Source: pgvector Version: 0.8.5-1 Severity: grave Tags: security upstream Forwarded: https://github.com/pgvector/pgvector/issues/1006 X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerability was published for pgvector. CVE-2026-18022[0]: | Integer wraparound in IVFFlat index build in pgvector before 0.8.6 | allows a database user to write data out-of-bounds, which could lead | to arbitrary code execution. Only 32-bit systems are affected. Despite the severity I guess for trixie it is enough to make a fix only via an upcomping point release as it only affects 32bit systems. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-18022 https://www.cve.org/CVERecord?id=CVE-2026-18022 [1] https://github.com/pgvector/pgvector/issues/1006 [2] https://github.com/pgvector/pgvector/commit/636a92a3395d2e036ffd40d07aeb400a708ae104 Please adjust the affected versions in the BTS as needed. Regards, Salvatore

