---
title: "CVE-2026-2003\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2026-2003?format=md
keywords: index, follow
---

# CVE-2026-2003

Publication date 12 February 2026

Last updated 4 March 2026

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**4.3 · Medium**

[Score breakdown](https://ubuntu.com/security/CVE-2026-2003?format=md#impact-score)

Toggle side navigation

## Description

Improper validation of type "oidvector" in PostgreSQL allows a database
user to disclose a few bytes of server memory. We have not ruled out
viability of attacks that arrange for presence of confidential information
in disclosed bytes, but they seem unlikely. Versions before PostgreSQL
18.2, 17.8, 16.12, 15.16, and 14.21 are affected.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2026-2003?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| postgresql-10 | 26.04 LTS resolute | Not in release |
| 25.10 questing | Not in release |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Not in release |
| 18.04 LTS bionic | Needs evaluation |
| postgresql-12 | 26.04 LTS resolute | Not in release |
| 25.10 questing | Not in release |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Not in release |
| 20.04 LTS focal | Needs evaluation |
| postgresql-14 | 26.04 LTS resolute | Not in release |
| 25.10 questing | Not in release |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Fixed 14.22-0ubuntu0.22.04.1 |
| postgresql-16 | 26.04 LTS resolute | Not in release |
| 25.10 questing | Not in release |
| 24.04 LTS noble | Fixed 16.13-0ubuntu0.24.04.1 |
| 22.04 LTS jammy | Not in release |
| postgresql-17 | 26.04 LTS resolute | Not in release |
| 25.10 questing | Fixed 17.9-0ubuntu0.25.10.1 |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Not in release |
| postgresql-18 | 26.04 LTS resolute | Not affected |
| 25.10 questing | Not in release |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Not in release |
| postgresql-9.3 | 26.04 LTS resolute | Not in release |
| 25.10 questing | Not in release |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Not in release |
| 14.04 LTS trusty | Vulnerable, fix deferred |
| postgresql-9.5 | 26.04 LTS resolute | Not in release |
| 25.10 questing | Not in release |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Not in release |
| 16.04 LTS xenial | Needs evaluation |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [leosilva](https://launchpad.net/~leosilva)

PostgreSQL 9.3 is end of life upstream, and no updates are
are available. Marking as deferred in -esm-main releases.

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

4.3 · Medium

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | Low |
  | Privileges required | Low |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | Low |
  | Integrity impact | None |
  | Availability impact | None |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 4.3 · Medium |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-2003)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2026-2003)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2026-2003)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2026-2003)

### Related Ubuntu Security Notices (USN)

+ [USN-8072-1](https://usn.ubuntu.com/USN-8072-1)
+ PostgreSQL vulnerabilities
+ 4 March 2026

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2026-2003>
* <https://www.postgresql.org/about/news/postgresql-182-178-1612-1516-and-1421-released-3235/>
* <https://www.postgresql.org/support/security/CVE-2026-2003/>
