Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-6477

PostgreSQL: libpq large object functions let a server superuser overwrite client stack memory

Technology

PostgreSQL

CVSS Score

8.8 / 10.0

Affected Versions

Before 18.4, 17.10, 16.14, 15.18 and 14.23 (supported versions only; 13 and older not assessed)

Upstream Fix

18.4; 17.10; 16.14; 15.18; 14.23

Published

May 14, 2026

OSSeva Coverage

Fixed upstream

Description

libpq's lo_export(), lo_read(), lo_lseek64() and lo_tell64() used PQfn with result_is_int=0, which stores a server-determined amount of data into a buffer of unspecified size. A server superuser could send an oversized response and overwrite the client's stack. psql's \lo_export and pg_dump both call lo_read(), so the attack reaches those tools. Scored 8.8 by PostgreSQL as the CNA. Fixed in 18.4, 17.10, 16.14, 15.18 and 14.23.

Upstream record: NVD · CVE.org

Is your PostgreSQL deployment affected?

If you're running Before 18.4, 17.10, 16.14, 15.18 and 14.23 (supported versions only; 13 and older not assessed), you need this patch. Book a discovery call to get covered.