GHSA-cfw8-qrr2-2ccrHighCVSS 8.1
pgPointcloud through 1.2.5 contains a heap out-of-bounds read vulnerability in dimensional patch...
🔗 CVE IDs covered (1)
📋 Description
pgPointcloud through 1.2.5 contains a heap out-of-bounds read vulnerability in dimensional patch WKB deserialization that allows authenticated database users to read adjacent heap memory. Attackers can supply crafted pcpatch values with attacker-controlled size fields to copy heap memory into stored patches for exfiltration or crash the PostgreSQL backend.
🔗 References (7)
- https://nvd.nist.gov/vuln/detail/CVE-2026-100387
- https://github.com/pgpointcloud/pointcloud/issues/387
- https://github.com/pgpointcloud/pointcloud/pull/388
- https://github.com/pgpointcloud/pointcloud
- https://github.com/pgpointcloud/pointcloud/blob/v1.2.5/lib/pc_bytes.c#L1347-L1373
- https://www.vulncheck.com/advisories/pgpointcloud-through-1.2.5-heap-out-of-bounds-read-via-wkb-deserialization
- https://github.com/advisories/GHSA-cfw8-qrr2-2ccr