| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-6438-1 | postgresql-17 security update |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://www.postgresql.org/support/security/CVE-2026-14662/ |
|
Thu, 13 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Aug 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Postgresql
Postgresql postgresql |
|
| Vendors & Products |
Postgresql
Postgresql postgresql |
Thu, 13 Aug 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds, via crafted large inputs. This may execute arbitrary code as the operating system user running the database. These types are typically sourced from application logic, not taken from the application's user. Hence, application users attacking the database, through the application as a conduit, are unlikely. CVE-2026-6473 had fixed similar problems. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected. | |
| Title | PostgreSQL tsvector and tsquery undersize allocations, via integer wraparound | |
| Weaknesses | CWE-190 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: PostgreSQL
Published:
Updated: 2026-08-13T15:34:11.197Z
Reserved: 2026-07-03T20:28:07.779Z
Link: CVE-2026-14662
Updated: 2026-08-13T15:34:02.974Z
Status : Received
Published: 2026-08-13T13:17:43.553
Modified: 2026-08-13T16:17:55.490
Link: CVE-2026-14662
No data.
OpenCVE Enrichment
Updated: 2026-08-13T15:15:13Z
Debian DSA