« Volver al listado

CVE-2026-16241

Estado: ModificadaBaja (3.8)—

Integer underflow in PostgreSQL ECPG allows a database server administrator to achieve temporary denial of service against the ECPG client via sending a bytea value lacking the mandatory prefix. The client overwrites a huge memory region with bytes outside attacker knowledge or control. This typically yields a simple SIGSEGV, but rare cases might achieve client-specific integrity impact via the write. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-16241",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-16241",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-08-13T13:30:50.360487Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 3.8,
          "attackVector": "NETWORK",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 2.5,
        "exploitabilityScore": 1.2
      }
    ]
  },
  "affected": [
    {
      "source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "PostgreSQL",
          "versions": [
            {
              "status": "affected",
              "version": "18",
              "lessThan": "18.6",
              "versionType": "rpm"
            },
            {
              "status": "affected",
              "version": "17",
              "lessThan": "17.11",
              "versionType": "rpm"
            },
            {
              "status": "affected",
              "version": "16",
              "lessThan": "16.15",
              "versionType": "rpm"
            },
            {
              "status": "affected",
              "version": "15",
              "lessThan": "15.19",
              "versionType": "rpm"
            },
            {
              "status": "affected",
              "version": "0",
              "lessThan": "14.24",
              "versionType": "rpm"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-08-13T13:17:46.670",
  "references": [
    {
      "url": "https://www.postgresql.org/support/security/CVE-2026-16241/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
      "description": [
        {
          "lang": "en",
          "value": "CWE-191"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Integer underflow in PostgreSQL ECPG allows a database server administrator to achieve temporary denial of service against the ECPG client via sending a bytea value lacking the mandatory prefix.  The client overwrites a huge memory region with bytes outside attacker knowledge or control.  This typically yields a simple SIGSEGV, but rare cases might achieve client-specific integrity impact via the write.  Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected."
    }
  ],
  "lastModified": "2026-08-29T23:17:19.957",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6BEE5714-C2EF-48DC-8613-C3EAA149E12E",
              "versionEndExcluding": "14.24",
              "versionStartIncluding": "14.0"
            },
            {
              "criteria": "cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F433746A-733F-4ED0-9913-8AF69E0C8BF2",
              "versionEndExcluding": "15.19",
              "versionStartIncluding": "15.0"
            },
            {
              "criteria": "cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1996B91F-E0B2-4A78-8788-E17EA68D179C",
              "versionEndExcluding": "16.15",
              "versionStartIncluding": "16.0"
            },
            {
              "criteria": "cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3D04E642-71D7-4979-AA19-B9CCDEFD8C31",
              "versionEndExcluding": "17.11",
              "versionStartIncluding": "17.0"
            },
            {
              "criteria": "cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8494F67B-673A-4E1F-8F40-D24DCC1F8DA4",
              "versionEndExcluding": "18.5",
              "versionStartIncluding": "18.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"
}