Heap buffer overflow in PostgreSQL plperl return of a tied hash allows the function owner to execute arbitrary code as the operating system user running the database, via a crafted function body. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.
Attacker has permission to "CREATE EXTENSION plperl", or another user previously issued that. Attacker has permission to create objects (temporary objects or non-temporary objects in at least one schema).