Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-5869

29
FAUCET Score

CVE-2023-5869 is a high-severity integer overflow vulnerability in PostgreSQL that allows authenticated database users to execute arbitrary code by crafting malicious SQL array modifications. This flaw, rated 8.8 CVSS, enables remote attackers to achieve arbitrary code execution, memory writing, and extensive memory reading due to missing overflow checks. While no public exploit code or active exploitation has been observed, and community discussion is minimal, its high FAUCET Risk Score of 72/100 indicates a significant potential threat.

Impacted Technologies

VendorProductVersion(s)CPE
>= 11.0, < 11.22CPE matchmatch criteria
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
>= 12.0, < 12.17CPE matchmatch criteria
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
>= 13.0, < 13.13CPE matchmatch criteria
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
>= 14.0, < 14.10CPE matchmatch criteria
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
>= 15.0, < 15.5CPE matchmatch criteria
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.8HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
4.32%
Probability of exploitation in next 30 days
EPSS Percentile
90.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0432 is in the 89th percentile among its peer group of 17,822 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (63)

3cxpatch availablevia llm_extracted
Fixed in: 9.4.2
3cxpatch availablevia llm_extracted
Fixed in: 9.4.2, 9.3.4, 9.2.6, 9.1.9
beckhoffpatch availablevia llm_extracted
Fixed in: 16.1, 15.5, 14.10
View patch
dhis2patch availablevia llm_extracted
Fixed in: 16.1, 15.5, 14.10
View patch
fortinetpatch availablevia llm_extracted
Fixed in: 16.1, 15.5, 14.10
View patch
microsoftpatch availablevia msrc
Product: cbl2 postgresql 14.10-1 on CBL Mariner 2.0Fixed in: 14.10-1
microsoftpatch availablevia msrc
Product: 18239-16823Fixed in: 14.10-1
miniopatch availablevia llm_extracted
Fixed in: 16.1, 15.5, 14.10
View patch
navidromepatch availablevia llm_extracted
Fixed in: 16.1, 15.5, 14.10
View patch
netscoutpatch availablevia llm_extracted
Fixed in: 16.1, 15.5, 14.10
View patch
new_relicpatch availablevia llm_extracted
Fixed in: 16.1, 15.5, 14.10
View patch
nvidiapatch availablevia llm_extracted
Fixed in: 16.1, 15.5, 14.10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Advanced Update SupportFixed in: postgresql:12-8020020231128165246.4cda2c84
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Advanced Update SupportFixed in: postgresql:10-8020020231201202149.4cda2c84
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Telecommunications Update ServiceFixed in: postgresql:12-8020020231128165246.4cda2c84
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Telecommunications Update ServiceFixed in: postgresql:10-8020020231201202149.4cda2c84
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Update Services for SAP SolutionsFixed in: postgresql:12-8020020231128165246.4cda2c84
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Update Services for SAP SolutionsFixed in: postgresql:10-8020020231201202149.4cda2c84
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportFixed in: postgresql:12-8040020231127153301.522a0ee4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportFixed in: postgresql:13-8040020231127154806.522a0ee4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportFixed in: postgresql:10-8040020231127142440.522a0ee4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Telecommunications Update ServiceFixed in: postgresql:12-8040020231127153301.522a0ee4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Telecommunications Update ServiceFixed in: postgresql:13-8040020231127154806.522a0ee4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Telecommunications Update ServiceFixed in: postgresql:10-8040020231127142440.522a0ee4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Update Services for SAP SolutionsFixed in: postgresql:12-8040020231127153301.522a0ee4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Update Services for SAP SolutionsFixed in: postgresql:13-8040020231127154806.522a0ee4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Update Services for SAP SolutionsFixed in: postgresql:10-8040020231127142440.522a0ee4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Extended Update SupportFixed in: postgresql:13-8060020231114115246.ad008a3a
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Extended Update SupportFixed in: postgresql:12-8060020231128165328.ad008a3a
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Extended Update SupportFixed in: postgresql:10-8060020231201202249.ad008a3a
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Extended Update SupportFixed in: postgresql:13-8080020231114105206.63b34585
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Extended Update SupportFixed in: postgresql:12-8080020231128165335.63b34585
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Extended Update SupportFixed in: postgresql:10-8080020231201202316.63b34585
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Extended Update SupportFixed in: postgresql:15-8080020231113134015.63b34585
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: postgresql-0:13.13-1.el9_3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: postgresql:15-9030020231120082734.rhel9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.0 Extended Update SupportFixed in: postgresql-0:13.13-1.el9_0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.2 Extended Update SupportFixed in: postgresql-0:13.13-1.el9_2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-postgresql12-postgresql-0:12.17-1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-postgresql10-postgresql-0:10.23-2.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-postgresql13-postgresql-0:13.13-1.el7
View patch
redhatpatch availablevia redhat_api
Product: RHACS-3.74-RHEL-8Fixed in: advanced-cluster-security/rhacs-central-db-rhel8:3.74.8-9
View patch
redhatpatch availablevia redhat_api
Product: RHACS-3.74-RHEL-8Fixed in: advanced-cluster-security/rhacs-main-rhel8:3.74.8-9
View patch
redhatpatch availablevia redhat_api
Product: RHACS-3.74-RHEL-8Fixed in: advanced-cluster-security/rhacs-operator-bundle:3.74.8-7
View patch
redhatpatch availablevia redhat_api
Product: RHACS-3.74-RHEL-8Fixed in: advanced-cluster-security/rhacs-scanner-db-rhel8:3.74.8-9
View patch
redhatpatch availablevia redhat_api
Product: RHACS-3.74-RHEL-8Fixed in: advanced-cluster-security/rhacs-scanner-db-slim-rhel8:3.74.8-9
View patch
redhatpatch availablevia redhat_api
Product: RHACS-4.1-RHEL-8Fixed in: advanced-cluster-security/rhacs-central-db-rhel8:4.1.6-6
View patch
redhatpatch availablevia redhat_api
Product: RHACS-4.1-RHEL-8Fixed in: advanced-cluster-security/rhacs-main-rhel8:4.1.6-6
View patch
redhatpatch availablevia redhat_api
Product: RHACS-4.1-RHEL-8Fixed in: advanced-cluster-security/rhacs-operator-bundle:4.1.6-6
View patch
redhatpatch availablevia redhat_api
Product: RHACS-4.1-RHEL-8Fixed in: advanced-cluster-security/rhacs-scanner-db-rhel8:4.1.6-6
View patch
redhatpatch availablevia redhat_api
Product: RHACS-4.1-RHEL-8Fixed in: advanced-cluster-security/rhacs-scanner-db-slim-rhel8:4.1.6-6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.2 Extended Update SupportFixed in: postgresql:15-9020020231115020618.rhel9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Advanced Cluster Security 4.2Fixed in: advanced-cluster-security/rhacs-central-db-rhel8:4.2.4-6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Advanced Cluster Security 4.2Fixed in: advanced-cluster-security/rhacs-main-rhel8:4.2.4-6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Advanced Cluster Security 4.2Fixed in: advanced-cluster-security/rhacs-operator-bundle:4.2.4-7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Advanced Cluster Security 4.2Fixed in: advanced-cluster-security/rhacs-scanner-db-rhel8:4.2.4-6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Advanced Cluster Security 4.2Fixed in: advanced-cluster-security/rhacs-scanner-db-slim-rhel8:4.2.4-7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: postgresql-0:9.2.24-9.el7_9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: postgresql:13-8090020231114113712.a75119d5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: postgresql:12-8090020231128173330.a75119d5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: postgresql:10-8090020231201202407.a75119d5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: postgresql:15-8090020231114113548.a75119d5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.1 Update Services for SAP SolutionsFixed in: postgresql:10-8010020231130170510.c27ad7f8
View patch

Vendor Advisories (12)

3cxllm-3cx-c3a15eadabccae7dCRITICAL

Third-Party Package Updates in Splunk Enterprise - June 2025

Jun 2, 2025
3cxllm-3cx-2d792dcff1f0eb56CRITICAL

Third-Party Package Updates in Splunk Universal Forwarder - June 2025

Jun 2, 2025
microsoft2023-Dec/CVE-2023-5869Important

Postgresql: buffer overrun from integer overflow in array modification

Dec 12, 2023
redhatCVE-2023-5869Important

postgresql: Buffer overrun from integer overflow in array modification

Nov 9, 2023
fortinetllm-fortinet-cbd639edbb7db06fHIGH

Buffer overrun from integer overflow in array modification

Jan 1, 2023
netscoutllm-netscout-88834822a568f0b9HIGH

Buffer overrun from integer overflow in array modification

beckhoffllm-beckhoff-2bde09ea8e459592HIGH

Buffer overrun from integer overflow in array modification

new_relicllm-new_relic-c1d55cc95d4b2e0aHIGH

Buffer overrun from integer overflow in array modification

dhis2llm-dhis2-8b7f217c67827e46HIGH

Buffer overrun from integer overflow in array modification

miniollm-minio-1fd6f6c652f4a0d6HIGH

Buffer overrun from integer overflow in array modification

navidromellm-navidrome-bd5a043b780718f0HIGH

Buffer overrun from integer overflow in array modification

nvidiallm-nvidia-a62e88e45e01788bHIGH

Buffer overrun from integer overflow in array modification

References

lists.debian.org / debian-lts-announce/2023/11/msg00007.html
security.netapp.com / advisory/ntap-20240119-0003
access.redhat.com / errata/RHSA-2023:7545
Third Party Advisory
access.redhat.com / errata/RHSA-2023:7579
Third Party Advisory
access.redhat.com / errata/RHSA-2023:7580
Third Party Advisory
access.redhat.com / errata/RHSA-2023:7581
Third Party Advisory
access.redhat.com / errata/RHSA-2023:7616
Third Party Advisory
access.redhat.com / errata/RHSA-2023:7656
Third Party Advisory
access.redhat.com / errata/RHSA-2023:7666
Third Party Advisory
access.redhat.com / errata/RHSA-2023:7667
Third Party Advisory
access.redhat.com / errata/RHSA-2023:7694
Third Party Advisory
access.redhat.com / errata/RHSA-2023:7695
Third Party Advisory
access.redhat.com / errata/RHSA-2023:7714
Third Party Advisory
access.redhat.com / errata/RHSA-2023:7770
Third Party Advisory
access.redhat.com / errata/RHSA-2023:7771
Third Party Advisory
access.redhat.com / errata/RHSA-2023:7772
Third Party Advisory
access.redhat.com / errata/RHSA-2023:7778
Third Party Advisory
access.redhat.com / errata/RHSA-2023:7783
Third Party Advisory
access.redhat.com / errata/RHSA-2023:7784
access.redhat.com / errata/RHSA-2023:7785
access.redhat.com / errata/RHSA-2023:7786
access.redhat.com / errata/RHSA-2023:7788
access.redhat.com / errata/RHSA-2023:7789
access.redhat.com / errata/RHSA-2023:7790
access.redhat.com / errata/RHSA-2023:7878
access.redhat.com / errata/RHSA-2023:7883
access.redhat.com / errata/RHSA-2023:7884
access.redhat.com / errata/RHSA-2023:7885
access.redhat.com / errata/RHSA-2024:0304
access.redhat.com / errata/RHSA-2024:0332
access.redhat.com / errata/RHSA-2024:0337
access.redhat.com / security/cve/CVE-2023-5869
Third Party Advisory
bugzilla.redhat.com / show_bug.cgi
Issue Tracking
postgresql.org / about/news/postgresql-161-155-1410-1313-1217-and-1122-released-2749
Release Notes
postgresql.org / support/security/CVE-2023-5869
Vendor Advisory