Source: pgvector
Version: 0.8.5-1
Severity: grave
Tags: security upstream
Forwarded: https://github.com/pgvector/pgvector/issues/1006
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for pgvector.

CVE-2026-18022[0]:
| Integer wraparound in IVFFlat index build in pgvector before 0.8.6
| allows a database user to write data out-of-bounds, which could lead
| to arbitrary code execution. Only 32-bit systems are affected.

Despite the severity I guess for trixie it is enough to make a fix
only via an upcomping point release as it only affects 32bit systems.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-18022
    https://www.cve.org/CVERecord?id=CVE-2026-18022
[1] https://github.com/pgvector/pgvector/issues/1006
[2] 
https://github.com/pgvector/pgvector/commit/636a92a3395d2e036ffd40d07aeb400a708ae104

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

Reply via email to