Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-6477

Опубликовано: 14 мая 2026
Источник: redhat
CVSS3: 8.4
EPSS Низкий

Описание

Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

A flaw was found in PostgreSQL libpq. A server superuser can exploit a buffer overflow vulnerability in the PQfn function, which is used by client functions such as lo_export(), lo_read(), lo_lseek64(), and lo_tell64(). This allows the superuser to send an arbitrarily large response, overwriting the client's stack memory, specifically in tools like psql and pg_dump. This could lead to arbitrary code execution on the client system.

Отчет

This IMPORTANT buffer overflow in PostgreSQL libpq allows a malicious server superuser to overwrite client stack memory via lo_* functions. Exploitation requires the victim to connect to a compromised or malicious server (UI:R). The scope is changed as the server attack affects the client system. Impact is high to confidentiality, integrity, and availability through potential client-side code execution. Affects versions before 18.4, 17.10, 16.14, 15.18, and 14.23.

Меры по смягчению последствий

Only connect to trusted PostgreSQL servers. Avoid using psql or pg_dump against untrusted or potentially compromised database servers.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6postgresqlOut of support scope
Red Hat Enterprise Linux 7postgresqlAffected
Red Hat Enterprise Linux 8postgresqlNot affected
Red Hat Enterprise Linux 8postgresql-jdbcNot affected
Self-service automation portal 2ansible-automation-platform/bootc-automation-portal-rhel9Affected
Red Hat Enterprise Linux 10postgresql18FixedRHSA-2026:2774222.06.2026
Red Hat Enterprise Linux 10postgresql16FixedRHSA-2026:2774322.06.2026
Red Hat Enterprise Linux 10libpqFixedRHSA-2026:4439123.07.2026
Red Hat Enterprise Linux 10.0 Extended Update Supportpostgresql16FixedRHSA-2026:2771822.06.2026
Red Hat Enterprise Linux 8postgresqlFixedRHSA-2026:2618116.06.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=2477442postgresql: PostgreSQL libpq: Buffer overflow allows server superuser to overwrite client stack memory

EPSS

Процентиль: 20%
0.00284
Низкий

8.4 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
3 месяца назад

Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 8.8
nvd
3 месяца назад

Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 8.8
msrc
2 месяца назад

PostgreSQL libpq lo_* functions let server superuser overwrite client stack memory

CVSS3: 8.8
debian
3 месяца назад

Use of inherently dangerous function PQfn(..., result_is_int=0, ...) i ...

rocky
3 дня назад

Important: libpq security update

EPSS

Процентиль: 20%
0.00284
Низкий

8.4 High

CVSS3