Bug 2439325 (CVE-2026-2004)

Summary: CVE-2026-2004 postgresql: PostgreSQL intarray missing validation of type of input to selectivity estimator executes arbitrary code
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedKeywords: Security
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A type validation flaw has been discovered in PostgreSQL. Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the operating system user running the database.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2439462, 2439463, 2439464, 2439465, 2439459, 2439460, 2439461    
Bug Blocks:    

Description OSIDB Bzimport 2026-02-12 14:01:53 UTC
Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the operating system user running the database.  Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.

Comment 2 errata-xmlrpc 2026-03-04 14:20:58 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:3730 https://access.redhat.com/errata/RHSA-2026:3730

Comment 3 errata-xmlrpc 2026-03-05 13:07:38 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:3887 https://access.redhat.com/errata/RHSA-2026:3887

Comment 4 errata-xmlrpc 2026-03-05 14:35:50 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:3896 https://access.redhat.com/errata/RHSA-2026:3896

Comment 6 errata-xmlrpc 2026-03-09 11:35:53 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:4024 https://access.redhat.com/errata/RHSA-2026:4024

Comment 7 errata-xmlrpc 2026-03-09 12:47:44 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:4059 https://access.redhat.com/errata/RHSA-2026:4059

Comment 8 errata-xmlrpc 2026-03-09 13:32:42 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:4063 https://access.redhat.com/errata/RHSA-2026:4063

Comment 9 errata-xmlrpc 2026-03-09 14:09:54 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:4064 https://access.redhat.com/errata/RHSA-2026:4064

Comment 10 errata-xmlrpc 2026-03-09 14:19:44 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2026:4074 https://access.redhat.com/errata/RHSA-2026:4074

Comment 11 errata-xmlrpc 2026-03-09 14:24:51 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2026:4075 https://access.redhat.com/errata/RHSA-2026:4075

Comment 14 errata-xmlrpc 2026-03-09 16:46:04 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:4110 https://access.redhat.com/errata/RHSA-2026:4110

Comment 15 errata-xmlrpc 2026-03-11 03:37:14 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:4254 https://access.redhat.com/errata/RHSA-2026:4254

Comment 16 errata-xmlrpc 2026-03-12 08:52:33 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:4441 https://access.redhat.com/errata/RHSA-2026:4441

Comment 17 errata-xmlrpc 2026-03-12 13:27:20 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:4475 https://access.redhat.com/errata/RHSA-2026:4475

Comment 18 errata-xmlrpc 2026-03-12 15:10:37 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.2 Advanced Update Support

Via RHSA-2026:4506 https://access.redhat.com/errata/RHSA-2026:4506

Comment 19 errata-xmlrpc 2026-03-12 15:16:14 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On

Via RHSA-2026:4504 https://access.redhat.com/errata/RHSA-2026:4504

Comment 20 errata-xmlrpc 2026-03-12 15:20:08 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.6 Telecommunications Update Service

Via RHSA-2026:4505 https://access.redhat.com/errata/RHSA-2026:4505

Comment 21 errata-xmlrpc 2026-03-12 15:25:33 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On

Via RHSA-2026:4509 https://access.redhat.com/errata/RHSA-2026:4509

Comment 22 errata-xmlrpc 2026-03-12 16:10:49 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.6 Telecommunications Update Service

Via RHSA-2026:4516 https://access.redhat.com/errata/RHSA-2026:4516

Comment 23 errata-xmlrpc 2026-03-12 16:13:21 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions

Via RHSA-2026:4518 https://access.redhat.com/errata/RHSA-2026:4518

Comment 24 errata-xmlrpc 2026-03-12 16:27:25 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions

Via RHSA-2026:4515 https://access.redhat.com/errata/RHSA-2026:4515

Comment 25 errata-xmlrpc 2026-03-12 17:58:23 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Extended Update Support

Via RHSA-2026:4524 https://access.redhat.com/errata/RHSA-2026:4524

Comment 26 errata-xmlrpc 2026-03-12 18:52:39 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:4528 https://access.redhat.com/errata/RHSA-2026:4528

Comment 27 errata-xmlrpc 2026-03-12 22:20:59 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:4546 https://access.redhat.com/errata/RHSA-2026:4546

Comment 28 errata-xmlrpc 2026-03-12 22:28:08 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Extended Update Support

Via RHSA-2026:4544 https://access.redhat.com/errata/RHSA-2026:4544

Comment 29 errata-xmlrpc 2026-03-12 22:36:38 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:4547 https://access.redhat.com/errata/RHSA-2026:4547

Comment 30 errata-xmlrpc 2026-03-12 22:55:24 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Extended Update Support

Via RHSA-2026:4548 https://access.redhat.com/errata/RHSA-2026:4548

Comment 34 errata-xmlrpc 2026-05-19 13:01:14 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:19009 https://access.redhat.com/errata/RHSA-2026:19009

Comment 35 errata-xmlrpc 2026-05-19 13:01:40 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:19010 https://access.redhat.com/errata/RHSA-2026:19010