CVE-2023-5869: PostgreSQL
High severity, CVSS 8.8. EPSS: 4.3% chance of exploitation in the next 30 days.
A flaw was found in PostgreSQL that allows authenticated database users to execute arbitrary code through missing overflow checks during SQL array value modification. This issue exists due to an integer overflow during array modification where a remote user can trigger the overflow by providing specially crafted data. This enables the execution of arbitrary code on the target system, allowing users to write arbitrary bytes to memory and extensively read the server's memory.
Affected products
- PostgreSQL PostgreSQL: from 11.0, before 11.22 (fixed in 11.22); from 12.0, before 12.17 (fixed in 12.17); from 13.0, before 13.13 (fixed in 13.13); from 14.0, before 14.10 (fixed in 14.10); from 15.0, before 15.5 (fixed in 15.5); version 16.0 only
- Red Hat Codeready Linux Builder Eus: version 9.2 only
- Red Hat Codeready Linux Builder Eus For Power Little Endian Eus: version 9.0_ppc64le only; version 9.2_ppc64le only
- Red Hat Codeready Linux Builder For ARM64 Eus: version 8.6_aarch64 only; version 9.0_aarch64 only; version 9.2_aarch64 only
- Red Hat Codeready Linux Builder For IBM Z Systems Eus: version 9.0_s390x only; version 9.2_s390x only
- Red Hat Codeready Linux Builder For Power Little Endian Eus: version 9.0_ppc64le only; version 9.2_ppc64le only
- Red Hat Enterprise Linux: version 8.0 only; version 9.0 only
- Red Hat Enterprise Linux Desktop: version 7.0 only
- Red Hat Enterprise Linux Eus: version 8.6 only; version 8.8 only; version 9.0 only; version 9.2 only
- Red Hat Enterprise Linux For Arm 64: version 8.0 only; version 8.8_aarch64 only
- Red Hat Enterprise Linux For IBM Z Systems: version 7.0_s390x only; version 8.0_s390x only
- Red Hat Enterprise Linux For IBM Z Systems Eus: version 8.6_s390x only; version 8.8_s390x only; version 9.0_s390x only; version 9.2_s390x only
- Red Hat Enterprise Linux For Power Big Endian: version 7.0_ppc64 only
- Red Hat Enterprise Linux For Power Little Endian: version 7.0_ppc64le only; version 8.0_ppc64le only
- Red Hat Enterprise Linux For Power Little Endian Eus: version 8.6_ppc64le only; version 8.8_ppc64le only; version 9.0_ppc64le only; version 9.2_ppc64le only
- Red Hat Enterprise Linux For Scientific Computing: version 7.0 only
- Red Hat Enterprise Linux Server: version 7.0 only
- Red Hat Enterprise Linux Server Aus: version 8.2 only; version 8.4 only; version 8.6 only; version 9.2 only
- Red Hat Enterprise Linux Server Tus: version 8.2 only; version 8.4 only; version 8.6 only
- Red Hat Enterprise Linux Workstation: version 7.0 only
- Red Hat Software Collections: version 1.0 only
Published 2023-12-10. Last modified 2026-06-17.