CVE-2025-12817
13.11.2025, 13:15
Missing authorization in PostgreSQL CREATE STATISTICS command allows a table owner to achieve denial of service against other CREATE STATISTICS users by creating in any schema. A later CREATE STATISTICS for the same name, from a user having the CREATE privilege, would then fail. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.Enginsight
Debian Releases
Debian Product | |||||||||
|---|---|---|---|---|---|---|---|---|---|
| postgresql-13 |
| ||||||||
| postgresql-15 |
| ||||||||
| postgresql-17 |
| ||||||||
| postgresql-18 |
|
Ubuntu Releases
Ubuntu Product | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| postgresql-18 |
| ||||||||||
| postgresql-17 |
| ||||||||||
| postgresql-16 |
| ||||||||||
| postgresql-14 |
| ||||||||||
| postgresql-12 |
| ||||||||||
| postgresql-10 |
| ||||||||||
| postgresql-9.5 |
| ||||||||||
| postgresql-9.3 |
|
Common Weakness Enumeration
Vulnerability Media Exposure