Heap-based buffer overflow in PostgreSQL - CVE-2026-14670
Published: August 15, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to heap-based buffer overflow in the PostgreSQL plperl tied hash return handling when processing a crafted function body that returns a tied hash. A remote user can create a crafted function body to execute arbitrary code.
The code executes as the operating system user running the database.
Affected software
Debian Linux
postgresql-17 (Debian package)
How to mitigate CVE-2026-14670
postgresql-17 (Debian package) - update to 17.11-0+deb13u1