RHSA-2025:16099HighCVSS 8.8
Red Hat Security Advisory: postgresql security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2025-8714 — postgresql: PostgreSQL code execution in restore operation
🎯 Affected products77
- Red Hat Enterprise Linux Server (v. 7 ELS)
- Red Hat Enterprise Linux Server Optional (v. 7 ELS)
- postgresql-0:9.2.24-9.el7_9.4.i686 as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
- postgresql-0:9.2.24-9.el7_9.4.ppc as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
- postgresql-0:9.2.24-9.el7_9.4.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
- postgresql-0:9.2.24-9.el7_9.4.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
- postgresql-0:9.2.24-9.el7_9.4.s390 as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
- postgresql-0:9.2.24-9.el7_9.4.s390x as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
- postgresql-0:9.2.24-9.el7_9.4.src as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
- postgresql-0:9.2.24-9.el7_9.4.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
- postgresql-contrib-0:9.2.24-9.el7_9.4.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
- postgresql-contrib-0:9.2.24-9.el7_9.4.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
- postgresql-contrib-0:9.2.24-9.el7_9.4.s390x as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
- postgresql-contrib-0:9.2.24-9.el7_9.4.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
- postgresql-debuginfo-0:9.2.24-9.el7_9.4.i686 as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
- postgresql-debuginfo-0:9.2.24-9.el7_9.4.i686 as a component of Red Hat Enterprise Linux Server Optional (v. 7 ELS)
- postgresql-debuginfo-0:9.2.24-9.el7_9.4.ppc as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
- postgresql-debuginfo-0:9.2.24-9.el7_9.4.ppc as a component of Red Hat Enterprise Linux Server Optional (v. 7 ELS)
- postgresql-debuginfo-0:9.2.24-9.el7_9.4.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
- postgresql-debuginfo-0:9.2.24-9.el7_9.4.ppc64 as a component of Red Hat Enterprise Linux Server Optional (v. 7 ELS)
- postgresql-debuginfo-0:9.2.24-9.el7_9.4.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
- postgresql-debuginfo-0:9.2.24-9.el7_9.4.ppc64le as a component of Red Hat Enterprise Linux Server Optional (v. 7 ELS)
- postgresql-debuginfo-0:9.2.24-9.el7_9.4.s390 as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
- postgresql-debuginfo-0:9.2.24-9.el7_9.4.s390 as a component of Red Hat Enterprise Linux Server Optional (v. 7 ELS)
- postgresql-debuginfo-0:9.2.24-9.el7_9.4.s390x as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
- postgresql-debuginfo-0:9.2.24-9.el7_9.4.s390x as a component of Red Hat Enterprise Linux Server Optional (v. 7 ELS)
- postgresql-debuginfo-0:9.2.24-9.el7_9.4.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
- postgresql-debuginfo-0:9.2.24-9.el7_9.4.x86_64 as a component of Red Hat Enterprise Linux Server Optional (v. 7 ELS)
- postgresql-devel-0:9.2.24-9.el7_9.4.i686 as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
- postgresql-devel-0:9.2.24-9.el7_9.4.ppc as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
- +47 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Do not restore a dump file from a server or user you do not explicitly trust.