Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

SUSE 15: 2022:2893-1 Important: Postgresql10 Security Fixes for Issues

suse
Calendar Grey August 25, 2022
Dist Suse Esm H88
SUSE Security Patch for postgresql11: Critical updates addressing various vulnerabilities such as buffer overflows and potential Denial of Service.
An update that solves four vulnerabilities and has 6 fixes is now available

Summary

This update for postgresql10 fixes the following issues: - Upgrade to 10.22: - CVE-2022-2625: Fixed an issue where extension scripts would replace objects not belonging to that extension (bsc#1202368). - Upgrade to 10.21: - CVE-2022-1552: Confined additional operations within "security restricted operation" sandboxes (bsc#1199475). - Upgrade to 10.20 (bsc#1195680) - Add constraints file with 12GB of memory for s390x as a workaround (boo#1190740) - Upgrade to version 10.19 (bsc#1192516): - CVE-2021-23214: Made the server reject extraneous data after an SSL or GSS encryption handshake - CVE-2021-23222: Made libpq reject extraneous data after an SSL or GSS encryption handshake - Fix for build with llvm12 on s390x. (bsc#1185952) - Re-enable 'icu' for PostgreSQL 10. (bsc#1179945)

References

#1179945 #1183168 #1185952 #1187751 #1190177

#1190740 #1192516 #1195680 #1199475 #1202368

Cross- CVE-2021-23214 CVE-2021-23222 CVE-2022-1552

CVE-2022-2625

CVSS scores:

CVE-2021-23214 (NVD) : 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CVE-2021-23214 (SUSE): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CVE-2021-23222 (NVD) : 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

CVE-2021-23222 (SUSE): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

CVE-2022-1552 (SUSE): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVE-2022-2625 (NVD) : 8 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

CVE-2022-2625 (SUSE): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

Affected Products:

SUSE CaaS Platform 4.0

SUSE Enterprise Storage 6

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2022:2893-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here