Bug 2540723 - CVE-2026-61817 postgresql18-pg_partman: privilege escalation via SQL injection in several functions via time decoder [epel-all]
Summary: CVE-2026-61817 postgresql18-pg_partman: privilege escalation via SQL injectio...
Keywords:
Status: NEW
Alias: None
Product: Fedora EPEL
Classification: Fedora
Component: postgresql18-pg_partman
Version: epel10
Hardware: Unspecified
OS: Unspecified
urgent
urgent
Target Milestone: ---
Assignee: Pavol Sloboda
QA Contact:
URL:
Whiteboard: {"flaws": ["9e0e9089-64e0-4cff-8190-c...
Depends On:
Blocks: CVE-2026-61817
TreeView+ depends on / blocked
 
Reported: 2026-09-24 19:08 UTC by Guilherme de Almeida Suckevicz
Modified: 2026-09-24 19:08 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Guilherme de Almeida Suckevicz 2026-09-24 19:08:37 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, run_maintenance(), show_partitions(), show_partition_info(), undo_partition(), and partition_data_time() interpolate the writable part_config.time_dncoder text value without identifier quoting into dynamic SQL. A role with the documented partman_user privileges can store SQL rather than a decoder function name. When an affected operation later uses the poisoned value, including pg_partman_bgw maintenance for a text- or UUID-keyed set, the SQL executes with the operation's privileges, which can be the default PostgreSQL superuser background-worker role. The persistent row can restore elevated access on later ticks, and successful exploitation can permit database-wide compromise and operating-system command execution as the PostgreSQL service account. This issue is fixed in version 5.5.0.


Note You need to log in before you can comment on or make changes to this bug.