CVE-2025-4207
Public on 2025-05-08
Modified on 2025-05-12
Description
Buffer over-read in PostgreSQL GB18030 encoding validation allows a database input provider to achieve temporary denial of service on platforms where a 1-byte over-read can elicit process termination. This affects the database server and also libpq. Versions before PostgreSQL 17.5, 16.9, 15.13, 14.18, and 13.21 are affected.
Severity
CVSS v3 Base Score
See breakdown
Affected Packages
Platform | Package | Release Date | Advisory | Status |
---|---|---|---|---|
Amazon Linux 2 - Core | postgresql | Pending Fix | ||
Amazon Linux 2 - Postgresql14 Extra | postgresql | Pending Fix | ||
Amazon Linux 2 - Postgresql13 Extra | postgresql | 2025-05-21 | ALAS2POSTGRESQL13-2025-011 | Fixed |
Amazon Linux 2023 | postgresql15 | 2025-05-21 | ALAS2023-2025-974 | Fixed |
Amazon Linux 2023 | postgresql16 | 2025-05-21 | ALAS2023-2025-973 | Fixed |
Amazon Linux 2023 | postgresql17 | 2025-05-21 | ALAS2023-2025-975 | Fixed |
Amazon Linux 1 | postgresql8 | No Fix Planned | ||
Amazon Linux 1 | postgresql92 | No Fix Planned | ||
Amazon Linux 1 | postgresql93 | No Fix Planned | ||
Amazon Linux 1 | postgresql94 | No Fix Planned | ||
Amazon Linux 1 | postgresql95 | No Fix Planned | ||
Amazon Linux 1 | postgresql96 | No Fix Planned |
CVSS Scores
Score Type | Score | Vector | |
---|---|---|---|
Amazon Linux | CVSSv3 | 5.9 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H |
NVD | CVSSv3 | 5.9 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H |