Impact
A type confusion flaw in PostgreSQL’s ctid selectivity estimator allows an object creator to use a non‑ctid input to recover an approximate calculation derived from an arbitrary 4‑byte memory span, enabling substantial recovery of memory contents. This data type confusion (CWE‑843) can lead to disclosure of sensitive in‑memory data.
Affected Systems
Prior to PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24, versions are affected. The flaw specifically targets releases before those major‑version patch numbers.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity. The EPSS score is less than 1%, indicating a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting no publicly confirmed exploits yet. Based on the description, the likely attack vector is that an attacker must create objects within a PostgreSQL database, implying privileged database access or local exploitation.
OpenCVE Enrichment
Debian DLA
Debian DSA
Ubuntu USN