Out-of-bounds read in PostgreSQL - CVE-2026-6575

 

Out-of-bounds read in PostgreSQL - CVE-2026-6575

Published: May 14, 2026


Vulnerability identifier: #VU131462
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-6575
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to an out-of-bounds read in the pg_restore_attribute_stats() function when accepting array values of unmatched length. A remote user can supply crafted array values to disclose sensitive information.

The issue allows a table maintainer to infer memory values past the end of one stats array.


Affected software

PostgreSQL
Gentoo Linux
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
Basesystem Module
SUSE Package Hub 15
Server Applications Module
openSUSE Leap
Ubuntu
dev-db/postgresql
postgresql-14 (Ubuntu package)
libpq5-debuginfo-32bit
libecpg6-debuginfo
libpq5
libpq5-debuginfo
libecpg6
libecpg6-32bit
libpq5-32bit
libecpg6-debuginfo-32bit
libpq5-32bit-debuginfo
postgresql18-debugsource
postgresql18-debuginfo
libpq5-64bit
libecpg6-64bit-debuginfo
libpq5-64bit-debuginfo
libecpg6-64bit
postgresql18-docs
libecpg6-32bit-debuginfo
postgresql18-plperl-debuginfo
postgresql18
postgresql18-devel-mini-debuginfo
postgresql18-plpython
postgresql18-llvmjit
postgresql18-server-devel
postgresql18-contrib-debuginfo
postgresql18-devel-debuginfo
postgresql18-plperl
postgresql18-mini-debugsource
postgresql18-llvmjit-devel
postgresql18-devel
postgresql18-contrib
postgresql18-test
postgresql18-pltcl
postgresql18-server-debuginfo
postgresql18-devel-mini
postgresql18-plpython-debuginfo
postgresql18-pltcl-debuginfo
postgresql18-server
postgresql18-server-devel-debuginfo
postgresql18-llvmjit-debuginfo

How to mitigate CVE-2026-6575

Install security update from vendor's website.

PostgreSQL - update to 18.4
dev-db/postgresql - update to 9.0.5
postgresql-14 (Ubuntu package) - addressed in versions 14.23-0ubuntu0.22.04.1, 16.14-0ubuntu0.24.04.1, 17.10-0ubuntu0.25.10.1, 18.4-0ubuntu0.26.04.1
libpq5-debuginfo-32bit - update to 18.4-8.12.1
libecpg6-debuginfo - addressed in versions 18.4-8.12.1, 18.4-150200.5.12.1, 18.4-150600.13.11.1
libpq5 - addressed in versions 18.4-8.12.1, 18.4-150200.5.12.1, 18.4-150600.13.11.1
libpq5-debuginfo - addressed in versions 18.4-8.12.1, 18.4-150200.5.12.1, 18.4-150600.13.11.1
libecpg6 - addressed in versions 18.4-8.12.1, 18.4-150200.5.12.1, 18.4-150600.13.11.1
libecpg6-32bit - addressed in versions 18.4-8.12.1, 18.4-150600.13.11.1
libpq5-32bit - addressed in versions 18.4-8.12.1, 18.4-150200.5.12.1, 18.4-150600.13.11.1
libecpg6-debuginfo-32bit - update to 18.4-8.12.1
libpq5-32bit-debuginfo - addressed in versions 18.4-150200.5.12.1, 18.4-150600.13.11.1
postgresql18-debugsource - addressed in versions 18.4-150200.5.12.1, 18.4-150600.13.11.1
postgresql18-debuginfo - addressed in versions 18.4-150200.5.12.1, 18.4-150600.13.11.1
libpq5-64bit - update to 18.4-150600.13.11.1
libecpg6-64bit-debuginfo - update to 18.4-150600.13.11.1
libpq5-64bit-debuginfo - update to 18.4-150600.13.11.1
libecpg6-64bit - update to 18.4-150600.13.11.1
postgresql18-docs - update to 18.4-150600.13.11.1
libecpg6-32bit-debuginfo - update to 18.4-150600.13.11.1
postgresql18-plperl-debuginfo - update to 18.4-150600.13.11.1
postgresql18 - update to 18.4-150600.13.11.1
postgresql18-devel-mini-debuginfo - update to 18.4-150600.13.11.1
postgresql18-plpython - update to 18.4-150600.13.11.1
postgresql18-llvmjit - update to 18.4-150600.13.11.1
postgresql18-server-devel - update to 18.4-150600.13.11.1
postgresql18-contrib-debuginfo - update to 18.4-150600.13.11.1
postgresql18-devel-debuginfo - update to 18.4-150600.13.11.1
postgresql18-plperl - update to 18.4-150600.13.11.1
postgresql18-mini-debugsource - update to 18.4-150600.13.11.1
postgresql18-llvmjit-devel - update to 18.4-150600.13.11.1
postgresql18-devel - update to 18.4-150600.13.11.1
postgresql18-contrib - update to 18.4-150600.13.11.1
postgresql18-test - update to 18.4-150600.13.11.1
postgresql18-pltcl - update to 18.4-150600.13.11.1
postgresql18-server-debuginfo - update to 18.4-150600.13.11.1
postgresql18-devel-mini - update to 18.4-150600.13.11.1
postgresql18-plpython-debuginfo - update to 18.4-150600.13.11.1
postgresql18-pltcl-debuginfo - update to 18.4-150600.13.11.1
postgresql18-server - update to 18.4-150600.13.11.1
postgresql18-server-devel-debuginfo - update to 18.4-150600.13.11.1
postgresql18-llvmjit-debuginfo - update to 18.4-150600.13.11.1

External References

Related Security Bulletins