Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
This update for postgresql12 fixes the following issues: - Upgrade to 12.12: - CVE-2022-2625: Fixed an issue where extension scripts would replace objects not belonging to that extension (bsc#1202368). - Upgrade to 12.11: - CVE-2022-1552: Confined additional operations within "security restricted operation" sandboxes (bsc#1199475). - Upgrade to 12.10 (bsc#1195680) - Add constraints file with 12GB of memory for s390x as a workaround (boo#1190740) - Upgrade to version 12.9 (bsc#1192516): - CVE-2021-23214: Made the server reject extraneous data after an SSL or GSS encryption handshake - CVE-2021-23222: Made libpq reject extraneous data after an SSL or GSS encryption handshake - Upgrade to version 12.8: - CVE-2021-3677: Fixed memory disclosure in certain queries (bsc#1189748). - Upgrade to version 12.7:
#1179945 #1183168 #1185924 #1185925 #1185926
#1185952 #1187751 #1189748 #1190740 #1192516
#1195680 #1198166 #1199475 #1202368
Cross- CVE-2021-23214 CVE-2021-23222 CVE-2021-32027
CVE-2021-32028 CVE-2021-32029 CVE-2021-3677
CVE-2022-1552 CVE-2022-2625
CVSS scores:
CVE-2021-23214 (NVD) : 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE-2021-23214 (SUSE): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE-2021-23222 (NVD) : 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVE-2021-23222 (SUSE): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
CVE-2021-32027 (NVD) : 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE-2021-32027 (SUSE): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Get the latest Linux and open source security news straight to your inbox.