Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-6477

Опубликовано: 14 мая 2026
Источник: redhat
CVSS3: 8.4

Описание

Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

A flaw was found in PostgreSQL libpq. A server superuser can exploit a buffer overflow vulnerability in the PQfn function, which is used by client functions such as lo_export(), lo_read(), lo_lseek64(), and lo_tell64(). This allows the superuser to send an arbitrarily large response, overwriting the client's stack memory, specifically in tools like psql and pg_dump. This could lead to arbitrary code execution on the client system.

Отчет

This IMPORTANT buffer overflow in PostgreSQL libpq allows a malicious server superuser to overwrite client stack memory via lo_* functions. Exploitation requires the victim to connect to a compromised or malicious server (UI:R). The scope is changed as the server attack affects the client system. Impact is high to confidentiality, integrity, and availability through potential client-side code execution. Affects versions before 18.4, 17.10, 16.14, 15.18, and 14.23.

Меры по смягчению последствий

Only connect to trusted PostgreSQL servers. Avoid using psql or pg_dump against untrusted or potentially compromised database servers.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6postgresqlOut of support scope
Red Hat Enterprise Linux 8postgresqlNot affected
Red Hat Enterprise Linux 8postgresql-jdbcNot affected
Self-service automation portal 2ansible-automation-platform/bootc-automation-portal-rhel9Affected
Red Hat Enterprise Linux 10postgresql18FixedRHSA-2026:2774222.06.2026
Red Hat Enterprise Linux 10postgresql16FixedRHSA-2026:2774322.06.2026
Red Hat Enterprise Linux 10libpqFixedRHSA-2026:4439123.07.2026
Red Hat Enterprise Linux 10.0 Extended Update Supportpostgresql16FixedRHSA-2026:2771822.06.2026
Red Hat Enterprise Linux 10.0 Extended Update SupportlibpqFixedRHSA-2026:5086305.08.2026
Red Hat Enterprise Linux 7 Extended Lifecycle SupportpostgresqlFixedRHSA-2026:4952103.08.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=2477442postgresql: PostgreSQL libpq: Buffer overflow allows server superuser to overwrite client stack memory

8.4 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
4 месяца назад

Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 8.8
nvd
4 месяца назад

Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 8.8
msrc
4 месяца назад

PostgreSQL libpq lo_* functions let server superuser overwrite client stack memory

CVSS3: 8.8
debian
4 месяца назад

Use of inherently dangerous function PQfn(..., result_is_int=0, ...) i ...

rocky
около 2 месяцев назад

Important: libpq security update

8.4 High

CVSS3