CyberRota Analysis
AI-GeneratedA type confusion vulnerability in PostgreSQL's ctid data type selectivity estimator allows an attacker to access and view calculations derived from arbitrary memory spans, potentially leading to the recovery of sensitive data. This issue affects versions prior to PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24. Database administrators and organizations using these affected versions should prioritize patching to mitigate the risk of data exposure.
Original NVD Description
Type confusion regarding input of PostgreSQL ctid data type selectivity estimator allows an object creator to view a calculation derived from the value of an arbitrary 4-byte span of memory, via a chosen non-ctid input. While the calculation loses precision, substantial memory value recovery appears possible. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.