Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

SUSE: 2022:2958-1 Important: PostgreSQL12 Memory Disclosure Update

suse
Calendar Grey August 31, 2022
Scroller Suse
The latest update addresses 8 concerns in postgresql12 on SUSE Linux Enterprise Server. Key enhancements and bug fixes have been incorporated.
An update that solves 8 vulnerabilities and has 6 fixes is now available

Summary

This update for postgresql12 fixes the following issues: - Upgrade to 12.12: - CVE-2022-2625: Fixed an issue where extension scripts would replace objects not belonging to that extension (bsc#1202368). - Upgrade to 12.11: - CVE-2022-1552: Confined additional operations within "security restricted operation" sandboxes (bsc#1199475). - Upgrade to 12.10 (bsc#1195680) - Add constraints file with 12GB of memory for s390x as a workaround (boo#1190740) - Upgrade to version 12.9 (bsc#1192516): - CVE-2021-23214: Made the server reject extraneous data after an SSL or GSS encryption handshake - CVE-2021-23222: Made libpq reject extraneous data after an SSL or GSS encryption handshake - Upgrade to version 12.8: - CVE-2021-3677: Fixed memory disclosure in certain queries (bsc#1189748). - Upgrade to version 12.7:

References

#1179945 #1183168 #1185924 #1185925 #1185926

#1185952 #1187751 #1189748 #1190740 #1192516

#1195680 #1198166 #1199475 #1202368

Cross- CVE-2021-23214 CVE-2021-23222 CVE-2021-32027

CVE-2021-32028 CVE-2021-32029 CVE-2021-3677

CVE-2022-1552 CVE-2022-2625

CVSS scores:

CVE-2021-23214 (NVD) : 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CVE-2021-23214 (SUSE): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CVE-2021-23222 (NVD) : 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

CVE-2021-23222 (SUSE): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

CVE-2021-32027 (NVD) : 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVE-2021-32027 (SUSE): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2022:2958-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.