Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Mageia 9: PostgreSQL Critical Create Privilege Issue MGASA-2025-0302

mageia
Calendar Grey November 18, 2025
Dist Mageia Esm H88
PostgreSQL security patch for Mageia releases fixing critical vulnerabilities in postgresql15 and postgresql13 packages.
MGASA-2025-0302 - Updated postgresql15 & postgresql13 packages fix security vulnerabilities

Summary

Description: PostgreSQL CREATE STATISTICS does not check for schema CREATE privilege. (CVE-2025-12817) PostgreSQL libpq undersizes allocations, via integer wraparound. (CVE-2025-12818)

References

- https://bugs.mageia.org/show_bug.cgi?id=34752

- https://www.postgresql.org/about/news/postgresql-181-177-1611-1515-1420-and-1323-released-3171/

- https://www.cve.org/CVERecord?id=CVE-2025-12817

- https://www.cve.org/CVERecord?id=CVE-2025-12818

Resolution

SRPMS

- 9/core/postgresql15-15.15-1.mga9

- 9/core/postgresql13-13.23-1.mga9

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 18 Nov 2025
URL: https://advisories.mageia.org/MGASA-2025-0302.html
Type: security
CVE: CVE-2025-12817, CVE-2025-12818

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here