Impact
Based on the updated CVE description, PostgreSQL's incomplete tracking of role changes leads to stale row‑level security policies, allowing users who have recently lost privileges to read or modify rows they should no longer access.
Affected Systems
PostgreSQL instances running any version prior to 18.6, 17.11, 16.15, 15.19, or 14.24 are affected.
Risk and Exploitability
The CVSS score of 4.2 indicates a moderate impact. The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is via plan reuse after a role or ownership change that alters row‑level security requirements; an attacker then executes a query that reuses the stale plan. This attack path requires knowledge of the application’s privilege model and is therefore less likely to be widely exploitable, but it remains a concern for environments that rely heavily on role‑specific row security.
OpenCVE Enrichment
Debian DLA
Debian DSA
Ubuntu USN