Bug 2477448 (CVE-2026-6473)
| Summary: | CVE-2026-6473 postgresql: integer overflow can cause an undersized allocation and an out-of-bounds write | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | dschmidt, erezende, fnffree67, jlanda, kshier, rhel-process-autobot, simaishi, smcdonal, stcannon, teagle, watson-tool-maintainers, yguenane |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in PostgreSQL. An integer overflow in multiple server features allows an unprivileged database user to cause an undersized memory allocation that leads to an out-of-bounds write. This issue allows an attacker to execute arbitrary code as the operating system user running the database or, in applications that pass gigabyte-scale user inputs to the relevant database functions, to cause a segmentation fault, resulting in a denial of service.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2484431, 2484432, 2484433, 2484434 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-05-14 14:02:10 UTC
I encountered this bug on Red Hat Enterprise Linux 9.5 and Fedora 41 (https://fnffree.io) with the latest postgresql-server packages. It triggers during bulk INSERT/UPDATE operations with large integer values, causing a segmentation fault due to integer overflow and out-of-bounds write. This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:26181 https://access.redhat.com/errata/RHSA-2026:26181 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:26203 https://access.redhat.com/errata/RHSA-2026:26203 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:26204 https://access.redhat.com/errata/RHSA-2026:26204 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions Via RHSA-2026:26524 https://access.redhat.com/errata/RHSA-2026:26524 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:26525 https://access.redhat.com/errata/RHSA-2026:26525 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:26561 https://access.redhat.com/errata/RHSA-2026:26561 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:27738 https://access.redhat.com/errata/RHSA-2026:27738 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:27743 https://access.redhat.com/errata/RHSA-2026:27743 This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:27718 https://access.redhat.com/errata/RHSA-2026:27718 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:27742 https://access.redhat.com/errata/RHSA-2026:27742 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:27741 https://access.redhat.com/errata/RHSA-2026:27741 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:28037 https://access.redhat.com/errata/RHSA-2026:28037 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:28143 https://access.redhat.com/errata/RHSA-2026:28143 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:28999 https://access.redhat.com/errata/RHSA-2026:28999 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:29212 https://access.redhat.com/errata/RHSA-2026:29212 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On Via RHSA-2026:29815 https://access.redhat.com/errata/RHSA-2026:29815 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions Via RHSA-2026:29904 https://access.redhat.com/errata/RHSA-2026:29904 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:29953 https://access.redhat.com/errata/RHSA-2026:29953 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:32983 https://access.redhat.com/errata/RHSA-2026:32983 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On Via RHSA-2026:32994 https://access.redhat.com/errata/RHSA-2026:32994 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions Via RHSA-2026:33441 https://access.redhat.com/errata/RHSA-2026:33441 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:33497 https://access.redhat.com/errata/RHSA-2026:33497 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:34043 https://access.redhat.com/errata/RHSA-2026:34043 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:34363 https://access.redhat.com/errata/RHSA-2026:34363 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:34362 https://access.redhat.com/errata/RHSA-2026:34362 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:35880 https://access.redhat.com/errata/RHSA-2026:35880 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:42555 https://access.redhat.com/errata/RHSA-2026:42555 |