#1148946 pgbouncer: CVE-2026-6668 CVE-2026-6669 CVE-2026-19888

Package:
src:pgbouncer
Source:
src:pgbouncer
Submitter:
Salvatore Bonaccorso
Date:
2026-09-25 12:31:02 UTC
Severity:
normal
Tags:
#1148946#5
Date:
2026-09-25 12:28:56 UTC
From:
To:
Hi,

The following vulnerabilities were published for pgbouncer.

CVE-2026-6668[0]:
| Integer overflow in the packet buffer growth logic in PgBouncer
| through 1.25.2 allows an unauthenticated remote attacker to cause a
| denial of service. Sufficiently large input makes the buffer size
| computation overflow, leaving the growth loop unable to terminate.
| Because PgBouncer serves all clients from a single process, this
| saturates a CPU core and stalls every pooled connection until the
| process is killed. Both unauthenticated and authenticated code paths
| can reach the overflow.


CVE-2026-6669[1]:
| Missing upper bound on the key derivation iteration count accepted
| during SCRAM authentication to a backend server in PgBouncer through
| 1.25.2 allows a malicious or compromised PostgreSQL backend to cause
| uncontrolled CPU consumption in PgBouncer. The resulting key
| derivation cannot be interrupted in frontend builds such as
| PgBouncer. Because PgBouncer serves all clients from a single
| process, one backend can in this way stop it from serving traffic
| for every other database and client it is pooling, so the failure of
| a single backend is not contained.


CVE-2026-19888[2]:
| Missing validation of a mandatory attribute in the SCRAM client-
| final-message parser in PgBouncer through 1.25.2 allows an
| unauthenticated remote attacker to crash the process. A malformed
| message can make the parser report success while leaving a required
| value unset, which is then dereferenced as a NULL pointer. The crash
| occurs before any credential is verified, so no valid account is
| required. Because PgBouncer serves all clients from a single
| process, this terminates every pooled connection.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-6668
https://www.cve.org/CVERecord?id=CVE-2026-6668
[1] https://security-tracker.debian.org/tracker/CVE-2026-6669
https://www.cve.org/CVERecord?id=CVE-2026-6669
[2] https://security-tracker.debian.org/tracker/CVE-2026-19888
https://www.cve.org/CVERecord?id=CVE-2026-19888

Regards,
Salvatore