CVE-2026-6477: Use of Inherently Dangerous Function in PostgreSQL
Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
AI Analysis
Technical Summary
This vulnerability arises from the use of an inherently unsafe function PQfn in PostgreSQL's libpq client library, which does not properly limit the size of data copied into client stack buffers in functions lo_export(), lo_read(), lo_lseek64(), and lo_tell64(). A malicious PostgreSQL server superuser can exploit this to send an arbitrarily large response, causing a stack buffer overflow on the client side. This can overwrite stack memory in client tools such as psql and pg_dump, potentially leading to arbitrary code execution. The vulnerability affects PostgreSQL versions before 18.4, 17.10, 16.14, 15.18, and 14.23. Exploitation requires user interaction in connecting to a malicious or compromised server. The CVSS v3.1 base score is 8.8 (high severity) with network attack vector, low complexity, high privileges required on the server, and user interaction required on the client. The scope is changed as the attack affects the client system. Red Hat and PostgreSQL have released patches addressing this issue.
Potential Impact
A malicious PostgreSQL server superuser can exploit this vulnerability to overwrite client stack memory when a client connects using vulnerable versions of libpq functions. This can lead to arbitrary code execution on the client system, compromising confidentiality, integrity, and availability. The vulnerability affects client tools such as psql and pg_dump. Exploitation requires the client to connect to a malicious or compromised server and involves user interaction. No known exploits in the wild have been reported at this time.
Mitigation Recommendations
A fix is available in PostgreSQL versions 18.4, 17.10, 16.14, 15.18, and 14.23 and later. Users should upgrade to these fixed versions or later. Until patched, users should avoid connecting to untrusted or potentially compromised PostgreSQL servers using psql, pg_dump, or other client tools that use the vulnerable libpq functions. The vendor advisory explicitly recommends only connecting to trusted servers as a mitigation. No other specific mitigations are noted.
CVE-2026-6477: Use of Inherently Dangerous Function in PostgreSQL
Description
Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
CVSS v3.1
Score 8.8high
Affected software
PostgreSQL
pkg:deb/postgresql/postgresqlRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability arises from the use of an inherently unsafe function PQfn in PostgreSQL's libpq client library, which does not properly limit the size of data copied into client stack buffers in functions lo_export(), lo_read(), lo_lseek64(), and lo_tell64(). A malicious PostgreSQL server superuser can exploit this to send an arbitrarily large response, causing a stack buffer overflow on the client side. This can overwrite stack memory in client tools such as psql and pg_dump, potentially leading to arbitrary code execution. The vulnerability affects PostgreSQL versions before 18.4, 17.10, 16.14, 15.18, and 14.23. Exploitation requires user interaction in connecting to a malicious or compromised server. The CVSS v3.1 base score is 8.8 (high severity) with network attack vector, low complexity, high privileges required on the server, and user interaction required on the client. The scope is changed as the attack affects the client system. Red Hat and PostgreSQL have released patches addressing this issue.
Potential Impact
A malicious PostgreSQL server superuser can exploit this vulnerability to overwrite client stack memory when a client connects using vulnerable versions of libpq functions. This can lead to arbitrary code execution on the client system, compromising confidentiality, integrity, and availability. The vulnerability affects client tools such as psql and pg_dump. Exploitation requires the client to connect to a malicious or compromised server and involves user interaction. No known exploits in the wild have been reported at this time.
Mitigation Recommendations
A fix is available in PostgreSQL versions 18.4, 17.10, 16.14, 15.18, and 14.23 and later. Users should upgrade to these fixed versions or later. Until patched, users should avoid connecting to untrusted or potentially compromised PostgreSQL servers using psql, pg_dump, or other client tools that use the vulnerable libpq functions. The vendor advisory explicitly recommends only connecting to trusted servers as a mitigation. No other specific mitigations are noted.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- PostgreSQL
- Date Reserved
- 2026-04-17T00:44:19.965Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-6477","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:27718","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:27743","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:27742","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:27738","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:26181","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:29815","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:32994","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:26561","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:29953","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:26524","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:29904","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:32983","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:26525","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:29212","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:28037","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:26203","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:26204","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:27741","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:21182","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:22878","vendor":"Red Hat"}]
Threat ID: 6a05cfe8ec166c07b0e13947
Added to database: 05/14/2026, 13:36:40 UTC
Last enriched: 08/15/2026, 14:24:16 UTC
Last updated: 09/12/2026, 22:01:36 UTC
Views: 173
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.