cbcvebase.
CVE-2023-5869
published 2023-12-10

CVE-2023-5869: A flaw was found in PostgreSQL that allows authenticated database users to execute arbitrary code through missing overflow checks during SQL array value…

PriorityP264high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
4.32%
90.1th percentile
A flaw was found in PostgreSQL that allows authenticated database users to execute arbitrary code through missing overflow checks during SQL array value modification. This issue exists due to an integer overflow during array modification where a remote user can trigger the overflow by providing specially crafted data. This enables the execution of arbitrary code on the target system, allowing users to write arbitrary bytes to memory and extensively read the server's memory.

Affected

52 ranges· showing 25
VendorProductVersion rangeFixed in
debianpostgresql-13< postgresql-13 13.13-0+deb11u1 (bullseye)postgresql-13 13.13-0+deb11u1 (bullseye)
debianpostgresql-15< postgresql-13 13.13-0+deb11u1 (bullseye)postgresql-13 13.13-0+deb11u1 (bullseye)
msrccbl2_postgresql_14.10-1_on_cbl_mariner_2.0
postgresqlpostgresql
postgresqlpostgresql>= 11.0 < 11.2211.22
postgresqlpostgresql>= 12.0 < 12.1712.17
postgresqlpostgresql>= 13.0 < 13.1313.13
postgresqlpostgresql>= 14.0 < 14.1014.10
postgresqlpostgresql>= 15.0 < 15.515.5
redhatcodeready_linux_builder_eus
redhatcodeready_linux_builder_eus_for_power_little_endian_eus
redhatcodeready_linux_builder_eus_for_power_little_endian_eus
redhatcodeready_linux_builder_for_arm64_eus
redhatcodeready_linux_builder_for_arm64_eus
redhatcodeready_linux_builder_for_arm64_eus
redhatcodeready_linux_builder_for_ibm_z_systems_eus
redhatcodeready_linux_builder_for_ibm_z_systems_eus
redhatcodeready_linux_builder_for_power_little_endian_eus
redhatcodeready_linux_builder_for_power_little_endian_eus
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux_desktop
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_eus

Detection & IOCsextracted from sources · hover to see the quote

  • Trigger condition: integer overflow during SQL array value modification — look for authenticated database users submitting specially crafted array modification queries that could cause buffer overrun in PostgreSQL
  • Impact indicators: successful exploitation allows writing arbitrary bytes to memory and extensive server memory reads — monitor PostgreSQL for unexpected crashes, memory corruption errors, or abnormal process behavior following array modification operations
  • Vulnerability class: buffer overrun from integer overflow specifically in array modification code path — audit PostgreSQL logs for anomalous or oversized array value modification statements from authenticated users
  • ·Only authenticated database users can trigger this vulnerability — unauthenticated remote exploitation is not possible
  • ·Red Hat Enterprise Linux 8 and 9 with postgresql:16 stream are NOT affected; only older PostgreSQL versions on RHEL are impacted
  • ·Debian bullseye fix is available in postgresql 13.13-0+deb11u1 — systems running older versions remain vulnerable
  • ·No practical mitigation has been identified by Red Hat other than patching — update the affected package as soon as possible
  • ·A PostgreSQL service restart is required after patching for changes to take effect

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8HIGH
vendor_msrc8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.