Impact
Integer wraparound in PostgreSQL 32‑bit builds of the pltcl and plperl procedural languages allows an object creator to cause a negative allocation size during function body parsing, resulting in an out‑of‑bounds write. This enables the attacker to overwrite memory and execute arbitrary code as the operating system user that owns the database server, a flaw rooted in unchecked integer arithmetic (CWE‑190). Similar issues were addressed by CVE‑2026‑6473. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Affected Systems
PostgreSQL 32‑bit installations that include the pltcl and plperl extensions are vulnerable. Versions prior to 18.6, 17.11, 16.15, 15.19, and 14.24 are affected. The issue does not exist in newer releases or in 64‑bit builds.
Risk and Exploitability
The CVSS score of 8.8 classifies this vulnerability as high severity. The EPSS score of less than 1% signals a very low probability of exploitation. It is not listed in CISA’s KEV catalog, so no known active exploits are reported. The likely attack vector is via crafted function bodies submitted by a user with privileges to create or alter extensions, after which malicious code would run with database server privileges.
OpenCVE Enrichment
Debian DLA
Debian DSA
Ubuntu USN