CVE-2026-2007
PostgreSQL pg_trgm heap buffer overflow writes pattern onto server memory
8.2
HIGH
CVSS 3.1
EPSS 0.48%
描述
Heap buffer overflow in PostgreSQL pg_trgm allows a database user to achieve unknown impacts via a crafted input string. The attacker has limited control over the byte patterns to be written, but we have not ruled out the viability of attacks that lead to privilege escalation. PostgreSQL 18.1 and 18.0 are affected.
如何修補 CVE-2026-2007
要修補 CVE-2026-2007,請將受影響套件升級到下列已修補版本。
- —升級至 18.2.0 或更新版本
CVE-2026-2007 正在被利用嗎?
低 — EPSS 為 0.5%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- >= 18.0.0, < 18.2.0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.2 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H |