Описание
Missing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to find user-defined types, including extension-defined types. That is to say, the victim will execute arbitrary SQL functions of the attacker's choice. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
A flaw was found in PostgreSQL CREATE TYPE handling for multirange types. The database failed to properly verify schema CREATE privileges during multirange type creation. An authenticated database user could exploit this issue to hijack queries that rely on search_path resolution for user-defined or extension-defined types, potentially causing execution of arbitrary SQL functions within the affected database context.
Отчет
This vulnerability affects PostgreSQL multirange type creation functionality. Red Hat Product Security has assessed this issue as a Moderate severity vulnerability. The vulnerability does not directly provide operating system command execution or PostgreSQL superuser privileges. The impact is limited to the affected database context and depends on application query behavior and schema resolution patterns. Therefore, Red Hat assessed the Confidentiality and Integrity impacts as Low (C:L/I:L), with no demonstrated Availability impact (A:N).
Меры по смягчению последствий
Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | postgresql | Out of support scope | ||
| Red Hat Enterprise Linux 7 | postgresql | Fix deferred | ||
| Red Hat Enterprise Linux 8 | postgresql | Fix deferred | ||
| Red Hat Enterprise Linux 9 | postgresql | Fix deferred | ||
| Self-service automation portal 2 | ansible-automation-platform/bootc-automation-portal-rhel9 | Fix deferred | ||
| Red Hat Enterprise Linux 10 | postgresql18 | Fixed | RHSA-2026:27742 | 22.06.2026 |
| Red Hat Enterprise Linux 10 | postgresql16 | Fixed | RHSA-2026:27743 | 22.06.2026 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | postgresql16 | Fixed | RHSA-2026:27718 | 22.06.2026 |
| Red Hat Enterprise Linux 8 | postgresql | Fixed | RHSA-2026:26181 | 16.06.2026 |
| Red Hat Enterprise Linux 8 | postgresql | Fixed | RHSA-2026:28143 | 23.06.2026 |
Показывать по
Дополнительная информация
Статус:
5.4 Medium
CVSS3
Связанные уязвимости
Missing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to find user-defined types, including extension-defined types. That is to say, the victim will execute arbitrary SQL functions of the attacker's choice. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Missing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to find user-defined types, including extension-defined types. That is to say, the victim will execute arbitrary SQL functions of the attacker's choice. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
PostgreSQL CREATE TYPE does not check multirange schema CREATE privilege
Missing authorization in PostgreSQL CREATE TYPE allows an object creat ...
Missing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to find user-defined types, including extension-defined types. That is to say, the victim will execute arbitrary SQL functions of the attacker's choice. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
5.4 Medium
CVSS3