USN-7315-1: PostgreSQL vulnerability
USN-7315-1: PostgreSQL vulnerability
3 March 2025
PostgreSQL could be made to execute arbitrary code if it received specially crafted input.
Releases
Ubuntu 24.10 Ubuntu 24.04 LTS Ubuntu 22.04 LTS Ubuntu 20.04 LTS
Packages
postgresql-12 - Object-relational SQL database
postgresql-14 - Object-relational SQL database
postgresql-16 - Object-relational SQL database
Details
Stephen Fewer discovered that PostgreSQL incorrectly handled quoting syntax
in certain scenarios. A remote attacker could possibly use this issue to
perform SQL injection attacks.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 24.10
- postgresql-16 - 16.8-0ubuntu0.24.10.1
- postgresql-client-16 - 16.8-0ubuntu0.24.10.1
Ubuntu 24.04 - postgresql-16 - 16.8-0ubuntu0.24.04.1
- postgresql-client-16 - 16.8-0ubuntu0.24.04.1
Ubuntu 22.04 - postgresql-14 - 14.17-0ubuntu0.22.04.1
- postgresql-client-14 - 14.17-0ubuntu0.22.04.1
Ubuntu 20.04 - postgresql-12 - 12.22-0ubuntu0.20.04.2
- postgresql-client-12 - 12.22-0ubuntu0.20.04.2
This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart PostgreSQL to
make all the necessary changes.