HomeDefectsLIN1024-21264
Acknowledged

LIN1024-21264 : Security Advisory - postgresql - CVE-2026-6474

Created: May 15, 2026    Updated: Jun 3, 2026
Found In Version: 10.24.33.2
Severity: Standard
Applicable for: Wind River Linux LTS 24
Component/s: Userspace

Description

Externally-controlled format string in PostgreSQL timeofday() function allows an attacker to retrieve portions of server memory, via crafted timezone zones.  Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.