Buffer over-read in PostgreSQL function pg_restore_attribute_stats() accepts array values of unmatched length, which causes query planning to read past end of one array. This allows a table maintainer to infer memory values past that array end. Within major version 18, minor versions before PostgreSQL 18.4 are affected. Versions before PostgreSQL 18 are unaffected.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 14 May 2026 13:30:00 +0000

Type Values Removed Values Added
Description Buffer over-read in PostgreSQL function pg_restore_attribute_stats() accepts array values of unmatched length, which causes query planning to read past end of one array. This allows a table maintainer to infer memory values past that array end. Within major version 18, minor versions before PostgreSQL 18.4 are affected. Versions before PostgreSQL 18 are unaffected.
Title PostgreSQL pg_restore_attribute_stats accepts values that cause query planning to read past end of stats array
Weaknesses CWE-126
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: PostgreSQL

Published:

Updated: 2026-05-14T13:00:14.542Z

Reserved: 2026-04-19T00:06:35.060Z

Link: CVE-2026-6575

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-05-14T14:16:25.693

Modified: 2026-05-14T14:16:25.693

Link: CVE-2026-6575

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses