What is CVE-2026-14668?
CVE-2026-14668 is a type confusion vulnerability in PostgreSQL's ctid data type selectivity estimator. An attacker can use a specially crafted non-ctid input to recover arbitrary 4-byte spans of server memory. This could lead to sensitive memory data leakage, though the recovery is limited due to precision loss during calculation.
Azərbaycanca: CVE-2026-14668 PostgreSQL-in "ctid" data növünün selectivity estimator funksiyasında type confusion zəifliyidir. Təcavüzkar xüsusi hazırlanmış "non-ctid" giriş vasitəsilə server yaddaşından özbaşına 4 baytlıq məlumat əldə edə bilər. Bu, həssas yaddaş məlumatlarının sızmasına səbəb ola bilər, lakin hesablama zamanı dəqiqlik itkisi olduğu üçün məlumat bərpası məhduddur.
Related CVEs
link basis: shared vendor: PostgreSQL
FAQ1
What type of data leakage can CVE-2026-14668 cause in PostgreSQL servers?
This vulnerability allows an attacker to recover arbitrary 4-byte spans of server memory, potentially leading to sensitive memory data leakage. However, the recovery is limited due to precision loss during calculation.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.