The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing a slice bounds out of range panic.
The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Pgproto3 | Jackc | 2.0.0 (including) | 2.3.3 (including) |
| Red Hat Enterprise Linux 10 | RedHat | osbuild-composer-0:165.1-2.el10_2 | * |
| Red Hat Enterprise Linux 9 | RedHat | osbuild-composer-0:165.1-2.el9_8 | * |
| Multicluster Global Hub 1.3.4 | RedHat | multicluster-globalhub/multicluster-globalhub-agent-rhel9:1779210675 | * |
| Multicluster Global Hub 1.3.4 | RedHat | multicluster-globalhub/multicluster-globalhub-manager-rhel9:1779210608 | * |
| Multicluster Global Hub 1.3.4 | RedHat | multicluster-globalhub/multicluster-globalhub-rhel9-operator:1779209992 | * |
| Multicluster Global Hub 1.4.5 | RedHat | multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779579439 | * |
| Multicluster Global Hub 1.5.4 | RedHat | multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1778867753 | * |
| Multicluster Global Hub 1.6.2 | RedHat | multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1780167118 | * |
| Red Hat Advanced Cluster Security for Kubernetes 4.8 | RedHat | advanced-cluster-security/rhacs-main-rhel8:1777307791 | * |
| Red Hat Advanced Cluster Security for Kubernetes 4.8 | RedHat | advanced-cluster-security/rhacs-scanner-v4-rhel8:1777307791 | * |
| Red Hat Advanced Cluster Security for Kubernetes 4.8 | RedHat | advanced-cluster-security/rhacs-main-rhel8:1777307791 | * |
| Red Hat Advanced Cluster Security for Kubernetes 4.8 | RedHat | advanced-cluster-security/rhacs-scanner-v4-rhel8:1777307791 | * |
| Red Hat Quay 3.1 | RedHat | quay/quay-rhel8:1776736910 | * |
| Red Hat Quay 3.12 | RedHat | quay/quay-rhel8:1776752646 | * |
| Red Hat Quay 3.14 | RedHat | quay/quay-rhel8:1779689392 | * |
| Red Hat Quay 3.15 | RedHat | quay/quay-rhel8:1780891395 | * |
| Red Hat Quay 3.16 | RedHat | quay/quay-rhel9:1779204086 | * |
| Red Hat Quay 3.17 | RedHat | quay/quay-rhel9:1779922205 | * |
| Red Hat Quay 3.9 | RedHat | quay/quay-rhel8:1776782369 | * |
| Golang-github-jackc-pgproto3 | Ubuntu | upstream | * |