CVE-2025-12818
13.11.2025, 13:15
Integer wraparound in multiple PostgreSQL libpq client library functions allows an application input provider or network peer to cause libpq to undersize an allocation and write out-of-bounds by hundreds of megabytes. This results in a segmentation fault for the application using libpq. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.Enginsight
Debian Releases
Debian Product | |||||||||
|---|---|---|---|---|---|---|---|---|---|
| postgresql-13 |
| ||||||||
| postgresql-15 |
| ||||||||
| postgresql-17 |
| ||||||||
| postgresql-18 |
|
Ubuntu Releases
Ubuntu Product | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| postgresql-18 |
| ||||||||||
| postgresql-17 |
| ||||||||||
| postgresql-16 |
| ||||||||||
| postgresql-14 |
| ||||||||||
| postgresql-12 |
| ||||||||||
| postgresql-10 |
| ||||||||||
| postgresql-9.5 |
| ||||||||||
| postgresql-9.3 |
|
Vulnerability Media Exposure