7.5 HIGH
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): NONE
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): NONE
- Integrity impact (I): NONE
- Availability impact (A): HIGH
Github.com/jackc/pgproto3: pgproto3: denial of service via negative field length in datarow message
A flaw was found in pgproto3. A malicious or compromised PostgreSQL server can exploit this by sending a DataRow message with a negative field length. This input validation vulnerability can lead to a denial of service (DoS) due to a slice bounds out of range panic.
References
- https://access.redhat.com/security/cve/CVE-2026-4427 x_refsource_REDHAT vdb-entry
- RHBZ#2448626 issue-tracking x_refsource_REDHAT
- https://github.com/golang/vulndb/issues/4518
- https://github.com/jackc/pgproto3
- https://github.com/jackc/pgx/issues/2507
- https://securityinfinity.com/research/memory-safety-vulnerabilities-in-go-postg…
Affected products
Matching in nixpkgs
pkgs.rosa
CLI for the Red Hat OpenShift Service on AWS
pkgs.nemorosa
Specialized cross-seeding tool designed for music torrents
pkgs.haskellPackages.rosa
Query the namecoin blockchain
pkgs.python312Packages.librosa
Python library for audio and music analysis
pkgs.python313Packages.librosa
Python library for audio and music analysis
pkgs.python314Packages.librosa
Python library for audio and music analysis
pkgs.python312Packages.aerosandbox
Aircraft design optimization made fast through modern automatic differentiation
pkgs.python313Packages.aerosandbox
Aircraft design optimization made fast through modern automatic differentiation
pkgs.python314Packages.aerosandbox
Aircraft design optimization made fast through modern automatic differentiation
pkgs.python312Packages.torchlibrosa
PyTorch implemention of part of librosa functions
pkgs.python313Packages.torchlibrosa
PyTorch implemention of part of librosa functions
pkgs.python314Packages.torchlibrosa
PyTorch implemention of part of librosa functions
pkgs.pkgsRocm.python3Packages.librosa
Python library for audio and music analysis
Package maintainers
-
@Sigmanificient Yohann Boniface <sigmanificient@gmail.com>
-
@GuillaumeDesforges Guillaume Desforges <aceus02@gmail.com>
-
@azuwis Zhong Jianxin <azuwis@gmail.com>
-
@jfchevrette Jean-Francois Chevrette <jfchevrette@gmail.com>
-
@ambroisie Bruno BELANYI <bruno.nixpkgs@belanyi.fr>
-
@carlthome Carl Thomé <carlthome@gmail.com>