Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2025:4363-1

Опубликовано: 11 дек. 2025
Источник: suse-cvrf

Описание

Security update for postgresql17, postgresql18

This update for postgresql17, postgresql18 fixes the following issues:

Changes in postgresql18:

  • Fix build with uring for post SLE15 code streams.

Update to 18.1:

  • https://www.postgresql.org/about/news/p-3171/
  • https://www.postgresql.org/docs/release/18.1/
  • bsc#1253332, CVE-2025-12817: Missing check for CREATE privileges on the schema in CREATE STATISTICS allowed table owners to create statistics in any schema, potentially leading to unexpected naming conflicts.
  • bsc#1253333, CVE-2025-12818: Several places in libpq were not sufficiently careful about computing the required size of a memory allocation. Sufficiently large inputs could cause integer overflow, resulting in an undersized buffer, which would then lead to writing past the end of the buffer.
  • pg_config --libs returns -lnuma so we need to require it.

Update to 18.0:

Changes in postgresql17:

Update to 17.7:

  • https://www.postgresql.org/about/news/p-3171/
  • https://www.postgresql.org/docs/release/17.7/
  • bsc#1253332, CVE-2025-12817: Missing check for CREATE privileges on the schema in CREATE STATISTICS allowed table owners to create statistics in any schema, potentially leading to unexpected naming conflicts.
  • bsc#1253333, CVE-2025-12818: Several places in libpq were not sufficiently careful about computing the required size of a memory allocation. Sufficiently large inputs could cause integer overflow, resulting in an undersized buffer, which would then lead to writing past the end of the buffer.
  • switch library to pg 18

Список пакетов

Container private-registry/harbor-db:latest
libpq5-18.1-150600.13.3.1
postgresql-18-150600.17.9.1
postgresql-server-18-150600.17.9.1
postgresql17-17.7-150600.13.19.1
postgresql17-server-17.7-150600.13.19.1
Container suse/kea:latest
libpq5-18.1-150600.13.3.1
Container suse/postgres:16
libpq5-18.1-150600.13.3.1
postgresql-18-150700.23.3.1
postgresql-server-18-150700.23.3.1
Container suse/postgres:latest
libpq5-18.1-150600.13.3.1
postgresql-18-150700.23.3.1
postgresql-server-18-150700.23.3.1
postgresql17-17.7-150600.13.19.1
postgresql17-server-17.7-150600.13.19.1
SUSE Linux Enterprise Module for Basesystem 15 SP6
libpq5-18.1-150600.13.3.1
libpq5-32bit-18.1-150600.13.3.1
postgresql-18-150600.17.9.1
postgresql17-17.7-150600.13.19.1
postgresql18-18.1-150600.13.3.1
SUSE Linux Enterprise Module for Basesystem 15 SP7
libpq5-18.1-150600.13.3.1
libpq5-32bit-18.1-150600.13.3.1
postgresql-18-150700.23.3.1
postgresql17-17.7-150600.13.19.1
postgresql18-18.1-150600.13.3.1
SUSE Linux Enterprise Module for Package Hub 15 SP6
postgresql-18-150600.17.9.1
postgresql-contrib-18-150600.17.9.1
postgresql-devel-18-150600.17.9.1
postgresql-docs-18-150600.17.9.1
postgresql-llvmjit-18-150600.17.9.1
postgresql-llvmjit-devel-18-150600.17.9.1
postgresql-plperl-18-150600.17.9.1
postgresql-plpython-18-150600.17.9.1
postgresql-pltcl-18-150600.17.9.1
postgresql-server-18-150600.17.9.1
postgresql-server-devel-18-150600.17.9.1
postgresql-test-18-150600.17.9.1
postgresql17-llvmjit-17.7-150600.13.19.1
postgresql17-llvmjit-devel-17.7-150600.13.19.1
postgresql17-test-17.7-150600.13.19.1
postgresql18-llvmjit-18.1-150600.13.3.1
postgresql18-llvmjit-devel-18.1-150600.13.3.1
postgresql18-test-18.1-150600.13.3.1
SUSE Linux Enterprise Module for Package Hub 15 SP7
postgresql-18-150700.23.3.1
postgresql-contrib-18-150700.23.3.1
postgresql-devel-18-150700.23.3.1
postgresql-docs-18-150700.23.3.1
postgresql-llvmjit-18-150700.23.3.1
postgresql-llvmjit-devel-18-150700.23.3.1
postgresql-plperl-18-150700.23.3.1
postgresql-plpython-18-150700.23.3.1
postgresql-pltcl-18-150700.23.3.1
postgresql-server-18-150700.23.3.1
postgresql-server-devel-18-150700.23.3.1
postgresql-test-18-150700.23.3.1
postgresql17-llvmjit-17.7-150600.13.19.1
postgresql17-llvmjit-devel-17.7-150600.13.19.1
postgresql17-test-17.7-150600.13.19.1
postgresql18-llvmjit-18.1-150600.13.3.1
postgresql18-llvmjit-devel-18.1-150600.13.3.1
postgresql18-test-18.1-150600.13.3.1
SUSE Linux Enterprise Module for Server Applications 15 SP6
libecpg6-18.1-150600.13.3.1
postgresql-contrib-18-150600.17.9.1
postgresql-devel-18-150600.17.9.1
postgresql-docs-18-150600.17.9.1
postgresql-plperl-18-150600.17.9.1
postgresql-plpython-18-150600.17.9.1
postgresql-pltcl-18-150600.17.9.1
postgresql-server-18-150600.17.9.1
postgresql-server-devel-18-150600.17.9.1
postgresql17-contrib-17.7-150600.13.19.1
postgresql17-devel-17.7-150600.13.19.1
postgresql17-docs-17.7-150600.13.19.1
postgresql17-plperl-17.7-150600.13.19.1
postgresql17-plpython-17.7-150600.13.19.1
postgresql17-pltcl-17.7-150600.13.19.1
postgresql17-server-17.7-150600.13.19.1
postgresql17-server-devel-17.7-150600.13.19.1
postgresql18-contrib-18.1-150600.13.3.1
postgresql18-devel-18.1-150600.13.3.1
postgresql18-docs-18.1-150600.13.3.1
postgresql18-plperl-18.1-150600.13.3.1
postgresql18-plpython-18.1-150600.13.3.1
postgresql18-pltcl-18.1-150600.13.3.1
postgresql18-server-18.1-150600.13.3.1
postgresql18-server-devel-18.1-150600.13.3.1
SUSE Linux Enterprise Module for Server Applications 15 SP7
libecpg6-18.1-150600.13.3.1
postgresql-contrib-18-150700.23.3.1
postgresql-devel-18-150700.23.3.1
postgresql-docs-18-150700.23.3.1
postgresql-plperl-18-150700.23.3.1
postgresql-plpython-18-150700.23.3.1
postgresql-pltcl-18-150700.23.3.1
postgresql-server-18-150700.23.3.1
postgresql-server-devel-18-150700.23.3.1
postgresql17-contrib-17.7-150600.13.19.1
postgresql17-devel-17.7-150600.13.19.1
postgresql17-docs-17.7-150600.13.19.1
postgresql17-plperl-17.7-150600.13.19.1
postgresql17-plpython-17.7-150600.13.19.1
postgresql17-pltcl-17.7-150600.13.19.1
postgresql17-server-17.7-150600.13.19.1
postgresql17-server-devel-17.7-150600.13.19.1
postgresql18-contrib-18.1-150600.13.3.1
postgresql18-devel-18.1-150600.13.3.1
postgresql18-docs-18.1-150600.13.3.1
postgresql18-plperl-18.1-150600.13.3.1
postgresql18-plpython-18.1-150600.13.3.1
postgresql18-pltcl-18.1-150600.13.3.1
postgresql18-server-18.1-150600.13.3.1
postgresql18-server-devel-18.1-150600.13.3.1
openSUSE Leap 15.6
libecpg6-18.1-150600.13.3.1
libecpg6-32bit-18.1-150600.13.3.1
libpq5-18.1-150600.13.3.1
libpq5-32bit-18.1-150600.13.3.1
postgresql-18-150600.17.9.1
postgresql-contrib-18-150600.17.9.1
postgresql-devel-18-150600.17.9.1
postgresql-docs-18-150600.17.9.1
postgresql-llvmjit-18-150600.17.9.1
postgresql-llvmjit-devel-18-150600.17.9.1
postgresql-plperl-18-150600.17.9.1
postgresql-plpython-18-150600.17.9.1
postgresql-pltcl-18-150600.17.9.1
postgresql-server-18-150600.17.9.1
postgresql-server-devel-18-150600.17.9.1
postgresql-test-18-150600.17.9.1
postgresql17-17.7-150600.13.19.1
postgresql17-contrib-17.7-150600.13.19.1
postgresql17-devel-17.7-150600.13.19.1
postgresql17-docs-17.7-150600.13.19.1
postgresql17-llvmjit-17.7-150600.13.19.1
postgresql17-llvmjit-devel-17.7-150600.13.19.1
postgresql17-plperl-17.7-150600.13.19.1
postgresql17-plpython-17.7-150600.13.19.1
postgresql17-pltcl-17.7-150600.13.19.1
postgresql17-server-17.7-150600.13.19.1
postgresql17-server-devel-17.7-150600.13.19.1
postgresql17-test-17.7-150600.13.19.1
postgresql18-18.1-150600.13.3.1
postgresql18-contrib-18.1-150600.13.3.1
postgresql18-devel-18.1-150600.13.3.1
postgresql18-docs-18.1-150600.13.3.1
postgresql18-llvmjit-18.1-150600.13.3.1
postgresql18-llvmjit-devel-18.1-150600.13.3.1
postgresql18-plperl-18.1-150600.13.3.1
postgresql18-plpython-18.1-150600.13.3.1
postgresql18-pltcl-18.1-150600.13.3.1
postgresql18-server-18.1-150600.13.3.1
postgresql18-server-devel-18.1-150600.13.3.1
postgresql18-test-18.1-150600.13.3.1

Описание

Missing authorization in PostgreSQL CREATE STATISTICS command allows a table owner to achieve denial of service against other CREATE STATISTICS users by creating in any schema. A later CREATE STATISTICS for the same name, from a user having the CREATE privilege, would then fail. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.


Затронутые продукты
Container private-registry/harbor-db:latest:libpq5-18.1-150600.13.3.1
Container private-registry/harbor-db:latest:postgresql-18-150600.17.9.1
Container private-registry/harbor-db:latest:postgresql-server-18-150600.17.9.1
Container private-registry/harbor-db:latest:postgresql17-17.7-150600.13.19.1

Ссылки

Описание

Integer wraparound in multiple PostgreSQL libpq client library functions allows an application input provider or network peer to cause libpq to undersize an allocation and write out-of-bounds by hundreds of megabytes. This results in a segmentation fault for the application using libpq. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.


Затронутые продукты
Container private-registry/harbor-db:latest:libpq5-18.1-150600.13.3.1
Container private-registry/harbor-db:latest:postgresql-18-150600.17.9.1
Container private-registry/harbor-db:latest:postgresql-server-18-150600.17.9.1
Container private-registry/harbor-db:latest:postgresql17-17.7-150600.13.19.1

Ссылки