Impact
A stack buffer overflow exists in PostgreSQL’s argument name matching routine. An object creator can trigger the overflow by supplying a specially crafted OUT parameter count, causing the server to write only 0x0 and 0x1 bytes into memory. The exact impact remains unspecified, but the nature of the flaw, a classic stack overflow, implies the potential to corrupt stack data and achieve remote code execution or other destructive operations.
Affected Systems
The vulnerability targets PostgreSQL database servers. Versions prior to 18.6, 17.11, 16.15, 15.19, and 14.24 are affected. No other vendors are listed in the attribution.
Risk and Exploitability
The flaw has a CVSS score of 8.2, indicating high severity. The EPSS score indicates a very low exploitation probability (<1%). The vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves an entity with the ability to create database objects, such as through crafted SQL commands, potentially from a remote client if the database is exposed. Because the precise impact is unknown, the risk remains significant due to the inherent danger of a stack buffer overflow and the high severity rating.
OpenCVE Enrichment
Debian DLA
Debian DSA
Ubuntu USN