Bug 2477448 (CVE-2026-6473)

Summary: CVE-2026-6473 postgresql: integer overflow can cause an undersized allocation and an out-of-bounds write
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: dschmidt, erezende, fnffree67, jlanda, kshier, rhel-process-autobot, simaishi, smcdonal, stcannon, teagle, watson-tool-maintainers, yguenane
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in PostgreSQL. An integer overflow in multiple server features allows an unprivileged database user to cause an undersized memory allocation that leads to an out-of-bounds write. This issue allows an attacker to execute arbitrary code as the operating system user running the database or, in applications that pass gigabyte-scale user inputs to the relevant database functions, to cause a segmentation fault, resulting in a denial of service.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2484431, 2484432, 2484433, 2484434    
Bug Blocks:    

Description OSIDB Bzimport 2026-05-14 14:02:10 UTC
Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds.  This may execute arbitrary code as the operating system user running the database.  In applications that pass gigabyte-scale user inputs to the relevant database functions, the application input provider may achieve a segmentation fault.  Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

Comment 2 David Raya 2026-06-08 07:30:51 UTC
I encountered this bug on Red Hat Enterprise Linux 9.5 and Fedora 41 (https://fnffree.io) with the latest postgresql-server packages. It triggers during bulk INSERT/UPDATE operations with large integer values, causing a segmentation fault due to integer overflow and out-of-bounds write.

Comment 4 errata-xmlrpc 2026-06-16 07:44:51 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:26181 https://access.redhat.com/errata/RHSA-2026:26181

Comment 5 errata-xmlrpc 2026-06-16 11:49:45 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:26203 https://access.redhat.com/errata/RHSA-2026:26203

Comment 6 errata-xmlrpc 2026-06-16 11:50:01 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:26204 https://access.redhat.com/errata/RHSA-2026:26204

Comment 7 errata-xmlrpc 2026-06-17 07:50:43 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:26524 https://access.redhat.com/errata/RHSA-2026:26524

Comment 8 errata-xmlrpc 2026-06-17 08:40:50 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:26525 https://access.redhat.com/errata/RHSA-2026:26525

Comment 9 errata-xmlrpc 2026-06-17 11:51:52 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2026:26561 https://access.redhat.com/errata/RHSA-2026:26561

Comment 10 errata-xmlrpc 2026-06-22 05:28:08 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:27738 https://access.redhat.com/errata/RHSA-2026:27738

Comment 11 errata-xmlrpc 2026-06-22 05:44:52 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:27743 https://access.redhat.com/errata/RHSA-2026:27743

Comment 12 errata-xmlrpc 2026-06-22 05:46:06 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:27718 https://access.redhat.com/errata/RHSA-2026:27718

Comment 13 errata-xmlrpc 2026-06-22 05:48:14 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:27742 https://access.redhat.com/errata/RHSA-2026:27742

Comment 14 errata-xmlrpc 2026-06-22 06:05:55 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:27741 https://access.redhat.com/errata/RHSA-2026:27741

Comment 15 errata-xmlrpc 2026-06-22 19:51:04 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:28037 https://access.redhat.com/errata/RHSA-2026:28037

Comment 16 errata-xmlrpc 2026-06-23 10:03:04 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:28143 https://access.redhat.com/errata/RHSA-2026:28143

Comment 17 errata-xmlrpc 2026-06-24 13:39:03 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:28999 https://access.redhat.com/errata/RHSA-2026:28999

Comment 18 errata-xmlrpc 2026-06-25 02:33:25 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:29212 https://access.redhat.com/errata/RHSA-2026:29212

Comment 19 errata-xmlrpc 2026-06-25 10:29:31 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On

Via RHSA-2026:29815 https://access.redhat.com/errata/RHSA-2026:29815

Comment 20 errata-xmlrpc 2026-06-25 12:20:47 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:29904 https://access.redhat.com/errata/RHSA-2026:29904

Comment 21 errata-xmlrpc 2026-06-25 15:04:59 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:29953 https://access.redhat.com/errata/RHSA-2026:29953

Comment 22 errata-xmlrpc 2026-06-29 11:55:13 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:32983 https://access.redhat.com/errata/RHSA-2026:32983

Comment 23 errata-xmlrpc 2026-06-29 12:16:14 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On

Via RHSA-2026:32994 https://access.redhat.com/errata/RHSA-2026:32994

Comment 24 errata-xmlrpc 2026-06-30 08:52:13 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:33441 https://access.redhat.com/errata/RHSA-2026:33441

Comment 25 errata-xmlrpc 2026-06-30 12:47:16 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:33497 https://access.redhat.com/errata/RHSA-2026:33497

Comment 26 errata-xmlrpc 2026-07-01 06:32:55 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2026:34043 https://access.redhat.com/errata/RHSA-2026:34043

Comment 27 errata-xmlrpc 2026-07-01 18:15:57 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On

Via RHSA-2026:34363 https://access.redhat.com/errata/RHSA-2026:34363

Comment 28 errata-xmlrpc 2026-07-01 18:16:17 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On

Via RHSA-2026:34362 https://access.redhat.com/errata/RHSA-2026:34362

Comment 29 errata-xmlrpc 2026-07-06 09:48:36 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2026:35880 https://access.redhat.com/errata/RHSA-2026:35880

Comment 30 errata-xmlrpc 2026-07-21 06:32:59 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2026:42555 https://access.redhat.com/errata/RHSA-2026:42555