Impact
A NULL pointer dereference allows an unauthenticated attacker to terminate the Pgpool-II watchdog process. Because the watchdog supervises the database connection pool, its abrupt crash can lead to loss of service for database connections and effectively deny users the ability to access the database cluster. The vulnerability is a classic memory-safety flaw and does not directly compromise confidentiality or integrity, but it disrupts availability.
Affected Systems
Pgpool-II provided by the Pgpool Global Development Group. No specific affected versions are listed, so all released versions are potentially vulnerable until an update is applied.
Risk and Exploitability
The CVSS base score of 8.7 indicates a high severity vulnerability. No EPSS data is available, and the vulnerability is not listed in the CISA KEV catalog, suggesting it is not widely exploited at present. The flaw is reachable without authentication, so an attacker could trigger it from any network location with access to the Pgpool-II service. Once triggered, the watchdog process terminates, leaving the system without active supervision, which can cause a cascading failure in the database pool.
OpenCVE Enrichment