Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-16238

Опубликовано: 13 авг. 2026
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

Type confusion in PostgreSQL pg_restore_attribute_stats() allows an object creator to execute arbitrary code as the operating system user running the database, via conflation of range and multirange values. Within major version 18, minor versions before PostgreSQL 18.5 are affected. Versions before PostgreSQL 18 are unaffected.

A flaw was found in PostgreSQL. An object creator can exploit a type confusion vulnerability in the pg_restore_attribute_stats() function. This flaw occurs due to the conflation of range and multirange values, allowing the attacker to execute arbitrary code as the operating system user running the database. This could lead to a complete compromise of the database system.

Отчет

A type confusion flaw in PostgreSQL’s pg_restore_attribute_stats() function allows an authenticated user with object-creation privileges to achieve arbitrary code execution under the database server process (postgres) via crafted range and multirange values. Note: Red Hat Enterprise Linux 9.6 and earlier releases do not ship the vulnerable PostgreSQL major version (18.x) and are therefore not affected.

Меры по смягчению последствий

To mitigate this issue, restrict the ability to create database objects and perform database restorations to only highly trusted administrative users. This operational control limits the attack surface by ensuring that only authorized personnel can introduce potentially malicious objects into the database environment. Carefully manage user privileges to enforce this restriction.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10postgresql16Not affected
Red Hat Enterprise Linux 10postgresql18Affected
Red Hat Enterprise Linux 6postgresqlNot affected
Red Hat Enterprise Linux 7postgresqlNot affected
Red Hat Enterprise Linux 8postgresql:12/postgresqlNot affected
Red Hat Enterprise Linux 8postgresql:15/postgresqlNot affected
Red Hat Enterprise Linux 8postgresql:16/postgresqlNot affected
Red Hat Enterprise Linux 9postgresqlNot affected
Red Hat Enterprise Linux 9postgresql:15/postgresqlNot affected
Red Hat Enterprise Linux 9postgresql:16/postgresqlNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-843
https://bugzilla.redhat.com/show_bug.cgi?id=2515319postgresql: PostgreSQL: Arbitrary code execution via type confusion in pg_restore_attribute_stats()

EPSS

Процентиль: 35%
0.00414
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 1 месяца назад

Type confusion in PostgreSQL pg_restore_attribute_stats() allows an object creator to execute arbitrary code as the operating system user running the database, via conflation of range and multirange values. Within major version 18, minor versions before PostgreSQL 18.6 are affected. Versions before PostgreSQL 18 are unaffected.

CVSS3: 8.8
nvd
около 1 месяца назад

Type confusion in PostgreSQL pg_restore_attribute_stats() allows an object creator to execute arbitrary code as the operating system user running the database, via conflation of range and multirange values. Within major version 18, minor versions before PostgreSQL 18.6 are affected. Versions before PostgreSQL 18 are unaffected.

msrc
25 дней назад

PostgreSQL type confusion in pg_restore_attribute_stats() executes arbitrary code

CVSS3: 8.8
debian
около 1 месяца назад

Type confusion in PostgreSQL pg_restore_attribute_stats() allows an ob ...

CVSS3: 8.8
github
около 1 месяца назад

Type confusion in PostgreSQL pg_restore_attribute_stats() allows an object creator to execute arbitrary code as the operating system user running the database, via conflation of range and multirange values. Within major version 18, minor versions before PostgreSQL 18.5 are affected. Versions before PostgreSQL 18 are unaffected.

EPSS

Процентиль: 35%
0.00414
Низкий

8.8 High

CVSS3