Impact
Heap buffer overflow in PostgreSQL plperl, triggered by the return of a tied hash, lets a function owner execute arbitrary code as the operating system user running the database, via a crafted function body. This classic buffer overflow (CWE‑122) overflows internal memory when the tied hash is returned, giving the attacker control over the database server.
Affected Systems
The vulnerability affects PostgreSQL, versions before 18.6, 17.11, 16.15, 15.19, and 14.24. Users running any of those releases need to upgrade to the patched versions listed above or newer.
Risk and Exploitability
The CVSS score is 8.8, indicating a high severity, while the EPSS score is < 1%, leaving the likelihood of exploitation uncertain. The vulnerability is not listed in the CISA KEV catalog. Attackers who can create or modify PL/Perl functions with a crafted body can exploit the buffer overflow, potentially running arbitrary code as the database server's operating system user.
OpenCVE Enrichment
Debian DLA
Debian DSA
Ubuntu USN