Impact
TimescaleDB versions up to 2.29.1 contain a flaw in the Gorilla compression reverse row iterator that allows an authenticated attacker with DML rights to a compressed hypertable to trigger an unsigned integer wraparound during bucket index calculation. This overflow causes an out‑of‑bounds read of the internal bucket array, resulting in a SIGSEGV crash. The crash can be repeatedly triggered on each subsequent reverse‑order scan, leading to a denial of service.
Affected Systems
The vulnerability affects the TimescaleDB product from Timescale, specifically version 2.29.1. The issue was addressed in commit 517c13e; any release that incorporates that commit or later versions is considered fixed.
Risk and Exploitability
The CVSS score of 7.1 categorizes the issue as medium severity. The EPSS score is not available, suggesting the likelihood of exploitation is uncertain but not high. The vulnerability is not currently listed in CISA KEV and requires authenticated DML access to a compressed hypertable, implying it is a privilege‑dependent attack.
OpenCVE Enrichment