Red Hat Security Advisory: postgresql:12 security update
🔗 CVE IDs covered (4)
📋 Description
CVE-2021-3393 — postgresql: Partition constraint violation errors leak values of denied columns CVE-2021-32027 — postgresql: Buffer overrun from integer overflow in array subscripting calculations CVE-2021-32028 — postgresql: Memory disclosure in INSERT ... ON CONFLICT ... DO UPDATE CVE-2021-32029 — postgresql: Memory disclosure in partitioned-table UPDATE ... RETURNING
🎯 Affected products125
- Red Hat Enterprise Linux AppStream (v. 8)
- pgaudit-0:1.4.0-6.module+el8.4.0+11288+c193d6d7.aarch64 (postgresql:12) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- pgaudit-0:1.4.0-6.module+el8.4.0+11288+c193d6d7.ppc64le (postgresql:12) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- pgaudit-0:1.4.0-6.module+el8.4.0+11288+c193d6d7.s390x (postgresql:12) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- pgaudit-0:1.4.0-6.module+el8.4.0+11288+c193d6d7.src (postgresql:12) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- pgaudit-0:1.4.0-6.module+el8.4.0+11288+c193d6d7.x86_64 (postgresql:12) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- pgaudit-debuginfo-0:1.4.0-6.module+el8.4.0+11288+c193d6d7.aarch64 (postgresql:12) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- pgaudit-debuginfo-0:1.4.0-6.module+el8.4.0+11288+c193d6d7.ppc64le (postgresql:12) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- pgaudit-debuginfo-0:1.4.0-6.module+el8.4.0+11288+c193d6d7.s390x (postgresql:12) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- pgaudit-debuginfo-0:1.4.0-6.module+el8.4.0+11288+c193d6d7.x86_64 (postgresql:12) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- pgaudit-debugsource-0:1.4.0-6.module+el8.4.0+11288+c193d6d7.aarch64 (postgresql:12) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- pgaudit-debugsource-0:1.4.0-6.module+el8.4.0+11288+c193d6d7.ppc64le (postgresql:12) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- pgaudit-debugsource-0:1.4.0-6.module+el8.4.0+11288+c193d6d7.s390x (postgresql:12) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- pgaudit-debugsource-0:1.4.0-6.module+el8.4.0+11288+c193d6d7.x86_64 (postgresql:12) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- postgres-decoderbufs-0:0.10.0-2.module+el8.4.0+11288+c193d6d7.aarch64 (postgresql:12) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- postgres-decoderbufs-0:0.10.0-2.module+el8.4.0+11288+c193d6d7.ppc64le (postgresql:12) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- postgres-decoderbufs-0:0.10.0-2.module+el8.4.0+11288+c193d6d7.s390x (postgresql:12) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- postgres-decoderbufs-0:0.10.0-2.module+el8.4.0+11288+c193d6d7.src (postgresql:12) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- postgres-decoderbufs-0:0.10.0-2.module+el8.4.0+11288+c193d6d7.x86_64 (postgresql:12) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- postgres-decoderbufs-debuginfo-0:0.10.0-2.module+el8.4.0+11288+c193d6d7.aarch64 (postgresql:12) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- postgres-decoderbufs-debuginfo-0:0.10.0-2.module+el8.4.0+11288+c193d6d7.ppc64le (postgresql:12) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- postgres-decoderbufs-debuginfo-0:0.10.0-2.module+el8.4.0+11288+c193d6d7.s390x (postgresql:12) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- postgres-decoderbufs-debuginfo-0:0.10.0-2.module+el8.4.0+11288+c193d6d7.x86_64 (postgresql:12) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- postgres-decoderbufs-debugsource-0:0.10.0-2.module+el8.4.0+11288+c193d6d7.aarch64 (postgresql:12) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- postgres-decoderbufs-debugsource-0:0.10.0-2.module+el8.4.0+11288+c193d6d7.ppc64le (postgresql:12) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- postgres-decoderbufs-debugsource-0:0.10.0-2.module+el8.4.0+11288+c193d6d7.s390x (postgresql:12) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- postgres-decoderbufs-debugsource-0:0.10.0-2.module+el8.4.0+11288+c193d6d7.x86_64 (postgresql:12) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- postgresql-0:12.7-1.module+el8.4.0+11288+c193d6d7.aarch64 (postgresql:12) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- postgresql-0:12.7-1.module+el8.4.0+11288+c193d6d7.ppc64le (postgresql:12) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- postgresql-0:12.7-1.module+el8.4.0+11288+c193d6d7.s390x (postgresql:12) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- +95 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 If the postgresql service is running, it will be automatically restarted after installing this update. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update as soon as possible.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2021:2372
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1924005
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1956876
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1956877
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1956883
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_2372.json