OESA-2025-2728

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2025-2728
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2025-2728.json
JSON Data
https://api.osv.dev/v1/vulns/OESA-2025-2728
Upstream
  • CVE-2025-12817
  • CVE-2025-12818
Published
2025-11-22T11:09:51Z
Modified
2026-08-18T01:19:21.011150800Z
Severity
  • 5.9 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
libpq security update
Details

PostgreSQL is a powerful, open source object-relational database system that uses and extends the SQL language combined with many features that safely store and scale the most complicated data workloads. This package provides the essential shared library for any PostgreSQL client program or interface.

Security Fix(es):

Missing authorization in PostgreSQL CREATE STATISTICS command allows a table owner to achieve denial of service against other CREATE STATISTICS users by creating in any schema. A later CREATE STATISTICS for the same name, from a user having the CREATE privilege, would then fail. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.(CVE-2025-12817)

Integer wraparound in multiple PostgreSQL libpq client library functions allows an application input provider or network peer to cause libpq to undersize an allocation and write out-of-bounds by hundreds of megabytes. This results in a segmentation fault for the application using libpq. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.(CVE-2025-12818)

Database specific
{
    "severity": "Medium"
}
References

Affected packages

openEuler:22.03-LTS-SP4 / libpq

Package

Name
libpq
Purl
pkg:rpm/openEuler/libpq&distro=openEuler-22.03-LTS-SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
13.23-1.oe2203sp4

Ecosystem specific

{
    "x86_64": [
        "libpq-13.23-1.oe2203sp4.x86_64.rpm",
        "libpq-debuginfo-13.23-1.oe2203sp4.x86_64.rpm",
        "libpq-debugsource-13.23-1.oe2203sp4.x86_64.rpm",
        "libpq-devel-13.23-1.oe2203sp4.x86_64.rpm"
    ],
    "aarch64": [
        "libpq-13.23-1.oe2203sp4.aarch64.rpm",
        "libpq-debuginfo-13.23-1.oe2203sp4.aarch64.rpm",
        "libpq-debugsource-13.23-1.oe2203sp4.aarch64.rpm",
        "libpq-devel-13.23-1.oe2203sp4.aarch64.rpm"
    ],
    "src": [
        "libpq-13.23-1.oe2203sp4.src.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2025-2728.json"