CVE-2026-16238

EUVD-2026-57848
Type confusion in PostgreSQL pg_restore_attribute_stats() allows an object creator to execute arbitrary code as the operating system user running the database, via conflation of range and multirange values.  Within major version 18, minor versions before PostgreSQL 18.5 are affected.  Versions before PostgreSQL 18 are unaffected.
Type Confusion
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Debian logo
Debian Releases
Debian Product
Codename
postgresql-13
bullseye
13.16-0+deb11u1
fixed
bullseye (security)
13.23-0+deb11u4
fixed
postgresql-15
bookworm
15.18-0+deb12u1
fixed
bookworm (security)
15.19-0+deb12u1
fixed
postgresql-17
trixie
17.10-0+deb13u1
fixed
trixie (security)
17.11-0+deb13u1
fixed
postgresql-18
forky
vulnerable
sid
vulnerable