterprise Linux 9 | postgresql:15/postgresql | Not affected | ||
| Red Hat Enterprise Linux 9 | postgresql:16/postgresql | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
8.8 High
CVSS3
Связанные уязвимости
Heap buffer overflow in PostgreSQL pg_stat_statements allows the query author to execute arbitrary code as the operating system user running the database, via crafted queries containing array constants. Within major version 18, minor versions before PostgreSQL 18.6 are affected. Versions before PostgreSQL 18 are unaffected.
Heap buffer overflow in PostgreSQL pg_stat_statements allows the query author to execute arbitrary code as the operating system user running the database, via crafted queries containing array constants. Within major version 18, minor versions before PostgreSQL 18.6 are affected. Versions before PostgreSQL 18 are unaffected.
Heap buffer overflow in PostgreSQL pg_stat_statements allows the query ...
Heap buffer overflow in PostgreSQL pg_stat_statements allows the query author to execute arbitrary code as the operating system user running the database, via crafted queries containing array constants. Within major version 18, minor versions before PostgreSQL 18.5 are affected. Versions before PostgreSQL 18 are unaffected.
Уязвимость расширения pg_stat_statements системы управления базами данных PostgreSQL, позволяющая нарушителю выполнить произвольный код
EPSS
8.8 High
CVSS3