Количество 28
Количество 28
BDU:2026-07098
Уязвимость функции lo_export(), lo_read(), lo_lseek64() и lo_tell64() клиентской библиотеке libpq системы управления базами данных PostgreSQL, позволяющая нарушителю перезаписать память стека pg_dump или psql
CVE-2026-6477
Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
CVE-2026-6477
Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
CVE-2026-6477
Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
CVE-2026-6477
PostgreSQL libpq lo_* functions let server superuser overwrite client stack memory
CVE-2026-6477
Use of inherently dangerous function PQfn(..., result_is_int=0, ...) i ...
GHSA-jm5f-gpfq-q9h3
Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
RLSA-2026:28037
Important: postgresql:15 security update
RLSA-2026:26204
Important: postgresql:18 security update
RLSA-2026:26203
Important: postgresql:16 security update
RLSA-2026:26181
Important: postgresql:15 security update
ELSA-2026-27738
ELSA-2026-27738: libpq security update (IMPORTANT)
SUSE-SU-2026:2117-1
Security update for postgresql14
SUSE-SU-2026:2086-1
Security update for postgresql14
SUSE-SU-2026:2085-1
Security update for postgresql15
SUSE-SU-2026:2007-1
Security update for postgresql14
SUSE-SU-2026:2000-1
Security update for postgresql15
SUSE-SU-2026:1999-1
Security update for postgresql15
SUSE-SU-2026:2084-1
Security update for postgresql16
SUSE-SU-2026:2001-1
Security update for postgresql16
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2026-07098 Уязвимость функции lo_export(), lo_read(), lo_lseek64() и lo_tell64() клиентской библиотеке libpq системы управления базами данных PostgreSQL, позволяющая нарушителю перезаписать память стека pg_dump или psql | CVSS3: 8.8 | 0% Низкий | 3 месяца назад | |
CVE-2026-6477 Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected. | CVSS3: 8.8 | 0% Низкий | 3 месяца назад | |
CVE-2026-6477 Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected. | CVSS3: 8.4 | 0% Низкий | 3 месяца назад | |
CVE-2026-6477 Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected. | CVSS3: 8.8 | 0% Низкий | 3 месяца назад | |
CVE-2026-6477 PostgreSQL libpq lo_* functions let server superuser overwrite client stack memory | CVSS3: 8.8 | 0% Низкий | 2 месяца назад | |
CVE-2026-6477 Use of inherently dangerous function PQfn(..., result_is_int=0, ...) i ... | CVSS3: 8.8 | 0% Низкий | 3 месяца назад | |
GHSA-jm5f-gpfq-q9h3 Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected. | CVSS3: 8.8 | 0% Низкий | 3 месяца назад | |
RLSA-2026:28037 Important: postgresql:15 security update | около 1 месяца назад | |||
RLSA-2026:26204 Important: postgresql:18 security update | около 1 месяца назад | |||
RLSA-2026:26203 Important: postgresql:16 security update | около 1 месяца назад | |||
RLSA-2026:26181 Important: postgresql:15 security update | около 1 месяца назад | |||
ELSA-2026-27738 ELSA-2026-27738: libpq security update (IMPORTANT) | около 1 месяца назад | |||
SUSE-SU-2026:2117-1 Security update for postgresql14 | 2 месяца назад | |||
SUSE-SU-2026:2086-1 Security update for postgresql14 | 2 месяца назад | |||
SUSE-SU-2026:2085-1 Security update for postgresql15 | 2 месяца назад | |||
SUSE-SU-2026:2007-1 Security update for postgresql14 | 2 месяца назад | |||
SUSE-SU-2026:2000-1 Security update for postgresql15 | 2 месяца назад | |||
SUSE-SU-2026:1999-1 Security update for postgresql15 | 2 месяца назад | |||
SUSE-SU-2026:2084-1 Security update for postgresql16 | 2 месяца назад | |||
SUSE-SU-2026:2001-1 Security update for postgresql16 | 2 месяца назад |
Уязвимостей на страницу