Executive brief
PostgreSQL is a widely used database system for storing and managing organizational data. A security flaw in how the database handles certain text characters allows a database user to run malicious commands on the underlying server. If exploited, this could lead to a full system takeover, unauthorized data access, or disruption of database services.
Technical details
A buffer overflow vulnerability exists in the PostgreSQL core server due to improper validation of multibyte character lengths during text manipulation. An authenticated database user can trigger this flaw by issuing specially crafted SQL queries. The root cause is identified as improper validation of array indices or input offsets (CWE-129/CWE-1285) when processing multibyte strings. Successful exploitation allows for a heap buffer overrun, enabling arbitrary code execution with the privileges of the operating system user running the PostgreSQL service. Patches are available in versions 18.2, 17.8, 16.12, 15.16, and 14.21.
Affected products
- PostgreSQL PostgreSQL Before 18.2, 17.8, 16.12, 15.16, 14.21
- Red Hat Red Hat Enterprise Linux 10 postgresql18, postgresql16
Timeline
- 2026-02-12: advisory: PostgreSQL released security advisory and fixed versions.
- 2026-02-12: patched
- 2026-05-19: patched: Red Hat released security updates for RHEL 10.
References
- https://www.postgresql.org/support/security/CVE-2026-2006/
- https://access.redhat.com/errata/RHSA-2026:19009
- https://access.redhat.com/errata/RHSA-2026:19010
- https://access.redhat.com/errata/RHSA-2026:3730
- https://access.redhat.com/errata/RHSA-2026:3887
- https://access.redhat.com/errata/RHSA-2026:3896
- https://access.redhat.com/errata/RHSA-2026:4024