Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-3172

Опубликовано: 25 фев. 2026
Источник: redhat
CVSS3: 6.8
EPSS Низкий

Описание

Buffer overflow in parallel HNSW index build in pgvector 0.6.0 through 0.8.1 allows a database user to leak sensitive data from other relations or crash the database server.

A flaw was found in pgvector. A buffer overflow vulnerability in the parallel Hierarchical Navigable Small World (HNSW) index build process allows a database user to exploit this flaw. This can lead to the disclosure of sensitive data from other database relations or cause the database server to crash, resulting in a denial of service.

Отчет

A buffer overflow during parallel HNSW index builds can be exploited by a database user, potentially leading to information disclosure from other database relations or a denial of service by crashing the database server, although the high impact on availability and confidentiality Red Hat Product Security team has rated this as having a moderate severity. This happens because, besides the low privileges required, to successfully exploit this flaw the attack needs to win a race condition among several worker threads which may be a task considered of a high complexity.

Меры по смягчению последствий

To mitigate this issue, restrict the use of parallel index builds in PostgreSQL. This can be achieved by setting the max_parallel_workers_per_gather parameter to 0 in the postgresql.conf file. This configuration change may impact the performance of other parallel operations within PostgreSQL. A restart of the PostgreSQL service is required for the changes to take effect.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Lightspeedopenshift-lightspeed/lightspeed-ocp-rag-rhel9Fix deferred
Red Hat Enterprise Linux 10postgresql16-pgvectorUnder investigation
Red Hat Enterprise Linux 10postgresql18-pgvectorUnder investigation
Red Hat Enterprise Linux 9postgresql:16/pgvectorUnder investigation
Red Hat Enterprise Linux 9postgresql:18/pgvectorUnder investigation
Red Hat Trusted Profile Analyzerrhtpa/rhtpa-trustification-service-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=2443037pgvector: pgvector: Information disclosure or denial of service via buffer overflow in parallel HNSW index build

EPSS

Процентиль: 18%
0.00263
Низкий

6.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
6 месяцев назад

Buffer overflow in parallel HNSW index build in pgvector 0.6.0 through 0.8.1 allows a database user to leak sensitive data from other relations or crash the database server.

CVSS3: 8.1
nvd
6 месяцев назад

Buffer overflow in parallel HNSW index build in pgvector 0.6.0 through 0.8.1 allows a database user to leak sensitive data from other relations or crash the database server.

CVSS3: 8.1
debian
6 месяцев назад

Buffer overflow in parallel HNSW index build in pgvector 0.6.0 through ...

suse-cvrf
4 месяца назад

Security update for pgvector

suse-cvrf
5 месяцев назад

Security update for pgvector

EPSS

Процентиль: 18%
0.00263
Низкий

6.8 Medium

CVSS3