Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-14679

Опубликовано: 13 авг. 2026
Источник: redhat
CVSS3: 7.1

Описание

Stack buffer overflow in PostgreSQL argument name matching allows an object creator to achieve unknown impacts via OUT parameter count. The attack can write only 0x0 and 0x1 bytes. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.

A flaw was found in PostgreSQL. An object creator can exploit a stack buffer overflow vulnerability within the argument name matching component. By manipulating the OUT parameter count, an attacker can write limited arbitrary bytes (0x0 and 0x1) to server memory, which may lead to unknown impacts.

Отчет

This Important PostgreSQL stack buffer overflow allows an authenticated object creator to trigger unknown impacts by manipulating OUT parameter counts. While requiring existing database privileges, successful exploitation could lead to service disruption and minor data integrity issues, elevating the risk beyond a Moderate classification.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10postgresql16Affected
Red Hat Enterprise Linux 10postgresql18Affected
Red Hat Enterprise Linux 6postgresqlOut of support scope
Red Hat Enterprise Linux 7postgresqlAffected
Red Hat Enterprise Linux 8postgresql:12/postgresqlAffected
Red Hat Enterprise Linux 8postgresql:15/postgresqlAffected
Red Hat Enterprise Linux 8postgresql:16/postgresqlAffected
Red Hat Enterprise Linux 9postgresqlAffected
Red Hat Enterprise Linux 9postgresql:15/postgresqlAffected
Red Hat Enterprise Linux 9postgresql:16/postgresqlAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-121
https://bugzilla.redhat.com/show_bug.cgi?id=2515321postgresql: PostgreSQL: Stack buffer overflow via OUT parameter count manipulation

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.2
ubuntu
около 1 месяца назад

Stack buffer overflow in PostgreSQL argument name matching allows an object creator to achieve unknown impacts via OUT parameter count. The attack can write only 0x0 and 0x1 bytes. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

CVSS3: 8.2
nvd
около 1 месяца назад

Stack buffer overflow in PostgreSQL argument name matching allows an object creator to achieve unknown impacts via OUT parameter count. The attack can write only 0x0 and 0x1 bytes. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

CVSS3: 8.2
debian
около 1 месяца назад

Stack buffer overflow in PostgreSQL argument name matching allows an o ...

CVSS3: 8.2
github
около 1 месяца назад

Stack buffer overflow in PostgreSQL argument name matching allows an object creator to achieve unknown impacts via OUT parameter count. The attack can write only 0x0 and 0x1 bytes. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.

CVSS3: 8.2
fstec
около 1 месяца назад

Уязвимость системы управления базами данных PostgreSQL, связанная с переполнением буфера в динамической памяти, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании

7.1 High

CVSS3