Impact
Type confusion in PostgreSQL’s refint module allows an object creator to execute arbitrary code as the operating system user running the database. The fix for this vulnerability was introduced in the source code with the commit message "refint: Remove plan cache.", but no CVE was assigned. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Affected Systems
The vulnerability affects PostgreSQL releases prior to 18.6, 17.11, 16.15, 15.19, and 14.24. Users running any of these versions on a PostgreSQL server are at risk.
Risk and Exploitability
The CVSS score is 8.8, indicating high severity. The EPSS score is < 1%, indicating a very low exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires a user with object‑creation privileges within the database; once such a user introduces a malicious refint object, the code runs with the database process’s OS privileges.
OpenCVE Enrichment
Debian DLA
Debian DSA
Ubuntu USN