Impact
A type confusion flaw in PostgreSQL’s ctid selectivity estimator enables an object creator to extract a calculation based on an arbitrary 4‑byte memory span, allowing substantial recovery of memory contents. The vulnerability is categorized as a data type confusion (CWE‑843) and can lead to disclosure of sensitive data stored in memory.
Affected Systems
The flaw affects PostgreSQL releases prior to version 18.5, 17.11, 16.15, 15.19, and 14.24.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting no publicly confirmed exploits yet. The likely attack vector requires that an attacker has the ability to create objects within a PostgreSQL database, implying privileged database access or local exploitation.
OpenCVE Enrichment