Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:0525

Опубликовано: 14 янв. 2026
Источник: rocky
Оценка: Moderate

Описание

Moderate: postgresql16 security update

PostgreSQL is an advanced Object-Relational database management system (DBMS). The base postgresql package contains the client programs that you'll need to access a PostgreSQL DBMS server, as well as HTML documentation for the whole system. These client programs can be located on the same machine as the PostgreSQL server, or on a remote machine that accesses a PostgreSQL server over a network connection. The PostgreSQL server can be found in the postgresql-server sub-package.

Security Fix(es):

  • postgresql: libpq undersizes allocations, via integer wraparound (CVE-2025-12818)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 10

НаименованиеАрхитектураРелизRPM
postgresql-plpython3x86_641.el10_1postgresql-plpython3-16.11-1.el10_1.x86_64.rpm
postgresql-staticx86_641.el10_1postgresql-static-16.11-1.el10_1.x86_64.rpm
postgresql-docsx86_641.el10_1postgresql-docs-16.11-1.el10_1.x86_64.rpm
postgresqlx86_641.el10_1postgresql-16.11-1.el10_1.x86_64.rpm
postgresql-private-develx86_641.el10_1postgresql-private-devel-16.11-1.el10_1.x86_64.rpm
postgresql-contribx86_641.el10_1postgresql-contrib-16.11-1.el10_1.x86_64.rpm
postgresql-upgrade-develx86_641.el10_1postgresql-upgrade-devel-16.11-1.el10_1.x86_64.rpm
postgresql-plperlx86_641.el10_1postgresql-plperl-16.11-1.el10_1.x86_64.rpm
postgresql-server-develx86_641.el10_1postgresql-server-devel-16.11-1.el10_1.x86_64.rpm
postgresql-serverx86_641.el10_1postgresql-server-16.11-1.el10_1.x86_64.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 5.9
ubuntu
3 месяца назад

Integer wraparound in multiple PostgreSQL libpq client library functions allows an application input provider or network peer to cause libpq to undersize an allocation and write out-of-bounds by hundreds of megabytes. This results in a segmentation fault for the application using libpq. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.

CVSS3: 5.9
nvd
3 месяца назад

Integer wraparound in multiple PostgreSQL libpq client library functions allows an application input provider or network peer to cause libpq to undersize an allocation and write out-of-bounds by hundreds of megabytes. This results in a segmentation fault for the application using libpq. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.

CVSS3: 5.9
msrc
3 месяца назад

PostgreSQL libpq undersizes allocations, via integer wraparound

CVSS3: 5.9
debian
3 месяца назад

Integer wraparound in multiple PostgreSQL libpq client library functio ...

rocky
18 дней назад

Moderate: libpq security update