Impact
The updated description explains that a type confusion error involving PostgreSQL’s internal data type allows any database user to invoke a function with that internal argument. The internal type contains structure definitions that are not designed for SQL access. When encountered, PostgreSQL attempts to process the argument as a different type, leading to an arbitrary code execution with the privileges of the database server’s operating‑system account. An attacker able to call such a function can gain full control of the database server and the underlying host.
Affected Systems
PostgreSQL database servers prior to version 18.6, 17.11, 16.15, 15.19, or 14.24 are affected.
Risk and Exploitability
The CVSS score of 8.8 reflects high severity and full exploitation potential. The EPSS score, which is less than 1%, indicates a very low but nonzero exploitation probability. The flaw is not listed in the CISA KEV catalog, yet the availability of a high‑impact vulnerability indicates that it could be abused in the wild. The attack vector requires a user to invoke a function with an internal argument, which is possible for any database user. Once invoked, the attacker gains operating‑system level code execution, making the risk extremely high for untrusted or poorly isolated database users.
OpenCVE Enrichment
Debian DLA
Debian DSA
Ubuntu USN