{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/timescaledb-2.29.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-70634"},{"cvss":7.1,"id":"CVE-2026-70635"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["TimescaleDB (2.29.1)","TimescaleDB (\u003c= 2.29.1)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Timescale"],"content_html":"\u003cp\u003eTimescaleDB versions up to and including 2.29.1 contain an out-of-bounds read vulnerability (CVE-2026-70634) located within the Dictionary compression reverse row iterator (tsl/src/compression/algorithms/dictionary.c). While the forward decoding path correctly validates index values, the reverse path relies on an assertion that is omitted in production release builds. This oversight leaves the 64-bit Simple8b index unvalidated and the read offset effectively attacker-controlled.\u003c/p\u003e\n\u003cp\u003eAn attacker possessing DML (Data Manipulation Language) access to a physical compressed relation can insert a specifically crafted datum. By subsequently executing a reverse-order scan on the table, the attacker can trigger the out-of-bounds read. If the targeted column utilizes a pass-by-value type, the database engine returns the out-of-bounds memory contents to the client as a legitimate column value. This mechanism bypasses standard SQL access controls, potentially leaking sensitive information stored within the backend memory and the shared buffer pool. The vulnerability is patched in commit 517c13e.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the unauthorized disclosure of sensitive server-side memory, including contents of the shared buffer pool. This information leakage could expose credentials, data from other user sessions, or other proprietary information resident in the database backend memory. The vulnerability is restricted to authenticated users with DML privileges on compressed tables, limiting the attack surface to existing database users.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade all TimescaleDB instances to a version containing the fix (commit 517c13e or later).\u003c/li\u003e\n\u003cli\u003eReview database user permissions and restrict DML access to sensitive compressed relations to trusted accounts only.\u003c/li\u003e\n\u003cli\u003eMonitor database logs for unusual reverse-order scan queries or suspicious DML activity on compressed tables if database auditing is available.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-08-06T23:31:44Z","date_published":"2026-08-06T23:31:41Z","id":"https://feed.craftedsignal.io/briefs/2026-08-timescaledb-oob-read/","summary":"An out-of-bounds read vulnerability in the TimescaleDB Dictionary compression reverse row iterator allows authenticated attackers with DML access to disclose sensitive backend memory and shared buffer pool contents.","title":"Out-of-Bounds Read in TimescaleDB Dictionary Compression","url":"https://feed.craftedsignal.io/briefs/2026-08-timescaledb-oob-read/"}],"language":"en","title":"CraftedSignal Threat Feed - TimescaleDB (2.29.1)","version":"https://jsonfeed.org/version/1.1"}