This update for postgresql10 fixes the following issues: - Upgrade to 10.22: - CVE-2022-2625: Fixed an issue where extension scripts would replace objects not belonging to that extension (bsc#1202368). - Upgrade to 10.21: - CVE-2022-1552: Confined additional operations within "security restricted operation" sandboxes (bsc#1199475). - Upgrade to 10.20 (bsc#1195680) - Add constraints file with 12GB of memory for s390x as a workaround (boo#1190740) - Upgrade to version 10.19 (bsc#1192516): - CVE-2021-23214: Made the server reject extraneous data after an SSL or GSS encryption handshake - CVE-2021-23222: Made libpq reject extraneous data after an SSL or GSS encryption handshake - Fix for build with llvm12 on s390x. (bsc#1185952) - Re-enable 'icu' for PostgreSQL 10. (bsc#1179945)
#1179945 #1183168 #1185952 #1187751 #1190177
#1190740 #1192516 #1195680 #1199475 #1202368
Cross- CVE-2021-23214 CVE-2021-23222 CVE-2022-1552
CVE-2022-2625
CVSS scores:
CVE-2021-23214 (NVD) : 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE-2021-23214 (SUSE): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE-2021-23222 (NVD) : 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVE-2021-23222 (SUSE): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
CVE-2022-1552 (SUSE): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE-2022-2625 (NVD) : 8 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CVE-2022-2625 (SUSE): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Affected Products:
SUSE CaaS Platform 4.0
SUSE Enterprise Storage 6
Get the latest Linux and open source security news straight to your inbox.