CVE-2025-4207

EUVD-2025-14007
Buffer over-read in PostgreSQL GB18030 encoding validation allows a database input provider to achieve temporary denial of service on platforms where a 1-byte over-read can elicit process termination.  This affects the database server and also libpq.  Versions before PostgreSQL 17.5, 16.9, 15.13, 14.18, and 13.21 are affected.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.9 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
PostgreSQLCNA
5.9 MEDIUM
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 55%
Debian logo
Debian Releases
Debian Product
Codename
postgresql-13
bullseye
vulnerable
bullseye (security)
13.23-0+deb11u1
fixed
postgresql-15
bookworm
15.15-0+deb12u1
fixed
bookworm (security)
15.16-0+deb12u1
fixed
postgresql-17
trixie
17.7-0+deb13u1
fixed
trixie (security)
17.8-0+deb13u1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
postgresql-17
focal
dne
jammy
dne
noble
dne
oracular
dne
plucky
Fixed 17.5-0ubuntu0.25.04.1
released
questing
not-affected
postgresql-16
focal
dne
jammy
dne
noble
Fixed 16.9-0ubuntu0.24.04.1
released
oracular
Fixed 16.9-0ubuntu0.24.10.1
released
plucky
dne
questing
dne
postgresql-14
focal
dne
jammy
Fixed 14.18-0ubuntu0.22.04.1
released
noble
dne
oracular
dne
plucky
dne
questing
dne
postgresql-12
focal
Fixed 12.22-0ubuntu0.20.04.4
released
jammy
dne
noble
dne
oracular
dne
plucky
dne
questing
dne
postgresql-10
bionic
needs-triage
focal
dne
jammy
dne
noble
dne
oracular
dne
plucky
dne
questing
dne
postgresql-9.5
focal
dne
jammy
dne
noble
dne
oracular
dne
plucky
dne
questing
dne
xenial
needs-triage
postgresql-9.3
focal
dne
jammy
dne
noble
dne
oracular
dne
plucky
dne
questing
dne
trusty
deferred