Bug 2515320 (CVE-2026-16241) - CVE-2026-16241 postgresql: PostgreSQL ECPG: Denial of Service via integer underflow
Summary: CVE-2026-16241 postgresql: PostgreSQL ECPG: Denial of Service via integer und...
Keywords:
Status: NEW
Alias: CVE-2026-16241
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2527313 2527314
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-13 13:30 UTC by OSIDB Bzimport
Modified: 2026-09-02 10:31 UTC (History)
9 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-08-13 13:30:37 UTC
Integer underflow in PostgreSQL ECPG allows a database server administrator to achieve temporary denial of service against the ECPG client via sending a bytea value lacking the mandatory prefix.  The client overwrites a huge memory region with bytes outside attacker knowledge or control.  This typically yields a simple SIGSEGV, but rare cases might achieve client-specific integrity impact via the write.  Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.


Note You need to log in before you can comment on or make changes to this bug.