suse · CVE-2026-2003

Quick triage

Priority: medium Published: 2026-03-05 00:19:23 UTC Updated: 2026-04-16 13:38:38 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2026-2003 severity moderate: SUSE including 346 source package names (2.2.1-5.40:grub2-2.12-slfo.1.1_2.1, 2.2.1-5.40:grub2-i386-pc-2.12-slfo.1.1_2.1, …), 1251 product×package rows across 73 product lines (Container suse/manager/5.0/x86_64/server, Container suse/manager/5.0/x86_64/server-migration-14-16, … (73 product lines)): Fixed 1204, First Fixed 47.

Description:

Improper validation of type "oidvector" in PostgreSQL allows a database user to disclose a few bytes of server memory. We have not ruled out viability of attacks that arrange for presence of confidential information in disclosed bytes, but they seem unlikely. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.

cvelogic Threat Intelligence