PT-2026-68789 · Timescale · Timescaledb
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
TimescaleDB versions prior to 2.29.2
Description
An out-of-bounds read exists in the Gorilla compression reverse row iterator. Authenticated attackers with DML (Data Manipulation Language) access to a compressed hypertable can cause a denial of service by storing a crafted compressed datum with an internally inconsistent BitArray. This triggers an unsigned integer wraparound during the reverse iterator bucket index computation, leading to a read beyond the bucket array end and a SIGSEGV crash. This crash can be repeatedly triggered during subsequent reverse-order scans.
Recommendations
Update to version 2.29.2 or later to apply the fix implemented in commit 517c13e.
Exploit
Fix
DoS
Integer Underflow
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Timescaledb