PT-2026-68791 · Postgresql Global Development Group+1 · Postgresql+1
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
TimescaleDB versions prior to 2.29.1
Description
An out-of-bounds read occurs when authenticated attackers provide a crafted Simple8b selector-11 value. This value is stored in the signed
int16 Arrow dictionary-index type and bypasses index validation checks during bulk text dictionary decompression. Attackers with direct DML (Data Manipulation Language) access to a non-frozen physical compressed hypertable relation can trigger this read before the base of the live offsets array using the VectorAgg single-text hashing strategy. This can lead to query-result integrity failures, incorrect aggregation output, backend SIGSEGV (a segmentation fault), or PostgreSQL crash recovery.Recommendations
Update TimescaleDB to version 2.29.1 or later to apply the fix implemented in commit 517c13e.
Exploit
Fix
Out of bounds Read
Improper Validation of Array Index
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Postgresql
Timescaledb