Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-16241

Опубликовано: 13 авг. 2026
Источник: redhat
CVSS3: 3.8

Описание

Integer underflow in PostgreSQL ECPG allows a database server administrator to achieve temporary denial of service against the ECPG client via sending a bytea value lacking the mandatory prefix. The client overwrites a huge memory region with bytes outside attacker knowledge or control. This typically yields a simple SIGSEGV, but rare cases might achieve client-specific integrity impact via the write. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.

A flaw was found in PostgreSQL ECPG. A highly privileged database server administrator can trigger an integer underflow by sending a specially crafted bytea value to the ECPG client. This vulnerability causes the client to overwrite a large memory region, leading to a temporary denial of service (DoS). In rare cases, this could also result in client-specific data integrity issues.

Отчет

This Low impact flaw in PostgreSQL ECPG affects client applications. It requires a highly privileged database administrator to send a malformed bytea value, leading to an integer underflow and a temporary denial of service in the ECPG client. The limited scope to client-side disruption and the prerequisite of elevated server privileges contribute to its lower severity.

Меры по смягчению последствий

To mitigate this vulnerability, ensure that database server administrator privileges are tightly controlled and only granted to highly trusted individuals. Because exploiting this flaw requires an attacker to already have administrative control over the database server to target connecting ECPG clients, adhering to the principle of least privilege and maintaining strict access controls on server administration effectively neutralizes the risk.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10postgresql16Fix deferred
Red Hat Enterprise Linux 10postgresql18Fix deferred
Red Hat Enterprise Linux 6postgresqlNot affected
Red Hat Enterprise Linux 7postgresqlNot affected
Red Hat Enterprise Linux 8postgresql:12/postgresqlFix deferred
Red Hat Enterprise Linux 8postgresql:15/postgresqlFix deferred
Red Hat Enterprise Linux 8postgresql:16/postgresqlFix deferred
Red Hat Enterprise Linux 9postgresqlFix deferred
Red Hat Enterprise Linux 9postgresql:15/postgresqlFix deferred
Red Hat Enterprise Linux 9postgresql:16/postgresqlFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-191
https://bugzilla.redhat.com/show_bug.cgi?id=2515320postgresql: PostgreSQL ECPG: Denial of Service via integer underflow

3.8 Low

CVSS3

Связанные уязвимости

CVSS3: 3.8
ubuntu
около 1 месяца назад

Integer underflow in PostgreSQL ECPG allows a database server administrator to achieve temporary denial of service against the ECPG client via sending a bytea value lacking the mandatory prefix. The client overwrites a huge memory region with bytes outside attacker knowledge or control. This typically yields a simple SIGSEGV, but rare cases might achieve client-specific integrity impact via the write. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

CVSS3: 3.8
nvd
около 1 месяца назад

Integer underflow in PostgreSQL ECPG allows a database server administrator to achieve temporary denial of service against the ECPG client via sending a bytea value lacking the mandatory prefix. The client overwrites a huge memory region with bytes outside attacker knowledge or control. This typically yields a simple SIGSEGV, but rare cases might achieve client-specific integrity impact via the write. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

CVSS3: 3.8
debian
около 1 месяца назад

Integer underflow in PostgreSQL ECPG allows a database server administ ...

CVSS3: 3.8
github
около 1 месяца назад

Integer underflow in PostgreSQL ECPG allows a database server administrator to achieve temporary denial of service against the ECPG client via sending a bytea value lacking the mandatory prefix. The client overwrites a huge memory region with bytes outside attacker knowledge or control. This typically yields a simple SIGSEGV, but rare cases might achieve client-specific integrity impact via the write. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.

CVSS3: 3.8
fstec
около 1 месяца назад

Уязвимость ECPG-клиента системы управления базами данных PostgreSQL, позволяющая нарушителю вызвать отказ в обслуживании

3.8 Low

CVSS3