CNNVD-202511-1623 Information

CNNVD ID

CNNVD-202511-1623

CVE-2025-12818

  • CNNVD Published: 2025-11-13

Description (Chinese)

PostgreSQL是PostgreSQL组织的一套自由的对象关系型数据库管理系统。该系统支持大部分SQL标准并且提供了许多其他特性,例如外键、触发器、视图等。 PostgreSQL存在安全漏洞,该漏洞源于多个libpq客户端库函数存在整数环绕错误,可能导致越界写入。以下版本受到影响:18.1之前版本、17.7之前版本、16.11之前版本、15.15之前版本、14.20之前版本和13.23之前版本。

Description (English)

PostgreSQL is a free client relationship database management system organized by PostgreSQL. The system supports most SQL standards and provides many other features, such as external keys, triggers, views, etc. There is a security loophole in PostgreSQL, which stems from integer looping errors in multiple libpq client libraries that may lead to cross-border writing. The following versions were affected: pre- 18.1, pre-17.7, pre-16.11, pre-15, pre-14.20 and pre-13.23.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

PostgreSQL

Published

2025-11-13

Last Modified

2026-02-24

References

https://www.postgresql.org/support/security/CVE-2025-12818/ https://vigilance.fr/vulnerability/PostgreSQL-integer-overflow-via-libpq-48769 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-12818

Patch

https://www.postgresql.org/support/security/CVE-2025-12818/

Share on: