Integer underflow in PostgreSQL - CVE-2026-16241
Published: August 15, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to integer underflow in the ECPG client when processing a bytea value lacking the mandatory prefix. A remote privileged user can send a specially crafted bytea value to cause a denial of service.
In rare cases, the overwrite may also cause limited client-specific integrity impact.
Affected software
Debian Linux
postgresql-17 (Debian package)
How to mitigate CVE-2026-16241
postgresql-17 (Debian package) - update to 17.11-0+deb13u1