Bug 2538137 (CVE-2026-61818) - CVE-2026-61818 pg_partman: SQL injection in undo partition time encoder
Summary: CVE-2026-61818 pg_partman: SQL injection in undo partition time encoder
Keywords:
Status: NEW
Alias: CVE-2026-61818
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
urgent
urgent
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2540724
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-22 17:15 UTC by OSIDB Bzimport
Modified: 2026-09-24 19:08 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-22 17:15:00 UTC
pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, undo_partition() reads part_config.time_encoder as unrestricted text and interpolates it without identifier quoting into a dynamically executed SELECT statement. A role with partman_user access can store SQL rather than a function name, and the SQL executes with the privileges of the caller that invokes undo_partition(). The function is not part of the default background-worker path, which limits the automatic superuser escalation described by the related create-partition vulnerability, but a privileged caller can still have its available confidentiality, integrity, and availability permissions abused. This issue is fixed in version 5.5.0.


Note You need to log in before you can comment on or make changes to this bug.