Type Confusion in PostgreSQL - CVE-2026-16238

 

Type Confusion in PostgreSQL - CVE-2026-16238

Published: August 15, 2026


Vulnerability identifier: #VU142624
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-16238
CWE-ID: CWE-843
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to type confusion in pg_restore_attribute_stats() when restoring attribute statistics involving conflated range and multirange values. A remote user can create a crafted object to execute arbitrary code.

Code execution occurs as the operating system user running the database.


Affected software

PostgreSQL
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
SUSE Package Hub 15
Server Applications Module
Basesystem Module
openSUSE Leap
Ubuntu
postgresql-14 (Ubuntu package)
postgresql18 (Red Hat package)
libecpg6
libecpg6-debuginfo
libpq5-32bit
libpq5-debuginfo-32bit
libecpg6-debuginfo-32bit
libpq5-debuginfo
libecpg6-32bit
libpq5
libpq5-32bit-debuginfo
postgresql18-debuginfo
postgresql18-debugsource
postgresql18-server-devel
postgresql18-plpython
postgresql18-plperl
postgresql18-server
postgresql18-llvmjit-devel
postgresql18-docs
libpq5-64bit
libecpg6-64bit
libpq5-64bit-debuginfo
libecpg6-64bit-debuginfo
libecpg6-32bit-debuginfo
postgresql18-server-devel-debuginfo
postgresql18
postgresql18-devel
postgresql18-llvmjit
postgresql18-pltcl-debuginfo
postgresql18-devel-debuginfo
postgresql18-devel-mini-debuginfo
postgresql18-contrib
postgresql18-devel-mini
postgresql18-mini-debugsource
postgresql18-plpython-debuginfo
postgresql18-server-debuginfo
postgresql18-llvmjit-debuginfo
postgresql18-pltcl
postgresql18-contrib-debuginfo
postgresql18-test
postgresql18-plperl-debuginfo

How to mitigate CVE-2026-16238

Install security update from vendor's website.

PostgreSQL - update to 18.5
postgresql-14 (Ubuntu package) - addressed in versions 14.24-0ubuntu0.22.04.1, 16.15-0ubuntu0.24.04.1, 18.6-0ubuntu0.26.04.1
postgresql18 (Red Hat package) - update to 18.6-1.el10_2
libecpg6 - addressed in versions 18.6-8.17.1, 18.6-150200.5.17.1, 18.6-150600.13.16.1
libecpg6-debuginfo - addressed in versions 18.6-8.17.1, 18.6-150200.5.17.1, 18.6-150600.13.16.1
libpq5-32bit - addressed in versions 18.6-8.17.1, 18.6-150200.5.17.1, 18.6-150600.13.16.1
libpq5-debuginfo-32bit - update to 18.6-8.17.1
libecpg6-debuginfo-32bit - update to 18.6-8.17.1
libpq5-debuginfo - addressed in versions 18.6-8.17.1, 18.6-150200.5.17.1, 18.6-150600.13.16.1
libecpg6-32bit - addressed in versions 18.6-8.17.1, 18.6-150600.13.16.1
libpq5 - addressed in versions 18.6-8.17.1, 18.6-150200.5.17.1, 18.6-150600.13.16.1
libpq5-32bit-debuginfo - addressed in versions 18.6-150200.5.17.1, 18.6-150600.13.16.1
postgresql18-debuginfo - addressed in versions 18.6-150200.5.17.1, 18.6-150600.13.16.1
postgresql18-debugsource - addressed in versions 18.6-150200.5.17.1, 18.6-150600.13.16.1
postgresql18-server-devel - update to 18.6-150600.13.16.1
postgresql18-plpython - update to 18.6-150600.13.16.1
postgresql18-plperl - update to 18.6-150600.13.16.1
postgresql18-server - update to 18.6-150600.13.16.1
postgresql18-llvmjit-devel - update to 18.6-150600.13.16.1
postgresql18-docs - update to 18.6-150600.13.16.1
libpq5-64bit - update to 18.6-150600.13.16.1
libecpg6-64bit - update to 18.6-150600.13.16.1
libpq5-64bit-debuginfo - update to 18.6-150600.13.16.1
libecpg6-64bit-debuginfo - update to 18.6-150600.13.16.1
libecpg6-32bit-debuginfo - update to 18.6-150600.13.16.1
postgresql18-server-devel-debuginfo - update to 18.6-150600.13.16.1
postgresql18 - update to 18.6-150600.13.16.1
postgresql18-devel - update to 18.6-150600.13.16.1
postgresql18-llvmjit - update to 18.6-150600.13.16.1
postgresql18-pltcl-debuginfo - update to 18.6-150600.13.16.1
postgresql18-devel-debuginfo - update to 18.6-150600.13.16.1
postgresql18-devel-mini-debuginfo - update to 18.6-150600.13.16.1
postgresql18-contrib - update to 18.6-150600.13.16.1
postgresql18-devel-mini - update to 18.6-150600.13.16.1
postgresql18-mini-debugsource - update to 18.6-150600.13.16.1
postgresql18-plpython-debuginfo - update to 18.6-150600.13.16.1
postgresql18-server-debuginfo - update to 18.6-150600.13.16.1
postgresql18-llvmjit-debuginfo - update to 18.6-150600.13.16.1
postgresql18-pltcl - update to 18.6-150600.13.16.1
postgresql18-contrib-debuginfo - update to 18.6-150600.13.16.1
postgresql18-test - update to 18.6-150600.13.16.1
postgresql18-plperl-debuginfo - update to 18.6-150600.13.16.1

External References

Related Security Bulletins