Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2025:4364-1

Опубликовано: 11 дек. 2025
Источник: suse-cvrf

Описание

Security update for postgresql17, postgresql18

This update for postgresql17, postgresql18 fixes the following issues:

Changes in postgresql18:

  • Fix build with uring for post SLE15 code streams.

Update to 18.1:

  • https://www.postgresql.org/about/news/p-3171/
  • https://www.postgresql.org/docs/release/18.1/
  • bsc#1253332, CVE-2025-12817: Missing check for CREATE privileges on the schema in CREATE STATISTICS allowed table owners to create statistics in any schema, potentially leading to unexpected naming conflicts.
  • bsc#1253333, CVE-2025-12818: Several places in libpq were not sufficiently careful about computing the required size of a memory allocation. Sufficiently large inputs could cause integer overflow, resulting in an undersized buffer, which would then lead to writing past the end of the buffer.
  • pg_config --libs returns -lnuma so we need to require it.

Update to 18.0:

Changes in postgresql17:

Update to 17.7:

  • https://www.postgresql.org/about/news/p-3171/
  • https://www.postgresql.org/docs/release/17.7/
  • bsc#1253332, CVE-2025-12817: Missing check for CREATE privileges on the schema in CREATE STATISTICS allowed table owners to create statistics in any schema, potentially leading to unexpected naming conflicts.
  • bsc#1253333, CVE-2025-12818: Several places in libpq were not sufficiently careful about computing the required size of a memory allocation. Sufficiently large inputs could cause integer overflow, resulting in an undersized buffer, which would then lead to writing past the end of the buffer.
  • switch library to pg 18

Список пакетов

SUSE Enterprise Storage 7.1
libecpg6-18.1-150200.5.3.1
libpq5-18.1-150200.5.3.1
postgresql-18-150300.10.30.2
postgresql-contrib-18-150300.10.30.2
postgresql-devel-18-150300.10.30.2
postgresql-docs-18-150300.10.30.2
postgresql-plperl-18-150300.10.30.2
postgresql-plpython-18-150300.10.30.2
postgresql-pltcl-18-150300.10.30.2
postgresql-server-18-150300.10.30.2
postgresql-server-devel-18-150300.10.30.2
SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS
libecpg6-18.1-150200.5.3.1
libpq5-18.1-150200.5.3.1
postgresql-18-150300.10.30.2
postgresql-contrib-18-150300.10.30.2
postgresql-devel-18-150300.10.30.2
postgresql-docs-18-150300.10.30.2
postgresql-plperl-18-150300.10.30.2
postgresql-plpython-18-150300.10.30.2
postgresql-pltcl-18-150300.10.30.2
postgresql-server-18-150300.10.30.2
postgresql-server-devel-18-150300.10.30.2
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS
libecpg6-18.1-150200.5.3.1
libpq5-18.1-150200.5.3.1
libpq5-32bit-18.1-150200.5.3.1
postgresql-18-150400.4.21.2
postgresql-contrib-18-150400.4.21.2
postgresql-devel-18-150400.4.21.2
postgresql-docs-18-150400.4.21.2
postgresql-llvmjit-18-150400.4.21.2
postgresql-llvmjit-devel-18-150400.4.21.2
postgresql-plperl-18-150400.4.21.2
postgresql-plpython-18-150400.4.21.2
postgresql-pltcl-18-150400.4.21.2
postgresql-server-18-150400.4.21.2
postgresql-server-devel-18-150400.4.21.2
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS
libecpg6-18.1-150200.5.3.1
libpq5-18.1-150200.5.3.1
libpq5-32bit-18.1-150200.5.3.1
postgresql-18-150400.4.21.2
postgresql-contrib-18-150400.4.21.2
postgresql-devel-18-150400.4.21.2
postgresql-docs-18-150400.4.21.2
postgresql-llvmjit-18-150400.4.21.2
postgresql-llvmjit-devel-18-150400.4.21.2
postgresql-plperl-18-150400.4.21.2
postgresql-plpython-18-150400.4.21.2
postgresql-pltcl-18-150400.4.21.2
postgresql-server-18-150400.4.21.2
postgresql-server-devel-18-150400.4.21.2
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS
libecpg6-18.1-150200.5.3.1
libpq5-18.1-150200.5.3.1
libpq5-32bit-18.1-150200.5.3.1
postgresql-18-150500.10.12.2
postgresql-contrib-18-150500.10.12.2
postgresql-devel-18-150500.10.12.2
postgresql-docs-18-150500.10.12.2
postgresql-plperl-18-150500.10.12.2
postgresql-plpython-18-150500.10.12.2
postgresql-pltcl-18-150500.10.12.2
postgresql-server-18-150500.10.12.2
postgresql-server-devel-18-150500.10.12.2
postgresql17-17.7-150200.5.19.1
postgresql17-contrib-17.7-150200.5.19.1
postgresql17-devel-17.7-150200.5.19.1
postgresql17-docs-17.7-150200.5.19.1
postgresql17-plperl-17.7-150200.5.19.1
postgresql17-plpython-17.7-150200.5.19.1
postgresql17-pltcl-17.7-150200.5.19.1
postgresql17-server-17.7-150200.5.19.1
postgresql17-server-devel-17.7-150200.5.19.1
SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS
libecpg6-18.1-150200.5.3.1
libpq5-18.1-150200.5.3.1
libpq5-32bit-18.1-150200.5.3.1
postgresql-18-150500.10.12.2
postgresql-contrib-18-150500.10.12.2
postgresql-devel-18-150500.10.12.2
postgresql-docs-18-150500.10.12.2
postgresql-plperl-18-150500.10.12.2
postgresql-plpython-18-150500.10.12.2
postgresql-pltcl-18-150500.10.12.2
postgresql-server-18-150500.10.12.2
postgresql-server-devel-18-150500.10.12.2
postgresql17-17.7-150200.5.19.1
postgresql17-contrib-17.7-150200.5.19.1
postgresql17-devel-17.7-150200.5.19.1
postgresql17-docs-17.7-150200.5.19.1
postgresql17-plperl-17.7-150200.5.19.1
postgresql17-plpython-17.7-150200.5.19.1
postgresql17-pltcl-17.7-150200.5.19.1
postgresql17-server-17.7-150200.5.19.1
postgresql17-server-devel-17.7-150200.5.19.1
SUSE Linux Enterprise Server 15 SP3-LTSS
libecpg6-18.1-150200.5.3.1
libpq5-18.1-150200.5.3.1
postgresql-18-150300.10.30.2
postgresql-contrib-18-150300.10.30.2
postgresql-devel-18-150300.10.30.2
postgresql-docs-18-150300.10.30.2
postgresql-plperl-18-150300.10.30.2
postgresql-plpython-18-150300.10.30.2
postgresql-pltcl-18-150300.10.30.2
postgresql-server-18-150300.10.30.2
postgresql-server-devel-18-150300.10.30.2
SUSE Linux Enterprise Server 15 SP4-LTSS
libecpg6-18.1-150200.5.3.1
libpq5-18.1-150200.5.3.1
libpq5-32bit-18.1-150200.5.3.1
postgresql-18-150400.4.21.2
postgresql-contrib-18-150400.4.21.2
postgresql-devel-18-150400.4.21.2
postgresql-docs-18-150400.4.21.2
postgresql-llvmjit-18-150400.4.21.2
postgresql-llvmjit-devel-18-150400.4.21.2
postgresql-plperl-18-150400.4.21.2
postgresql-plpython-18-150400.4.21.2
postgresql-pltcl-18-150400.4.21.2
postgresql-server-18-150400.4.21.2
postgresql-server-devel-18-150400.4.21.2
SUSE Linux Enterprise Server 15 SP5-LTSS
libecpg6-18.1-150200.5.3.1
libpq5-18.1-150200.5.3.1
libpq5-32bit-18.1-150200.5.3.1
postgresql-18-150500.10.12.2
postgresql-contrib-18-150500.10.12.2
postgresql-devel-18-150500.10.12.2
postgresql-docs-18-150500.10.12.2
postgresql-plperl-18-150500.10.12.2
postgresql-plpython-18-150500.10.12.2
postgresql-pltcl-18-150500.10.12.2
postgresql-server-18-150500.10.12.2
postgresql-server-devel-18-150500.10.12.2
postgresql17-17.7-150200.5.19.1
postgresql17-contrib-17.7-150200.5.19.1
postgresql17-devel-17.7-150200.5.19.1
postgresql17-docs-17.7-150200.5.19.1
postgresql17-llvmjit-17.7-150200.5.19.1
postgresql17-llvmjit-devel-17.7-150200.5.19.1
postgresql17-plperl-17.7-150200.5.19.1
postgresql17-plpython-17.7-150200.5.19.1
postgresql17-pltcl-17.7-150200.5.19.1
postgresql17-server-17.7-150200.5.19.1
postgresql17-server-devel-17.7-150200.5.19.1
SUSE Linux Enterprise Server for SAP Applications 15 SP3
libecpg6-18.1-150200.5.3.1
libpq5-18.1-150200.5.3.1
postgresql-18-150300.10.30.2
postgresql-contrib-18-150300.10.30.2
postgresql-devel-18-150300.10.30.2
postgresql-docs-18-150300.10.30.2
postgresql-plperl-18-150300.10.30.2
postgresql-plpython-18-150300.10.30.2
postgresql-pltcl-18-150300.10.30.2
postgresql-server-18-150300.10.30.2
postgresql-server-devel-18-150300.10.30.2
SUSE Linux Enterprise Server for SAP Applications 15 SP4
libecpg6-18.1-150200.5.3.1
libpq5-18.1-150200.5.3.1
libpq5-32bit-18.1-150200.5.3.1
postgresql-18-150400.4.21.2
postgresql-contrib-18-150400.4.21.2
postgresql-devel-18-150400.4.21.2
postgresql-docs-18-150400.4.21.2
postgresql-llvmjit-18-150400.4.21.2
postgresql-llvmjit-devel-18-150400.4.21.2
postgresql-plperl-18-150400.4.21.2
postgresql-plpython-18-150400.4.21.2
postgresql-pltcl-18-150400.4.21.2
postgresql-server-18-150400.4.21.2
postgresql-server-devel-18-150400.4.21.2
SUSE Linux Enterprise Server for SAP Applications 15 SP5
libecpg6-18.1-150200.5.3.1
libpq5-18.1-150200.5.3.1
libpq5-32bit-18.1-150200.5.3.1
postgresql-18-150500.10.12.2
postgresql-contrib-18-150500.10.12.2
postgresql-devel-18-150500.10.12.2
postgresql-docs-18-150500.10.12.2
postgresql-plperl-18-150500.10.12.2
postgresql-plpython-18-150500.10.12.2
postgresql-pltcl-18-150500.10.12.2
postgresql-server-18-150500.10.12.2
postgresql-server-devel-18-150500.10.12.2
postgresql17-17.7-150200.5.19.1
postgresql17-contrib-17.7-150200.5.19.1
postgresql17-devel-17.7-150200.5.19.1
postgresql17-docs-17.7-150200.5.19.1
postgresql17-llvmjit-17.7-150200.5.19.1
postgresql17-llvmjit-devel-17.7-150200.5.19.1
postgresql17-plperl-17.7-150200.5.19.1
postgresql17-plpython-17.7-150200.5.19.1
postgresql17-pltcl-17.7-150200.5.19.1
postgresql17-server-17.7-150200.5.19.1
postgresql17-server-devel-17.7-150200.5.19.1
SUSE Manager Proxy LTS 4.3
libecpg6-18.1-150200.5.3.1
libpq5-18.1-150200.5.3.1
libpq5-32bit-18.1-150200.5.3.1
postgresql-18-150400.4.21.2
postgresql-contrib-18-150400.4.21.2
postgresql-devel-18-150400.4.21.2
postgresql-docs-18-150400.4.21.2
postgresql-plperl-18-150400.4.21.2
postgresql-plpython-18-150400.4.21.2
postgresql-pltcl-18-150400.4.21.2
postgresql-server-18-150400.4.21.2
postgresql-server-devel-18-150400.4.21.2
SUSE Manager Server LTS 4.3
libecpg6-18.1-150200.5.3.1
libpq5-18.1-150200.5.3.1
libpq5-32bit-18.1-150200.5.3.1
postgresql-18-150400.4.21.2
postgresql-contrib-18-150400.4.21.2
postgresql-devel-18-150400.4.21.2
postgresql-docs-18-150400.4.21.2
postgresql-plperl-18-150400.4.21.2
postgresql-plpython-18-150400.4.21.2
postgresql-pltcl-18-150400.4.21.2
postgresql-server-18-150400.4.21.2
postgresql-server-devel-18-150400.4.21.2
postgresql17-17.7-150200.5.19.1
postgresql17-contrib-17.7-150200.5.19.1
postgresql17-devel-17.7-150200.5.19.1
postgresql17-docs-17.7-150200.5.19.1
postgresql17-plperl-17.7-150200.5.19.1
postgresql17-plpython-17.7-150200.5.19.1
postgresql17-pltcl-17.7-150200.5.19.1
postgresql17-server-17.7-150200.5.19.1
postgresql17-server-devel-17.7-150200.5.19.1

Описание

Missing authorization in PostgreSQL CREATE STATISTICS command allows a table owner to achieve denial of service against other CREATE STATISTICS users by creating in any schema. A later CREATE STATISTICS for the same name, from a user having the CREATE privilege, would then fail. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.


Затронутые продукты
SUSE Enterprise Storage 7.1:libecpg6-18.1-150200.5.3.1
SUSE Enterprise Storage 7.1:libpq5-18.1-150200.5.3.1
SUSE Enterprise Storage 7.1:postgresql-18-150300.10.30.2
SUSE Enterprise Storage 7.1:postgresql-contrib-18-150300.10.30.2

Ссылки

Описание

Integer wraparound in multiple PostgreSQL libpq client library functions allows an application input provider or network peer to cause libpq to undersize an allocation and write out-of-bounds by hundreds of megabytes. This results in a segmentation fault for the application using libpq. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.


Затронутые продукты
SUSE Enterprise Storage 7.1:libecpg6-18.1-150200.5.3.1
SUSE Enterprise Storage 7.1:libpq5-18.1-150200.5.3.1
SUSE Enterprise Storage 7.1:postgresql-18-150300.10.30.2
SUSE Enterprise Storage 7.1:postgresql-contrib-18-150300.10.30.2

Ссылки