What is CVE-2026-16238?
This critical vulnerability arises from a type confusion in PostgreSQL's pg_restore_attribute_stats() function, allowing an object creator to execute arbitrary code as the operating system user running the database due to conflation of range and multirange values. PostgreSQL major version 18, specifically minor versions prior to 18.5, are affected. Immediate upgrade to PostgreSQL 18.5 or later is strongly recommended.
Azərbaycanca: Bu kritik zəiflik PostgreSQL verilənlər bazasının pg_restore_attribute_stats() funksiyasındakı "type confusion" səbəbindən yaranır və obyekt yaradan şəxsə verilənlər bazasını işlədən əməliyyat sistemi istifadəçisi kimi ixtiyari kod icra etməyə imkan verir. Problem diapazon (range) və çoxdiapazon (multirange) dəyərlərinin qarışdırılmasından qaynaqlanır; PostgreSQL 18-in 18.5-dən əvvəlki versiyaları təsirlənmişdir. Dərhal PostgreSQL 18.5 və ya daha yeni versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-94; shared vendor: PostgreSQL
FAQ2
In which PostgreSQL function was CVE-2026-16238 discovered?
This vulnerability arises from a type confusion in PostgreSQL's pg_restore_attribute_stats() function.
Which version is recommended to upgrade to in order to mitigate the critical CVE-2026-16238 vulnerability?
Immediate upgrade to PostgreSQL 18.5 or later is strongly recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.