Alerts This Week
Warning Icon 1 1,394
Alerts This Week
Warning Icon 1 1,394

Ubuntu 24.10 LTS: USN-7315-1 critical: postgresql SQL injection

ubuntu
Calendar Grey March 3, 2025
Dist Ubuntu Esm H88
Ubuntu USN-7316-1 highlights security patches for PostgreSQL aimed at mitigating remote SQL injection vulnerabilities and unauthorized execution of code.
PostgreSQL could be made to execute arbitrary code if it received specially crafted input.

Summary

PostgreSQL could be made to execute arbitrary code if it received specially

crafted input.

Software Description:

- postgresql-16: Object-relational SQL database

- postgresql-14: Object-relational SQL database

- postgresql-12: Object-relational SQL database

Details:

Stephen Fewer discovered that PostgreSQL incorrectly handled quoting syntax

in certain scenarios. A remote attacker could possibly use this issue to

perform SQL injection attacks.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 24.10
   postgresql-16                   16.8-0ubuntu0.24.10.1
   postgresql-client-16            16.8-0ubuntu0.24.10.1

Ubuntu 24.04 LTS
   postgresql-16                   16.8-0ubuntu0.24.04.1
   postgresql-client-16            16.8-0ubuntu0.24.04.1

Ubuntu 22.04 LTS
   postgresql-14                   14.17-0ubuntu0.22.04.1
   postgresql-client-14            14.17-0ubuntu0.22.04.1

Ubuntu 20.04 LTS
   postgresql-12                   12.22-0ubuntu0.20.04.2
   postgresql-client-12            12.22-0ubuntu0.20.04.2

This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart PostgreSQL to
make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-7315-1

CVE-2025-1094

Severity
critical
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-7315-1

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here