Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-4427

Опубликовано: 18 мар. 2026
Источник: redhat
CVSS3: 7.5

Описание

A flaw was found in pgproto3. A malicious or compromised PostgreSQL server can exploit this by sending a DataRow message with a negative field length. This input validation vulnerability can lead to a denial of service (DoS) due to a slice bounds out of range panic.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Assisted Installer for Red Hat OpenShift Container Platform 2rhai/assisted-installer-controller-rhel9Affected
Assisted Installer for Red Hat OpenShift Container Platform 2rhai/assisted-installer-rhel9Affected
Multicluster Engine for Kubernetesmulticluster-engine/assisted-installer-agent-rhel8Affected
Multicluster Engine for Kubernetesmulticluster-engine/assisted-installer-agent-rhel9Affected
Multicluster Engine for Kubernetesmulticluster-engine/assisted-installer-controller-rhel8Affected
Multicluster Engine for Kubernetesmulticluster-engine/assisted-installer-controller-rhel9Affected
Multicluster Engine for Kubernetesmulticluster-engine/assisted-installer-rhel8Affected
Multicluster Engine for Kubernetesmulticluster-engine/assisted-installer-rhel9Affected
Multicluster Engine for Kubernetesmulticluster-engine/assisted-service-8-rhel8Affected
Multicluster Engine for Kubernetesmulticluster-engine/assisted-service-9-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-129
https://bugzilla.redhat.com/show_bug.cgi?id=2448626github.com/jackc/pgproto3: pgproto3: Denial of Service via negative field length in DataRow message

7.5 High

CVSS3

Связанные уязвимости

ubuntu
21 день назад

Rejected reason: Duplicate of CVE-2026-32286

nvd
21 день назад

Rejected reason: Duplicate of CVE-2026-32286

CVSS3: 7.5
github
21 день назад

Duplicate Advisory: pgproto3: Negative field length panics in DataRow.Decode

7.5 High

CVSS3