Bug#1143128: pgvector: CVE-2026-18022
Salvatore Bonaccorso <[email protected]>
| Newsgroups | gmane.linux.debian.devel.bugs.rc |
|---|---|
| Message-ID | <178543846743.1472825.3903961022888626507.reportbug__40261.5084358089$1785438557$gmane$org@eldamar.lan> |
Source: pgvector Version: 0.8.5-1 Severity: grave Tags: security upstream Forwarded: https://github.com/pgvector/pgvector/issues/1006 X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]> Hi, The following vulnerability was published for pgvector. CVE-2026-18022[0]: | Integer wraparound in IVFFlat index build in pgvector before 0.8.6 | allows a database user to write data out-of-bounds, which could lead | to arbitrary code execution. Only 32-bit systems are affected. Despite the severity I guess for trixie it is enough to make a fix only via an upcomping point release as it only affects 32bit systems. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-18022 https://www.cve.org/CVERecord?id=CVE-2026-18022 [1] https://github.com/pgvector/pgvector/issues/1006 [2] https://github.com/pgvector/pgvector/commit/636a92a3395d2e036ffd40d07aeb400a708ae104 Please adjust the affected versions in the BTS as needed. Regards, Salvatore