Integer overflow in PostgreSQL - CVE-2026-15742
Published: August 15, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to integer overflow in the fuzzystrmatch levenshtein() and levenshtein_less_equal() functions when processing extreme SQL inputs. A remote user can supply crafted input values to direct writes to a huge range of addresses and execute arbitrary code.
Code execution occurs as the operating system user running the database.
Affected software
Debian Linux
postgresql-17 (Debian package)
How to mitigate CVE-2026-15742
postgresql-17 (Debian package) - update to 17.11-0+deb13u1