PT-2026-65564 · Postgresql · Pglogical
CVSS v4.0
7.7
High
| Vector | AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
pglogical (affected versions not specified)
Description
A use-after-free condition exists in the worker signaling code. This occurs when a worker structure is dereferenced after the underlying slot has been freed or recycled during normal worker lifecycle events. A low-privileged user can trigger this condition by influencing the timing of worker start, stop, and restart operations. This typically results in the crashing of replication workers, affecting availability, but could potentially be used to achieve remote code execution with the privileges of the PostgreSQL backend.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pglogical