Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-6470

Опубликовано: 13 авг. 2026
Источник: redhat
CVSS3: 4.3

Описание

Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of service against ALTER and DROP of the type, via creating a dependency on the type. Many DDL operations did check the privilege, but assigning a range subtype and referencing the type from an SQL expression did not. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.

A flaw was found in PostgreSQL where missing authorization checks in DDL commands allow an authenticated user to create unauthorized dependencies on a data type (such as when assigning a range subtype or referencing the type in an SQL expression). This allows the user to block legitimate owners from altering or dropping that type, resulting in a targeted denial-of-service condition on the affected database object.

Отчет

This Moderate impact flaw allows an authenticated user with object creation rights to cause a targeted denial of service in PostgreSQL. Missing authorization checks during specific DDL operations allow an attacker to create type dependencies that block legitimate ALTER and DROP commands, preventing routine administrative management of affected data types.

Меры по смягчению последствий

To mitigate this vulnerability, administrators can proactively monitor for and manually remove unauthorized dependencies created on composite types by users lacking USAGE privileges. Restricting database access and object creation rights only to trusted users will limit the exposure.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10postgresql16Fix deferred
Red Hat Enterprise Linux 10postgresql18Fix deferred
Red Hat Enterprise Linux 6postgresqlNot affected
Red Hat Enterprise Linux 7postgresqlFix deferred
Red Hat Enterprise Linux 8postgresql:12/postgresqlFix deferred
Red Hat Enterprise Linux 8postgresql:15/postgresqlFix deferred
Red Hat Enterprise Linux 8postgresql:16/postgresqlFix deferred
Red Hat Enterprise Linux 9postgresqlFix deferred
Red Hat Enterprise Linux 9postgresql:15/postgresqlFix deferred
Red Hat Enterprise Linux 9postgresql:16/postgresqlFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-862
https://bugzilla.redhat.com/show_bug.cgi?id=2515318postgresql: PostgreSQL: Denial of Service via missing authorization in DDL commands

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
ubuntu
около 1 месяца назад

Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of service against ALTER and DROP of the type, via creating a dependency on the type. Many DDL operations did check the privilege, but assigning a range subtype and referencing the type from an SQL expression did not. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

CVSS3: 4.3
nvd
около 1 месяца назад

Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of service against ALTER and DROP of the type, via creating a dependency on the type. Many DDL operations did check the privilege, but assigning a range subtype and referencing the type from an SQL expression did not. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

CVSS3: 4.3
msrc
23 дня назад

PostgreSQL fails to check type USAGE privilege

CVSS3: 4.3
debian
около 1 месяца назад

Missing authorization in PostgreSQL DDL commands allows an object crea ...

CVSS3: 4.3
github
около 1 месяца назад

Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of service against ALTER and DROP of the type, via creating a dependency on the type. Many DDL operations did check the privilege, but assigning a range subtype and referencing the type from an SQL expression did not. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.

4.3 Medium

CVSS3