Bug 2540725 - CVE-2026-61819 postgresql18-pg_partman: privilege escalation via SQL injection in when using pg_jobmon and encountering exception [epel-all]
Summary: CVE-2026-61819 postgresql18-pg_partman: privilege escalation via SQL injectio...
Keywords:
Status: NEW
Alias: None
Product: Fedora EPEL
Classification: Fedora
Component: postgresql18-pg_partman
Version: epel10
Hardware: Unspecified
OS: Unspecified
urgent
urgent
Target Milestone: ---
Assignee: Pavol Sloboda
QA Contact:
URL:
Whiteboard: {"flaws": ["6ab0b2b1-cc6f-4bae-8d64-7...
Depends On:
Blocks: CVE-2026-61819
TreeView+ depends on / blocked
 
Reported: 2026-09-24 19:09 UTC by Guilherme de Almeida Suckevicz
Modified: 2026-09-24 19:09 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Guilherme de Almeida Suckevicz 2026-09-24 19:09:01 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, when pg_jobmon is installed and part_config.jobmon is true, exception handlers in multiple pg_partman functions place p_parent_table verbatim inside a SQL string literal used to call pg_jobmon.add_job(). A partman_user can create a parent-table name containing a single quote that terminates the literal and injects SQL when an affected exception path runs. If pg_partman_bgw reaches that path, the injected SQL executes with pg_partman_bgw.role privileges, which default to PostgreSQL superuser, permitting database-wide compromise and operating-system command execution as the PostgreSQL service account. The persistent part_config row can trigger the escalation again on later maintenance ticks. This issue is fixed in version 5.5.0.


Note You need to log in before you can comment on or make changes to this bug.