Skip to content

CVE-2026-16241 on CTRL-OS 26.05

Aliases: CVE-2026-16241

Packages: postgresql_14, postgresql_15, postgresql_16, postgresql_17, postgresql_18

Status: Plausible

Advisory Information

Integer underflow in PostgreSQL ECPG allows a database server administrator to achieve temporary denial of service against the ECPG client via sending a bytea value lacking the mandatory prefix. The client overwrites a huge memory region with bytes outside attacker knowledge or control. This typically yields a simple SIGSEGV, but rare cases might achieve client-specific integrity impact via the write. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.

Updates

2026-08-14 18:02 CEST

Metadata changes:

  • Status for package postgresql_14: “Plausible
  • Status for package postgresql_15: “Plausible
  • Status for package postgresql_16: “Plausible
  • Status for package postgresql_17: “Plausible
  • Status for package postgresql_18: “Plausible

(Amended on: 2026-08-14 18:03 CEST)

2026-08-14 18:02 CEST

Metadata changes:

  • Status for package postgresql_14: “New
  • Status for package postgresql_15: “New
  • Status for package postgresql_16: “New
  • Status for package postgresql_17: “New
  • Status for package postgresql_18: “New