{"id":"CVE-2026-6575","year":2026,"sequence":6575,"component":"core server","score":4.3,"cvss_version":"3.0","vector":"AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","first_published":"2026-05-14","source_url":"https://www.postgresql.org/support/security/CVE-2026-6575/","facts":{"affected":{"18":"18"},"affected_ranges":[{"from":"18","until":"18.4"}],"cna_url":"https://cveawg.mitre.org/api/cve/CVE-2026-6575","component":"core server","cvss_version":"3.0","description_en":"Buffer over-read in PostgreSQL function pg_restore_attribute_stats() accepts array values of unmatched length, which causes query planning to read past end of one array. This allows a table maintainer to infer memory values past that array end. Within major version 18, minor versions before PostgreSQL 18.4 are affected. Versions before PostgreSQL 18 are unaffected.","first_published":"2026-05-14","fixed":{"18":"18.4"},"id":"CVE-2026-6575","introduced":{},"published":{"18":"2026-05-14"},"score":4.3,"title":"PostgreSQL pg_restore_attribute_stats accepts values that cause query planning to read past end of stats array","url":"https://www.postgresql.org/support/security/CVE-2026-6575/","vector":"AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"},"reviewed_hash":"6a65a7884245936f6adaef8709d290d460e999dfce1ad78734fa7c9a324ed325","source_hash":"965b9e2323feab543f3cbeb74c418c3a5b43cbefc6594d2862ff0d24dcf8e6a2","text":{"locale":"zh-Hans","title":"PostgreSQL pg_restore_attribute_stats 接受可使查询规划越界读取统计数组的值","description":"PostgreSQL pg_restore_attribute_stats 接受可使查询规划越界读取统计数组的值","details":"PostgreSQL 函数 pg_restore_attribute_stats() 存在缓冲区越界读取：它会接受长度不匹配的数组值， 导致查询规划过程读取其中一个数组末尾之后的内存。表维护者可借此推断该数组末尾之后的内存值。 在主版本 18 中，PostgreSQL 18.4 之前的小版本受此问题影响，PostgreSQL 18 之前的版本不受影响。","format":"markdown","provenance":{"identity":"immutable_cve_code","sources":[{"observed_at":"2026-10-03 12:08:35.169032+08","raw":{"component":"core server","cve":"2026-6575","cvenumber":202606575,"description":"PostgreSQL pg_restore_attribute_stats 接受可使查询规划越界读取统计数组的值","details":"PostgreSQL 函数 pg_restore_attribute_stats() 存在缓冲区越界读取：它会接受长度不匹配的数组值， 导致查询规划过程读取其中一个数组末尾之后的内存。表维护者可借此推断该数组末尾之后的内存值。 在主版本 18 中，PostgreSQL 18.4 之前的小版本受此问题影响，PostgreSQL 18 之前的版本不受影响。","detailslink":"","id":53,"legacyscore":"","newspost_id":3294,"public":true,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"},"source":"center","source_id":53,"source_table_sha256":"b57ee28b2263464208af0ccf7512b31f0c1ab7140d12dda09a0c87de341f1372"},{"observed_at":"2026-10-03 12:08:55.967155+08","raw":{"component":"core server","cve":"2026-6575","cvenumber":202606575,"description":"PostgreSQL pg_restore_attribute_stats 接受可使查询规划越界读取统计数组的值","details":"PostgreSQL 函数 pg_restore_attribute_stats() 存在缓冲区越界读取：它会接受长度不匹配的数组值， 导致查询规划过程读取其中一个数组末尾之后的内存。表维护者可借此推断该数组末尾之后的内存值。 在主版本 18 中，PostgreSQL 18.4 之前的小版本受此问题影响，PostgreSQL 18 之前的版本不受影响。","detailslink":"","id":53,"legacyscore":"","newspost_id":3294,"public":true,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"},"source":"pgweb","source_id":53,"source_table_sha256":"b57ee28b2263464208af0ccf7512b31f0c1ab7140d12dda09a0c87de341f1372"}]},"text_hash":"d6de28e4aaf20d19af4de6d1c90df4166922c22d4ce693fd22e3d199c1645bff"},"locales":["en","zh-Hans"],"fixes":[{"major":"18","fixed_version":"18.4","introduced":null,"published_date":"2026-05-14","facts":{"fixed":"18.4","introduced":null,"published":"2026-05-14"}}],"legacy":[{"source":"center","source_id":53,"observed_at":"2026-10-03 12:08:35.169032+08","raw":{"id":53,"cve":"2026-6575","public":true,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","details":"PostgreSQL 函数 pg_restore_attribute_stats() 存在缓冲区越界读取：它会接受长度不匹配的数组值， 导致查询规划过程读取其中一个数组末尾之后的内存。表维护者可借此推断该数组末尾之后的内存值。 在主版本 18 中，PostgreSQL 18.4 之前的小版本受此问题影响，PostgreSQL 18 之前的版本不受影响。","component":"core server","cvenumber":202606575,"description":"PostgreSQL pg_restore_attribute_stats 接受可使查询规划越界读取统计数组的值","detailslink":"","legacyscore":"","newspost_id":3294},"fixes":[{"source_id":204,"source_version_id":31,"major":"18","fixed_minor":4,"raw":{"id":204,"patch_id":53,"version_id":31,"fixed_minor":4},"version_raw":{"id":31,"tree":18.0,"current":true,"docsgit":"","eoldate":"2030-11-14","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":6,"firstreldate":"2025-09-25"}}]},{"source":"pgweb","source_id":53,"observed_at":"2026-10-03 12:08:55.967155+08","raw":{"id":53,"cve":"2026-6575","public":true,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","details":"PostgreSQL 函数 pg_restore_attribute_stats() 存在缓冲区越界读取：它会接受长度不匹配的数组值， 导致查询规划过程读取其中一个数组末尾之后的内存。表维护者可借此推断该数组末尾之后的内存值。 在主版本 18 中，PostgreSQL 18.4 之前的小版本受此问题影响，PostgreSQL 18 之前的版本不受影响。","component":"core server","cvenumber":202606575,"description":"PostgreSQL pg_restore_attribute_stats 接受可使查询规划越界读取统计数组的值","detailslink":"","legacyscore":"","newspost_id":3294},"fixes":[{"source_id":204,"source_version_id":31,"major":"18","fixed_minor":4,"raw":{"id":204,"patch_id":53,"version_id":31,"fixed_minor":4},"version_raw":{"id":31,"tree":18.0,"current":true,"docsgit":"","eoldate":"2030-11-14","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":6,"firstreldate":"2025-09-25"}}]}]}
