REDHAT-BUG-2477448: High severity PostgreSQL postgresql vulnerability
Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds. This may execute arbitrary code as the operating system user running the database. In applications that pass gigabyte-scale user inputs to the relevant database functions, the application input provider may achieve a segmentation fault. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
PostgreSQLto a version that resolves this vulnerability.Fixed in 14.23 - Upgrade
Upgrade
PostgreSQLto a version that resolves this vulnerability.Fixed in 15.18 - Upgrade
Upgrade
PostgreSQLto a version that resolves this vulnerability.Fixed in 16.14 - Upgrade
Upgrade
PostgreSQLto a version that resolves this vulnerability.Fixed in 17.10 - Upgrade
Upgrade
PostgreSQLto a version that resolves this vulnerability.Fixed in 18.4
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2477448?
The severity of REDHAT-BUG-2477448 is high with a score of 7.
How do I fix REDHAT-BUG-2477448?
To fix REDHAT-BUG-2477448, you should update PostgreSQL to the latest patched version provided by Red Hat.
What vulnerability does REDHAT-BUG-2477448 describe?
REDHAT-BUG-2477448 describes an integer wraparound vulnerability in PostgreSQL server features that may allow arbitrary code execution.
Who is affected by REDHAT-BUG-2477448?
Unprivileged database users of PostgreSQL may be affected by REDHAT-BUG-2477448.
What is the potential impact of REDHAT-BUG-2477448?
The potential impact of REDHAT-BUG-2477448 includes the execution of arbitrary code as the operating system user running the PostgreSQL database.