Impact
The vulnerability resides in the pg_partman PostgreSQL extension, which manages partitioned tables for time or ID based partitioning. The run_maintenance function processes rows from the part_config table, but before version 5.5.0 it exits the loop when any exception occurs outside the row‑processing loop. An attacker who possesses partman_user privileges can insert or update a row that intentionally triggers an exception, assigning it a low maintenance_order so that it is processed first. Each subsequent maintenance tick then aborts before legitimate partition sets are maintained, causing a loss of automated partition maintenance throughout the database. This defect effectively degrades database availability and reliability as partitions are not periodically maintained, potentially leading to performance degradation or data inconsistency.
Affected Systems
Products impacted include the pgpartman pg_partman extension for PostgreSQL. Versions earlier than 5.5.0 are vulnerable; the issue is resolved in version 5.5.0 and later.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity impact, with no EPSS score available so the exploitation probability cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires access to a role with partman_user privileges and the ability to modify the part_config table, implying a local or privileged database attack vector. Given the medium severity and the need for specific role permissions, the overall risk is moderate, but should be mitigated promptly by applying the vendor fix.
OpenCVE Enrichment