Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:0458

Опубликовано: 14 янв. 2026
Источник: rocky
Оценка: Moderate

Описание

Moderate: libpq security update

The libpq package provides the PostgreSQL client library, which allows client programs to connect to PostgreSQL servers.

Security Fix(es):

  • postgresql: libpq undersizes allocations, via integer wraparound (CVE-2025-12818)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 9

НаименованиеАрхитектураРелизRPM
libpqi6861.el9_7libpq-13.23-1.el9_7.i686.rpm
libpqx86_641.el9_7libpq-13.23-1.el9_7.x86_64.rpm
libpq-develi6861.el9_7libpq-devel-13.23-1.el9_7.i686.rpm
libpq-develx86_641.el9_7libpq-devel-13.23-1.el9_7.x86_64.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 5.9
ubuntu
3 месяца назад

Integer wraparound in multiple PostgreSQL libpq client library functions allows an application input provider or network peer to cause libpq to undersize an allocation and write out-of-bounds by hundreds of megabytes. This results in a segmentation fault for the application using libpq. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.

CVSS3: 5.9
nvd
3 месяца назад

Integer wraparound in multiple PostgreSQL libpq client library functions allows an application input provider or network peer to cause libpq to undersize an allocation and write out-of-bounds by hundreds of megabytes. This results in a segmentation fault for the application using libpq. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.

CVSS3: 5.9
msrc
3 месяца назад

PostgreSQL libpq undersizes allocations, via integer wraparound

CVSS3: 5.9
debian
3 месяца назад

Integer wraparound in multiple PostgreSQL libpq client library functio ...

rocky
18 дней назад

Moderate: libpq security update