{"id":"CVE-2026-14662","title":"Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds, via crafted large inputs","summary":"Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds, via crafted large inputs.  This may execute arbitrary …","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-190","CWE-787"],"vendor":"postgresql","product":"postgresql","affected":["postgresql >= 14.0, < 14.24","postgresql >= 15.0, < 15.19","postgresql >= 16.0, < 16.15","postgresql >= 17.0, < 17.11","postgresql >= 18.0, < 18.5"],"patched":["postgresql 18.5"],"published":"2026-08-13","updated":"2026-08-29","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-14662","references":[{"url":"https://www.postgresql.org/support/security/CVE-2026-14662/","label":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-14662.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-14662"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2515302"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-14662"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-14662"},{"url":"https://access.redhat.com/errata/RHSA-2026:67280"},{"url":"https://access.redhat.com/errata/RHSA-2026:67491"},{"url":"https://access.redhat.com/errata/RHSA-2026:67848"},{"url":"https://access.redhat.com/errata/RHSA-2026:69698"},{"url":"https://access.redhat.com/errata/RHSA-2026:70186"},{"url":"https://access.redhat.com/errata/RHSA-2026:69923"},{"url":"https://access.redhat.com/errata/RHSA-2026:69876"},{"url":"https://access.redhat.com/errata/RHSA-2026:69914"},{"url":"https://access.redhat.com/errata/RHSA-2026:69607"},{"url":"https://access.redhat.com/errata/RHSA-2026:69924"},{"url":"https://access.redhat.com/errata/RHSA-2026:70602"},{"url":"https://access.redhat.com/errata/RHSA-2026:70763"},{"url":"https://access.redhat.com/errata/RHSA-2026:70762"},{"url":"https://access.redhat.com/errata/RHSA-2026:70856"},{"url":"https://access.redhat.com/errata/RHSA-2026:70559"}],"tags":["nvd","exploit-available","csaf","vex","red-hat"],"epss":0.0046,"epssPercentile":0.39158,"ingestedAt":"2026-08-29T23:43:52.870Z","exploits":{"github":1,"githubRepos":["https://github.com/Kihara-1/postgresql-cve-2026-14662"],"checkedAt":"2026-09-24T07:52:58.035Z"},"exploitAvailable":true,"slug":"CVE-2026-14662","body":"## Overview\n\nInteger wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds, via crafted large inputs.  This may execute arbitrary code as the operating system user running the database.  These types are typically sourced from application logic, not taken from the application's user.  Hence, application users attacking the database, through the application as a conduit, are unlikely.  CVE-2026-6473 had fixed similar problems.  Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.\n\n## Affected\n\n- `postgresql >= 14.0, < 14.24`\n- `postgresql >= 15.0, < 15.19`\n- `postgresql >= 16.0, < 16.15`\n- `postgresql >= 17.0, < 17.11`\n- `postgresql >= 18.0, < 18.5`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `postgresql 18.5`\n\n## Vendor advisories\n\n- **RHSA-2026:67280** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10), Red Hat Enterprise Linux CodeReady Linux Builder (v. 10) · released 2026-09-14 · [advisory](https://access.redhat.com/errata/RHSA-2026:67280)\n- **Red Hat VEX** · Important · affected: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Self-service automation portal 2 · no fix planned: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Self-service automation portal 2 · updated 2026-09-23 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-14662.json)\n- **RHSA-2026:67491** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2026-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:67491)\n- **RHSA-2026:67848** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:67848)\n- **RHSA-2026:69698** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v.9.6) · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69698)\n- **RHSA-2026:70186** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10), Red Hat Enterprise Linux CodeReady Linux Builder (v. 10) · released 2026-09-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:70186)\n- **RHSA-2026:69923** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8) · released 2026-09-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:69923)\n- **RHSA-2026:69876** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8) · released 2026-09-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:69876)\n- **RHSA-2026:69914** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2026-09-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:69914)\n- **RHSA-2026:69607** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9), Red Hat Enterprise Linux CodeReady Linux Builder (v. 9) · released 2026-09-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:69607)\n- **RHSA-2026:69924** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8) · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:69924)\n- **RHSA-2026:70602** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.8.8), Red Hat Enterprise Linux AppStream TUS (v.8.8) · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:70602)\n- **RHSA-2026:70763** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.2) · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:70763)\n- **RHSA-2026:70762** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.4) · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:70762)\n- **RHSA-2026:70856** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.4) · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:70856)\n- **RHSA-2026:70559** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v.9.6) · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:70559)","depth":"midnight","depthScore":60,"depthScoreParts":{"impact":48.4,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[{"seq":4956,"id":"CVE-2026-14662","ts":1788887219351,"field":"exploit_available","old":"false","new":"true"},{"seq":3839,"id":"CVE-2026-14662","ts":1788886352268,"field":"exploit_available","old":"true","new":"false"},{"seq":2673,"id":"CVE-2026-14662","ts":1788883016937,"field":"exploit_available","old":"false","new":"true"},{"seq":1702,"id":"CVE-2026-14662","ts":1788882421433,"field":"exploit_available","old":"true","new":"false"},{"seq":809,"id":"CVE-2026-14662","ts":1788881855330,"field":"exploit_available","old":"false","new":"true"}]}