Security Advisory

CVE-2023-5870

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2023-12-10 17:58:30
Last updated 2026-03-02 17:25:57
Assigner redhat
State PUBLISHED

Description

A flaw was found in PostgreSQL involving the pg_cancel_backend role that signals background workers, including the logical replication launcher, autovacuum workers, and the autovacuum launcher. Successful exploitation requires a non-core extension with a less-resilient background worker and would affect that specific background worker only. This issue may allow a remote high privileged user to launch a denial of service (DoS) attack.