Impact
IVFFlat index build in pgvector versions prior to 0.8.7 contains a buffer overflow that allows a database user to write memory outside the bounds of an internal buffer. The write can corrupt trusted execution context, resulting in arbitrary code execution within the database process. The issue stems from improper bounds checking during the construction of the approximate nearest neighbor index.
Affected Systems
The vulnerability affects the pgvector extension for PostgreSQL. Any installation using pgvector older than version 0.8.7 is vulnerable when creating IVFFlat indices. The specific CNA vendor/product is 'pgvector', and the affected versions are all releases before 0.8.7. The extension must be updated or removed to eliminate the risk.
Risk and Exploitability
The CVSS score of 8.8 reflects a high severity with impact on confidentiality, integrity, and availability, classified as arbitrary code execution. The EPSS score is not available, so the exact likelihood of exploitation is unknown, but the flaw allows local database users to trigger the overflow. The vulnerability is not listed in the CISA KEV catalog. Attackers can initiate the exploit by executing a CREATE INDEX statement that triggers the IVFFlat build, thereby requiring privileged database user rights or the ability to run arbitrary SQL. The lack of a public exploit reduces risk, but the high CVSS warrants immediate attention.
OpenCVE Enrichment