Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-12818

Опубликовано: 13 нояб. 2025
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Integer wraparound in multiple PostgreSQL libpq client library functions allows an application input provider or network peer to cause libpq to undersize an allocation and write out-of-bounds by hundreds of megabytes. This results in a segmentation fault for the application using libpq. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.

A vulnerability has been identified in PostgreSQL’s libpq client library, where integer wraparound in several allocation-size calculations allows a peer or input provider to cause an undersized buffer and then write out-of-bounds by hundreds of megabytes. This can lead to a client application segmentation fault or crash when using libpq to connect to a PostgreSQL server.

Отчет

This issue is rated Moderate severity by Red Hat Product Security, even though it carries a High CVSS v3.1 score. The flaw resides in the libpq client library and can be triggered when a client receives specially crafted PostgreSQL protocol data that causes an integer wraparound and an out-of-bounds write. The attack complexity is Low because the malformed protocol message is processed immediately during connection, with no timing or environmental conditions required. However, the impact is limited to a denial of service of the client application only. As a result, Red Hat classifies the overall product impact as Moderate, reflecting that the flaw can interrupt client availability.

Меры по смягчению последствий

No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6postgresqlOut of support scope
Red Hat Enterprise Linux 7postgresqlNot affected
Red Hat Enterprise Linux 8postgresql:12/postgresqlNot affected
Red Hat Enterprise Linux 10postgresql16FixedRHSA-2026:052513.01.2026
Red Hat Enterprise Linux 10libpqFixedRHSA-2026:059414.01.2026
Red Hat Enterprise Linux 10.0 Extended Update Supportpostgresql16FixedRHSA-2026:045612.01.2026
Red Hat Enterprise Linux 10.0 Extended Update SupportlibpqFixedRHSA-2026:086520.01.2026
Red Hat Enterprise Linux 8postgresqlFixedRHSA-2026:051913.01.2026
Red Hat Enterprise Linux 8postgresqlFixedRHSA-2026:052313.01.2026
Red Hat Enterprise Linux 8postgresqlFixedRHSA-2026:052413.01.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2414826postgresql: libpq: libpq undersizes allocations, via integer wraparound

EPSS

Процентиль: 27%
0.00096
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
4 месяца назад

Integer wraparound in multiple PostgreSQL libpq client library functions allows an application input provider or network peer to cause libpq to undersize an allocation and write out-of-bounds by hundreds of megabytes. This results in a segmentation fault for the application using libpq. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.

CVSS3: 5.9
nvd
4 месяца назад

Integer wraparound in multiple PostgreSQL libpq client library functions allows an application input provider or network peer to cause libpq to undersize an allocation and write out-of-bounds by hundreds of megabytes. This results in a segmentation fault for the application using libpq. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.

CVSS3: 5.9
msrc
4 месяца назад

PostgreSQL libpq undersizes allocations, via integer wraparound

CVSS3: 5.9
debian
4 месяца назад

Integer wraparound in multiple PostgreSQL libpq client library functio ...

rocky
2 месяца назад

Moderate: libpq security update

EPSS

Процентиль: 27%
0.00096
Низкий

7.5 High

CVSS3