CVE-2026-15742

NameCVE-2026-15742
DescriptionInteger wraparound in PostgreSQL fuzzystrmatch allows a user to direct writes to a huge range of addresses, executing arbitrary code as the operating system user running the database, via extreme inputs to SQL function levenshtein() or levenshtein_less_equal(). Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-4740-1, DSA-6438-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
postgresql-13 (PTS)bullseye13.16-0+deb11u1vulnerable
bullseye (security)13.23-0+deb11u4vulnerable
postgresql-15 (PTS)bookworm15.18-0+deb12u1vulnerable
bookworm (security)15.19-0+deb12u1fixed
postgresql-17 (PTS)trixie17.10-0+deb13u1vulnerable
trixie (security)17.11-0+deb13u1fixed
postgresql-18 (PTS)forky18.4-1vulnerable
sid18.6-3fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
postgresql-13source(unstable)(unfixed)
postgresql-15sourcebookworm15.19-0+deb12u1DLA-4740-1
postgresql-15source(unstable)(unfixed)
postgresql-17sourcetrixie17.11-0+deb13u1DSA-6438-1
postgresql-17source(unstable)(unfixed)
postgresql-18source(unstable)18.6-1

Notes

https://www.postgresql.org/support/security/CVE-2026-15742/
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/

Search for package or bug name: Reporting problems