Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-6637

Опубликовано: 14 мая 2026
Источник: redhat
CVSS3: 8.8

Описание

Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as the operating system user running the database. A distinct attack is possible if the application declares a user-controlled column as a "refint" cascade primary key and facilitates user-controlled updates to that column. In that case, a SQL injection allows a primary key update value provider to execute arbitrary SQL as the database user performing the primary key update. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

A flaw was found in PostgreSQL. A stack buffer overflow in the 'refint' module allows an unprivileged database user to execute arbitrary code as the operating system user running the database. Additionally, a separate vulnerability exists where, if an application uses a user-controlled column as a 'refint' cascade primary key and allows user-controlled updates, a SQL injection can enable an attacker to execute arbitrary SQL commands as the database user performing the update.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6postgresqlNot affected
Self-service automation portal 2ansible-automation-platform/bootc-automation-portal-rhel9Affected
Red Hat Enterprise Linux 10postgresql18FixedRHSA-2026:2774222.06.2026
Red Hat Enterprise Linux 10postgresql16FixedRHSA-2026:2774322.06.2026
Red Hat Enterprise Linux 10.0 Extended Update Supportpostgresql16FixedRHSA-2026:2771822.06.2026
Red Hat Enterprise Linux 7 Extended Lifecycle SupportpostgresqlFixedRHSA-2026:4952103.08.2026
Red Hat Enterprise Linux 8postgresqlFixedRHSA-2026:2618116.06.2026
Red Hat Enterprise Linux 8postgresqlFixedRHSA-2026:2814323.06.2026
Red Hat Enterprise Linux 8postgresqlFixedRHSA-2026:2820823.06.2026
Red Hat Enterprise Linux 8postgresqlFixedRHSA-2026:2899924.06.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=2477443postgresql: PostgreSQL: Arbitrary code execution vulnerability in 'refint' module

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
4 месяца назад

Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as the operating system user running the database. A distinct attack is possible if the application declares a user-controlled column as a "refint" cascade primary key and facilitates user-controlled updates to that column. In that case, a SQL injection allows a primary key update value provider to execute arbitrary SQL as the database user performing the primary key update. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 8.8
nvd
4 месяца назад

Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as the operating system user running the database. A distinct attack is possible if the application declares a user-controlled column as a "refint" cascade primary key and facilitates user-controlled updates to that column. In that case, a SQL injection allows a primary key update value provider to execute arbitrary SQL as the database user performing the primary key update. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 8.8
msrc
4 месяца назад

PostgreSQL refint allows stack buffer overflow and SQL injection

CVSS3: 8.8
debian
4 месяца назад

Stack buffer overflow in PostgreSQL module "refint" allows an unprivil ...

CVSS3: 8.8
github
4 месяца назад

Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as the operating system user running the database. A distinct attack is possible if the application declares a user-controlled column as a "refint" cascade primary key and facilitates user-controlled updates to that column. In that case, a SQL injection allows a primary key update value provider to execute arbitrary SQL as the database user performing the primary key update. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

8.8 High

CVSS3