{
  "threat_severity" : "Important",
  "public_date" : "2026-05-14T13:00:09Z",
  "bugzilla" : {
    "description" : "postgresql: integer overflow can cause an undersized allocation and an out-of-bounds write",
    "id" : "2477448",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2477448"
  },
  "cvss3" : {
    "cvss3_base_score" : "8.8",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-190",
  "details" : [ "Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds.  This may execute arbitrary code as the operating system user running the database.  In applications that pass gigabyte-scale user inputs to the relevant database functions, the application input provider may achieve a segmentation fault.  Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.", "A flaw was found in PostgreSQL. An integer overflow in multiple server features allows an unprivileged database user to cause an undersized memory allocation that leads to an out-of-bounds write. This issue allows an attacker to execute arbitrary code as the operating system user running the database or, in applications that pass gigabyte-scale user inputs to the relevant database functions, to cause a segmentation fault, resulting in a denial of service." ],
  "statement" : "To exploit this flaw, an attacker with minimal access to a database needs to pass extremely large inputs to vulnerable database functions, causing an integer overflow that leads to an out-of-bounds write. This flaw allows an attacker to potentially execute arbitrary code or, more likely, cause a denial of service.\nDefault Red Hat Enterprise Linux security features, including SELinux enforcement, Address Space Layout Randomization (ASLR) and NX (No-Execute) stack protection, significantly increase the difficulty of achieving arbitrary code execution, limiting the impact of this vulnerability.\nDue to these reasons, this vulnerability has been rated with an important severity.",
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 10",
    "release_date" : "2026-06-22T00:00:00Z",
    "advisory" : "RHSA-2026:27742",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10.2",
    "package" : "postgresql18-0:18.4-1.el10_2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 10",
    "release_date" : "2026-06-22T00:00:00Z",
    "advisory" : "RHSA-2026:27743",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10.2",
    "package" : "postgresql16-0:16.14-1.el10_2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 10.0 Extended Update Support",
    "release_date" : "2026-06-22T00:00:00Z",
    "advisory" : "RHSA-2026:27718",
    "cpe" : "cpe:/o:redhat:enterprise_linux_eus:10.0",
    "package" : "postgresql16-0:16.14-1.el10_0"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
    "release_date" : "2026-08-03T00:00:00Z",
    "advisory" : "RHSA-2026:49521",
    "cpe" : "cpe:/o:redhat:rhel_els:7",
    "package" : "postgresql-0:9.2.24-9.el7_9.6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2026-06-16T00:00:00Z",
    "advisory" : "RHSA-2026:26181",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "postgresql:15-8100020260605152259.489197e6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2026-06-22T00:00:00Z",
    "advisory" : "RHSA-2026:27738",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "libpq-0:13.23-2.el8_10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2026-06-23T00:00:00Z",
    "advisory" : "RHSA-2026:28143",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "postgresql:16-8100020260530205218.489197e6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2026-06-23T00:00:00Z",
    "advisory" : "RHSA-2026:28208",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "postgresql:13-8100020260605152256.489197e6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2026-06-24T00:00:00Z",
    "advisory" : "RHSA-2026:28999",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "postgresql:12-8100020260605152253.489197e6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
    "release_date" : "2026-07-01T00:00:00Z",
    "advisory" : "RHSA-2026:34362",
    "cpe" : "cpe:/a:redhat:rhel_aus:8.4",
    "package" : "postgresql:12-8040020260624104459.522a0ee4"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
    "release_date" : "2026-07-01T00:00:00Z",
    "advisory" : "RHSA-2026:34363",
    "cpe" : "cpe:/a:redhat:rhel_aus:8.4",
    "package" : "postgresql:13-8040020260630100922.522a0ee4"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
    "release_date" : "2026-07-23T00:00:00Z",
    "advisory" : "RHSA-2026:44420",
    "cpe" : "cpe:/a:redhat:rhel_aus:8.4",
    "package" : "libpq-0:13.23-1.el8_4.1"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
    "release_date" : "2026-07-01T00:00:00Z",
    "advisory" : "RHSA-2026:34362",
    "cpe" : "cpe:/a:redhat:rhel_eus_long_life:8.4",
    "package" : "postgresql:12-8040020260624104459.522a0ee4"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
    "release_date" : "2026-07-01T00:00:00Z",
    "advisory" : "RHSA-2026:34363",
    "cpe" : "cpe:/a:redhat:rhel_eus_long_life:8.4",
    "package" : "postgresql:13-8040020260630100922.522a0ee4"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
    "release_date" : "2026-07-23T00:00:00Z",
    "advisory" : "RHSA-2026:44420",
    "cpe" : "cpe:/a:redhat:rhel_eus_long_life:8.4",
    "package" : "libpq-0:13.23-1.el8_4.1"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
    "release_date" : "2026-06-25T00:00:00Z",
    "advisory" : "RHSA-2026:29815",
    "cpe" : "cpe:/a:redhat:rhel_aus:8.6",
    "package" : "postgresql:12-8060020260623094704.ad008a3a"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
    "release_date" : "2026-06-29T00:00:00Z",
    "advisory" : "RHSA-2026:32994",
    "cpe" : "cpe:/a:redhat:rhel_aus:8.6",
    "package" : "postgresql:13-8060020260625065744.ad008a3a"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
    "release_date" : "2026-06-25T00:00:00Z",
    "advisory" : "RHSA-2026:29815",
    "cpe" : "cpe:/a:redhat:rhel_eus_long_life:8.6",
    "package" : "postgresql:12-8060020260623094704.ad008a3a"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
    "release_date" : "2026-06-29T00:00:00Z",
    "advisory" : "RHSA-2026:32994",
    "cpe" : "cpe:/a:redhat:rhel_eus_long_life:8.6",
    "package" : "postgresql:13-8060020260625065744.ad008a3a"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
    "release_date" : "2026-06-17T00:00:00Z",
    "advisory" : "RHSA-2026:26561",
    "cpe" : "cpe:/a:redhat:rhel_tus:8.8",
    "package" : "postgresql:15-8080020260615085052.63b34585"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
    "release_date" : "2026-07-01T00:00:00Z",
    "advisory" : "RHSA-2026:34043",
    "cpe" : "cpe:/a:redhat:rhel_tus:8.8",
    "package" : "postgresql:12-8080020260626093604.63b34585"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
    "release_date" : "2026-07-06T00:00:00Z",
    "advisory" : "RHSA-2026:35880",
    "cpe" : "cpe:/a:redhat:rhel_tus:8.8",
    "package" : "libpq-0:13.23-1.el8_8.1"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
    "release_date" : "2026-07-21T00:00:00Z",
    "advisory" : "RHSA-2026:42555",
    "cpe" : "cpe:/a:redhat:rhel_tus:8.8",
    "package" : "postgresql:13-8080020260709122729.63b34585"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
    "release_date" : "2026-06-17T00:00:00Z",
    "advisory" : "RHSA-2026:26561",
    "cpe" : "cpe:/a:redhat:rhel_e4s:8.8",
    "package" : "postgresql:15-8080020260615085052.63b34585"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
    "release_date" : "2026-07-01T00:00:00Z",
    "advisory" : "RHSA-2026:34043",
    "cpe" : "cpe:/a:redhat:rhel_e4s:8.8",
    "package" : "postgresql:12-8080020260626093604.63b34585"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
    "release_date" : "2026-07-06T00:00:00Z",
    "advisory" : "RHSA-2026:35880",
    "cpe" : "cpe:/a:redhat:rhel_e4s:8.8",
    "package" : "libpq-0:13.23-1.el8_8.1"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
    "release_date" : "2026-07-21T00:00:00Z",
    "advisory" : "RHSA-2026:42555",
    "cpe" : "cpe:/a:redhat:rhel_e4s:8.8",
    "package" : "postgresql:13-8080020260709122729.63b34585"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2026-06-16T00:00:00Z",
    "advisory" : "RHSA-2026:26203",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "postgresql:16-9080020260605131007.rhel9"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2026-06-16T00:00:00Z",
    "advisory" : "RHSA-2026:26204",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "postgresql:18-9080020260605125734.rhel9"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2026-06-22T00:00:00Z",
    "advisory" : "RHSA-2026:27741",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "postgresql-0:13.23-3.el9_8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2026-06-22T00:00:00Z",
    "advisory" : "RHSA-2026:28037",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "postgresql:15-9080020260605124405.rhel9"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
    "release_date" : "2026-06-25T00:00:00Z",
    "advisory" : "RHSA-2026:29953",
    "cpe" : "cpe:/a:redhat:rhel_e4s:9.2",
    "package" : "postgresql-0:13.23-1.el9_2.2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
    "release_date" : "2026-06-30T00:00:00Z",
    "advisory" : "RHSA-2026:33497",
    "cpe" : "cpe:/a:redhat:rhel_e4s:9.2",
    "package" : "postgresql:15-9020020260625101129.rhel9"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
    "release_date" : "2026-06-17T00:00:00Z",
    "advisory" : "RHSA-2026:26524",
    "cpe" : "cpe:/a:redhat:rhel_e4s:9.4",
    "package" : "postgresql:16-9040020260612132455.rhel9"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
    "release_date" : "2026-06-25T00:00:00Z",
    "advisory" : "RHSA-2026:29904",
    "cpe" : "cpe:/a:redhat:rhel_e4s:9.4",
    "package" : "postgresql-0:13.23-1.el9_4.2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
    "release_date" : "2026-06-30T00:00:00Z",
    "advisory" : "RHSA-2026:33441",
    "cpe" : "cpe:/a:redhat:rhel_e4s:9.4",
    "package" : "postgresql:15-9040020260616071806.rhel9"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.6 Extended Update Support",
    "release_date" : "2026-06-17T00:00:00Z",
    "advisory" : "RHSA-2026:26525",
    "cpe" : "cpe:/a:redhat:rhel_eus:9.6",
    "package" : "postgresql:16-9060020260612084605.rhel9"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.6 Extended Update Support",
    "release_date" : "2026-06-25T00:00:00Z",
    "advisory" : "RHSA-2026:29212",
    "cpe" : "cpe:/a:redhat:rhel_eus:9.6",
    "package" : "postgresql-0:13.23-1.el9_6.2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.6 Extended Update Support",
    "release_date" : "2026-06-29T00:00:00Z",
    "advisory" : "RHSA-2026:32983",
    "cpe" : "cpe:/a:redhat:rhel_eus:9.6",
    "package" : "postgresql:15-9060020260622062902.rhel9"
  }, {
    "product_name" : "Red Hat Ansible Automation Platform 2.2",
    "release_date" : "2026-07-23T00:00:00Z",
    "advisory" : "RHSA-2026:44568",
    "cpe" : "cpe:/a:redhat:ansible_portal:2.2::el9",
    "package" : "ansible-automation-platform/bootc-automation-portal-rhel9:1784804630"
  }, {
    "product_name" : "Red Hat Hardened Images",
    "release_date" : "2026-06-03T00:00:00Z",
    "advisory" : "RHSA-2026:22878",
    "cpe" : "cpe:/a:redhat:hummingbird:1",
    "package" : "postgresql18-main-18.4-0.1.hum1"
  }, {
    "product_name" : "Red Hat Update Infrastructure 5",
    "release_date" : "2026-07-23T00:00:00Z",
    "advisory" : "RHSA-2026:44481",
    "cpe" : "cpe:/a:redhat:rhui:5::el9",
    "package" : "rhui5/rhua-rhel9:1784795076"
  }, {
    "product_name" : "Red Hat Update Infrastructure 5",
    "release_date" : "2026-08-24T00:00:00Z",
    "advisory" : "RHSA-2026:58981",
    "cpe" : "cpe:/a:redhat:rhui:5::el9",
    "package" : "rhui5/rhua-tp-rhel9:1787241260"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 6",
    "fix_state" : "Out of support scope",
    "package_name" : "postgresql",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "fix_state" : "Not affected",
    "package_name" : "postgresql",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "fix_state" : "Not affected",
    "package_name" : "postgresql-jdbc",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8"
  }, {
    "product_name" : "Red Hat Hardened Images",
    "fix_state" : "Not affected",
    "package_name" : "postgresql17",
    "cpe" : "cpe:/a:redhat:hummingbird:1"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-6473\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-6473\nhttps://www.postgresql.org/support/security/CVE-2026-6473/" ],
  "name" : "CVE-2026-6473",
  "mitigation" : {
    "value" : "To mitigate this vulnerability, validate the length of data and the size of objects on all client APIs and web interfaces. Also, block, drop, or truncate oversized string, array, or binary objects before they are passed into backend SQL queries.",
    "lang" : "en:us"
  },
  "csaw" : false
}