CVE-2026-61822 PUBLISHED

pg_partman disable maintenance for all partition sets

Assigner: GitHub_M
Reserved: 10.07.2026 Published: 18.09.2026 Updated: 18.09.2026

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, run_maintenance() handles exceptions outside the loop that processes rows from part_config, so an exception for one partition set immediately terminates the loop and skips every later set. A role with partman_user access can insert or update a row that reliably fails and assign it a low maintenance_order value so it is processed before legitimate rows. Repeated maintenance ticks then abort before legitimate partition sets are maintained, causing database-wide loss of automated partition maintenance. This issue is fixed in version 5.5.0.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS Score: 6.5

Product Status

Vendor pgpartman
Product pg_partman
Versions
  • Version < 5.5.0 is affected

References

Problem Types

  • CWE-703: Improper Check or Handling of Exceptional Conditions CWE