Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-6469

Опубликовано: 13 авг. 2026
Источник: redhat
CVSS3: 3.8
EPSS Низкий

Описание

Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of dependent statistics objects to the current user. This wrongly allows the table owner to run DROP STATISTICS and ALTER STATISTICS via this improper ownership. It wrongly denies those commands to the prior statistics object owner. DROP TABLE remains able to remove statistics objects, so this exploit achieves nothing in many ownership arrangements. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.

A flaw was found in PostgreSQL where the ALTER TABLE ALTER TYPE command incorrectly reassigns ownership of dependent statistics objects to the current user. This grants the table owner unauthorized privileges to execute DROP STATISTICS and ALTER STATISTICS while locking out the legitimate owner. The overall impact is limited, as standard DROP TABLE operations still correctly remove the affected objects.

Отчет

This flaw has a Low impact on Red Hat products. It provides minimal privilege escalation, as the improperly granted abilities (DROP STATISTICS and ALTER STATISTICS via ALTER TABLE ALTER TYPE) occur within an already highly privileged context where the table owner can simply use DROP TABLE to remove the statistics objects.

Меры по смягчению последствий

To mitigate this, limit the ALTER TABLE ALTER TYPE command to trusted database users. If the command must be used, manually review and restore the correct ownership of any affected extended statistics objects. Additionally, relying on standard DROP TABLE commands for routine object removal safely avoids the primary impacts of this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10postgresql16Fix deferred
Red Hat Enterprise Linux 10postgresql18Fix deferred
Red Hat Enterprise Linux 6postgresqlNot affected
Red Hat Enterprise Linux 7postgresqlNot affected
Red Hat Enterprise Linux 8postgresql:12/postgresqlFix deferred
Red Hat Enterprise Linux 8postgresql:15/postgresqlFix deferred
Red Hat Enterprise Linux 8postgresql:16/postgresqlFix deferred
Red Hat Enterprise Linux 9postgresqlFix deferred
Red Hat Enterprise Linux 9postgresql:15/postgresqlFix deferred
Red Hat Enterprise Linux 9postgresql:16/postgresqlFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-708
https://bugzilla.redhat.com/show_bug.cgi?id=2515331postgresql: PostgreSQL: Incorrect ownership assignment allows unauthorized statistics modification

EPSS

Процентиль: 8%
0.00188
Низкий

3.8 Low

CVSS3

Связанные уязвимости

CVSS3: 3.8
ubuntu
около 1 месяца назад

Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of dependent statistics objects to the current user. This wrongly allows the table owner to run DROP STATISTICS and ALTER STATISTICS via this improper ownership. It wrongly denies those commands to the prior statistics object owner. DROP TABLE remains able to remove statistics objects, so this exploit achieves nothing in many ownership arrangements. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

CVSS3: 3.8
nvd
около 1 месяца назад

Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of dependent statistics objects to the current user. This wrongly allows the table owner to run DROP STATISTICS and ALTER STATISTICS via this improper ownership. It wrongly denies those commands to the prior statistics object owner. DROP TABLE remains able to remove statistics objects, so this exploit achieves nothing in many ownership arrangements. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

CVSS3: 3.8
msrc
около 1 месяца назад

PostgreSQL ALTER TABLE ALTER TYPE resets extended statistics ownership

CVSS3: 3.8
debian
около 1 месяца назад

Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE co ...

CVSS3: 3.8
github
около 1 месяца назад

Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of dependent statistics objects to the current user. This wrongly allows the table owner to run DROP STATISTICS and ALTER STATISTICS via this improper ownership. It wrongly denies those commands to the prior statistics object owner. DROP TABLE remains able to remove statistics objects, so this exploit achieves nothing in many ownership arrangements. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.

EPSS

Процентиль: 8%
0.00188
Низкий

3.8 Low

CVSS3