Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-6269-1 | postgresql-15 security update |
Debian DSA |
DSA-6270-1 | postgresql-17 security update |
| Link | Providers |
|---|---|
| https://www.postgresql.org/support/security/CVE-2026-6473/ |
|
Thu, 14 May 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Postgresql
Postgresql postgresql |
|
| Vendors & Products |
Postgresql
Postgresql postgresql |
Thu, 14 May 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 14 May 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds. This may execute arbitrary code as the operating system user running the database. In applications that pass gigabyte-scale user inputs to the relevant database functions, the application input provider may achieve a segmentation fault. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected. | |
| Title | PostgreSQL server undersizes allocations, via integer wraparound | |
| Weaknesses | CWE-190 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: PostgreSQL
Published:
Updated: 2026-05-15T03:56:15.231Z
Reserved: 2026-04-17T00:27:22.802Z
Link: CVE-2026-6473
Updated: 2026-05-14T13:40:13.777Z
Status : Awaiting Analysis
Published: 2026-05-14T14:16:24.883
Modified: 2026-05-14T16:21:23.190
Link: CVE-2026-6473
No data.
OpenCVE Enrichment
Updated: 2026-05-14T14:45:22Z
Debian DSA