Buffer over-read in PostgreSQL ascii() SQL function allows a user to disclose up to 3 bytes after the end of a specific allocation, via a crafted text value. This is the same class of defect that CVE-2026-2006 fixed, though this instance has less impact. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Postgresql | Postgresql | 14.0 (including) | 14.24 (excluding) |
| Postgresql | Postgresql | 15.0 (including) | 15.19 (excluding) |
| Postgresql | Postgresql | 16.0 (including) | 16.15 (excluding) |
| Postgresql | Postgresql | 17.0 (including) | 17.11 (excluding) |
| Postgresql | Postgresql | 18.0 (including) | 18.5 (excluding) |
| Postgresql-10 | Ubuntu | upstream | * |
| Postgresql-12 | Ubuntu | upstream | * |
| Postgresql-14 | Ubuntu | jammy | * |
| Postgresql-16 | Ubuntu | noble | * |
| Postgresql-18 | Ubuntu | devel | * |
| Postgresql-18 | Ubuntu | resolute | * |
| Postgresql-9.3 | Ubuntu | upstream | * |
| Postgresql-9.5 | Ubuntu | upstream | * |