Stack-based buffer overflow in PostgreSQL - CVE-2026-14679
Published: August 15, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service and modify server memory.
The vulnerability exists due to stack-based buffer overflow in PostgreSQL argument name matching when processing crafted OUT parameter counts. A remote attacker can create an object with crafted parameters to cause a denial of service and modify server memory.
The memory write is limited to 0x0 and 0x1 byte values.
Affected software
Debian Linux
postgresql-17 (Debian package)
How to mitigate CVE-2026-14679
postgresql-17 (Debian package) - update to 17.11-0+deb13u1