yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2026-6474
Component Overview
Vulnerability Overview
Name
CVE-2026-6474
Source
NVD (
link
)
Debian (
link
)
Description
Externally-controlled format string in PostgreSQL timeofday() function allows an attacker to retrieve portions of server memory, via crafted timezone zones. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
CWEs
CWE-134
Published Date
May 14, 2026
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://www.postgresql.org/support/security/CVE-2026-6474/
Patch
Analysis
#
Affected Component
Analysis
postgresql
Exploitable
Vulnerability Ratings
#
4.3
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
postgresql
buildroot
2025.02.x
17.10
Not Affected
postgresql
buildroot
master
18.4
Not Affected
postgresql
openwrt
master
18.4-r1
Not Affected
postgresql
openwrt
openwrt-25.12
17.5-r3
Exploitable
postgresql
yocto
master
17.10
Not Affected
postgresql
yocto
scarthgap
16.14
Not Affected