Integer overflow in PostgreSQL - CVE-2026-14662
Published: August 15, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to integer overflow in tsvector and tsquery data type functions when processing crafted large inputs. A remote user can supply crafted large inputs to cause an undersized allocation and write out-of-bounds to execute arbitrary code.
This may execute code as the operating system user running the database.
Affected software
Debian Linux
postgresql-17 (Debian package)
How to mitigate CVE-2026-14662
postgresql-17 (Debian package) - update to 17.11-0+deb13u1