CVE-2026-14679: PostgreSQL stack buffer overflow in argument match writes 0x0 and 0x1 to server memory
Stack buffer overflow in PostgreSQL argument name matching allows an object creator to achieve unknown impacts via OUT parameter count. The attack can write only 0x0 and 0x1 bytes. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
PostgreSQLto a version that resolves this vulnerability.Fixed in 18.5 - Upgrade
Upgrade
PostgreSQLto a version that resolves this vulnerability.Fixed in 17.11 - Upgrade
Upgrade
PostgreSQLto a version that resolves this vulnerability.Fixed in 16.15 - Upgrade
Upgrade
PostgreSQLto a version that resolves this vulnerability.Fixed in 15.19 - Upgrade
Upgrade
PostgreSQLto a version that resolves this vulnerability.Fixed in 14.24
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14679?
The severity of CVE-2026-14679 is high, rated at 8.2.
How do I fix CVE-2026-14679?
To fix CVE-2026-14679, upgrade to PostgreSQL versions 18.5, 17.11, 16.15, 15.19, or 14.24.
What type of vulnerability is described in CVE-2026-14679?
CVE-2026-14679 is a stack buffer overflow vulnerability affecting PostgreSQL.
What impact can CVE-2026-14679 have on systems?
CVE-2026-14679 can lead to unknown impacts via OUT parameter count manipulation.
Which PostgreSQL versions are affected by CVE-2026-14679?
Versions of PostgreSQL prior to 18.5, 17.11, 16.15, 15.19, and 14.24 are affected by CVE-2026-14679.