CVE-2025-4207
Public on 2025-05-08
Modified on 2025-05-12
Description
Buffer over-read in PostgreSQL GB18030 encoding validation allows a database input provider to achieve temporary denial of service on platforms where a 1-byte over-read can elicit process termination. This affects the database server and also libpq. Versions before PostgreSQL 17.5, 16.9, 15.13, 14.18, and 13.21 are affected.
Severity
CVSS v3 Base Score
See breakdown
Affected Packages
Platform | Package | Release Date | Advisory | Status |
---|---|---|---|---|
HAQM Linux 2 - Core | postgresql | Pending Fix | ||
HAQM Linux 2 - Postgresql14 Extra | postgresql | Pending Fix | ||
HAQM Linux 2 - Postgresql13 Extra | postgresql | 2025-05-21 | ALAS2POSTGRESQL13-2025-011 | Fixed |
HAQM Linux 2023 | postgresql15 | 2025-05-21 | ALAS2023-2025-974 | Fixed |
HAQM Linux 2023 | postgresql16 | 2025-05-21 | ALAS2023-2025-973 | Fixed |
HAQM Linux 2023 | postgresql17 | 2025-05-21 | ALAS2023-2025-975 | Fixed |
HAQM Linux 1 | postgresql8 | No Fix Planned | ||
HAQM Linux 1 | postgresql92 | No Fix Planned | ||
HAQM Linux 1 | postgresql93 | No Fix Planned | ||
HAQM Linux 1 | postgresql94 | No Fix Planned | ||
HAQM Linux 1 | postgresql95 | No Fix Planned | ||
HAQM Linux 1 | postgresql96 | No Fix Planned |
CVSS Scores
Score Type | Score | Vector | |
---|---|---|---|
HAQM Linux | CVSSv3 | 5.9 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H |
NVD | CVSSv3 | 5.9 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H |