What is CVE-2026-14677?
This critical vulnerability is an integer wraparound in the pltcl and plperl procedural languages of 32-bit PostgreSQL builds. An attacker with object creation privileges can craft malicious function bodies to cause the server to allocate insufficient memory and write out-of-bounds, potentially leading to arbitrary code execution as the operating system user running the database. Immediate application of the vendor-supplied security patch is strongly recommended.
Azərbaycanca: Bu kritik boşluq PostgreSQL-in 32-bit versiyalarında pltcl və plperl prosedur dillərində tapılan Integer wraparound zəifliyidir. Təcavüzkar obyekt yaradıcısı kimi xüsusi hazırlanmış funksiya gövdələri vasitəsilə serverdə yaddaş aşımına səbəb ola bilər ki, bu da verilənlər bazasını işlədən əməliyyat sistemi istifadəçisi səviyyəsində ixtiyari kod icrasına yol aça bilər. Dərhal istehsalçı tərəfindən təqdim edilən təhlükəsizlik yeniləməsini tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-190
FAQ1
What software does CVE-2026-14677 affect and what is its main impact?
CVE-2026-14677 is a critical integer wraparound vulnerability found in the pltcl and plperl procedural languages of 32-bit PostgreSQL builds. An attacker with object creation privileges can potentially achieve arbitrary code execution via crafted function bodies.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.