Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-6470

Опубликовано: 13 авг. 2026
Источник: ubuntu
Приоритет: medium
CVSS3: 4.3

Описание

Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of service against ALTER and DROP of the type, via creating a dependency on the type. Many DDL operations did check the privilege, but assigning a range subtype and referencing the type from an SQL expression did not. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.

РелизСтатусПримечание
devel

DNE

esm-infra/bionic

needs-triage

jammy

DNE

noble

DNE

resolute

DNE

upstream

ignored

end of life

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra/focal

needs-triage

jammy

DNE

noble

DNE

resolute

DNE

upstream

ignored

end of life

Показывать по

РелизСтатусПримечание
devel

DNE

jammy

released

14.24-0ubuntu0.22.04.1
noble

DNE

resolute

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

jammy

DNE

noble

released

16.15-0ubuntu0.24.04.1
resolute

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

pending

18.6-3
jammy

DNE

noble

DNE

resolute

released

18.6-0ubuntu0.26.04.1
upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/trusty

deferred

2019-08-23
jammy

DNE

noble

DNE

resolute

DNE

upstream

ignored

end of life

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/xenial

needs-triage

jammy

DNE

noble

DNE

resolute

DNE

upstream

ignored

end of life

Показывать по

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
nvd
19 дней назад

Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of service against ALTER and DROP of the type, via creating a dependency on the type. Many DDL operations did check the privilege, but assigning a range subtype and referencing the type from an SQL expression did not. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

CVSS3: 4.3
msrc
9 дней назад

PostgreSQL fails to check type USAGE privilege

CVSS3: 4.3
debian
19 дней назад

Missing authorization in PostgreSQL DDL commands allows an object crea ...

CVSS3: 4.3
github
19 дней назад

Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of service against ALTER and DROP of the type, via creating a dependency on the type. Many DDL operations did check the privilege, but assigning a range subtype and referencing the type from an SQL expression did not. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.

CVSS3: 4.3
fstec
20 дней назад

Уязвимость DDL-команд системы управления базами данных PostgreSQL, позволяющая нарушителю вызвать отказ в обслуживании

4.3 Medium

CVSS3