CVE-2026-6477
PostgreSQL: libpq large object functions let a server superuser overwrite client stack memory
Technology
PostgreSQL
CVSS Score
8.8 / 10.0
Affected Versions
Before 18.4, 17.10, 16.14, 15.18 and 14.23 (supported versions only; 13 and older not assessed)
Upstream Fix
18.4; 17.10; 16.14; 15.18; 14.23
Published
May 14, 2026
OSSeva Coverage
Fixed upstream
Description
libpq's lo_export(), lo_read(), lo_lseek64() and lo_tell64() used PQfn with result_is_int=0, which stores a server-determined amount of data into a buffer of unspecified size. A server superuser could send an oversized response and overwrite the client's stack. psql's \lo_export and pg_dump both call lo_read(), so the attack reaches those tools. Scored 8.8 by PostgreSQL as the CNA. Fixed in 18.4, 17.10, 16.14, 15.18 and 14.23.
Is your PostgreSQL deployment affected?
If you're running Before 18.4, 17.10, 16.14, 15.18 and 14.23 (supported versions only; 13 and older not assessed), you need this patch. Book a discovery call to get covered.