AZL-103433

See a problem?
Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-103433.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-103433
Upstream
  • CVE-2026-6668
Published
2026-09-23T17:17:16Z
Modified
2026-09-25T05:36:32Z
Summary
CVE-2026-6668 affecting package pgbouncer 1.25.2-1
Details

Integer overflow in the packet buffer growth logic in PgBouncer through 1.25.2 allows an unauthenticated remote attacker to cause a denial of service. Sufficiently large input makes the buffer size computation overflow, leaving the growth loop unable to terminate. Because PgBouncer serves all clients from a single process, this saturates a CPU core and stalls every pooled connection until the process is killed. Both unauthenticated and authenticated code paths can reach the overflow.

References

Affected packages

Azure Linux:3 / pgbouncer

Package

Name
pgbouncer
Purl
pkg:rpm/azure-linux/pgbouncer

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
1.25.2-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-103433.json"