Bugzilla – Bug 1189748
VUL-0: CVE-2021-3677: postgresql: Memory disclosure in certain queries
Last modified: 2022-11-29 13:47:54 UTC
A purpose-crafted query can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can complete this attack at will. The attack does not require the ability to create objects. If server settings include max_worker_processes=0, the known versions of this attack are infeasible. However, undiscovered variants of the attack may be independent of that setting.
Hi Max, could you please provide your feedback about which commit needs to be backported to patch this vulnerability? I trimmed down the list to two possible candidates, 1acab12 [0] or 9c6fa34 [1]. [0] https://github.com/postgres/postgres/commit/1acab12 [1] https://github.com/postgres/postgres/commit/9c6fa34
(In reply to Gianluca Gabrielli from comment #1) > Hi Max, could you please provide your feedback about which commit needs to > be backported to patch this vulnerability? I trimmed down the list to two > possible candidates, 1acab12 [0] or 9c6fa34 [1]. > > [0] https://github.com/postgres/postgres/commit/1acab12 > [1] https://github.com/postgres/postgres/commit/9c6fa34 Please ignore my previous comment, I just remembered that we do version bump for Postgresql :)
This is an autogenerated message for OBS integration: This bug (1189748) was mentioned in https://build.opensuse.org/request/show/917540 Factory / postgresql11 https://build.opensuse.org/request/show/917541 Factory / postgresql12 https://build.opensuse.org/request/show/917542 Factory / postgresql13
# maintenance_jira_update_notice SUSE-SU-2021:3119-1: An update that solves one vulnerability and has three fixes is now available. Category: security (moderate) Bug References: 1179945,1185952,1187751,1189748 CVE References: CVE-2021-3677 JIRA References: Sources used: SUSE Linux Enterprise Software Development Kit 12-SP5 (src): postgresql12-12.8-3.18.2 SUSE Linux Enterprise Server 12-SP5 (src): postgresql12-12.8-3.18.2 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
# maintenance_jira_update_notice SUSE-SU-2021:3120-1: An update that solves one vulnerability and has three fixes is now available. Category: security (moderate) Bug References: 1179945,1185952,1187751,1189748 CVE References: CVE-2021-3677 JIRA References: Sources used: SUSE Linux Enterprise Software Development Kit 12-SP5 (src): postgresql13-13.4-3.12.2 SUSE Linux Enterprise Server 12-SP5 (src): postgresql13-13.4-3.12.2 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2021:3256-1: An update that solves one vulnerability and has three fixes is now available. Category: security (moderate) Bug References: 1179945,1185952,1187751,1189748 CVE References: CVE-2021-3677 JIRA References: Sources used: SUSE Linux Enterprise Module for Server Applications 15-SP2 (src): postgresql12-12.8-8.23.2 SUSE Linux Enterprise Module for Legacy Software 15-SP3 (src): postgresql12-12.8-8.23.2 SUSE Linux Enterprise Module for Basesystem 15-SP2 (src): postgresql12-12.8-8.23.2 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
openSUSE-SU-2021:3256-1: An update that solves one vulnerability and has three fixes is now available. Category: security (moderate) Bug References: 1179945,1185952,1187751,1189748 CVE References: CVE-2021-3677 JIRA References: Sources used: openSUSE Leap 15.3 (src): postgresql12-12.8-8.23.2
SUSE-SU-2021:3255-1: An update that solves one vulnerability and has three fixes is now available. Category: security (moderate) Bug References: 1179945,1185952,1187751,1189748 CVE References: CVE-2021-3677 JIRA References: Sources used: SUSE Linux Enterprise Module for Server Applications 15-SP3 (src): postgresql13-13.4-5.16.1, postgresql13-13.4-5.16.2 SUSE Linux Enterprise Module for Server Applications 15-SP2 (src): postgresql13-13.4-5.16.1, postgresql13-13.4-5.16.2 SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP3 (src): postgresql13-13.4-5.16.2 SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP2 (src): postgresql13-13.4-5.16.2 SUSE Linux Enterprise Module for Basesystem 15-SP3 (src): postgresql13-13.4-5.16.1, postgresql13-13.4-5.16.2 SUSE Linux Enterprise Module for Basesystem 15-SP2 (src): postgresql13-13.4-5.16.1, postgresql13-13.4-5.16.2 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
openSUSE-SU-2021:3255-1: An update that solves one vulnerability and has three fixes is now available. Category: security (moderate) Bug References: 1179945,1185952,1187751,1189748 CVE References: CVE-2021-3677 JIRA References: Sources used: openSUSE Leap 15.3 (src): postgresql13-13.4-5.16.1, postgresql13-13.4-5.16.2
SUSE-SU-2022:2958-1: An update that solves 8 vulnerabilities and has 6 fixes is now available. Category: security (important) Bug References: 1179945,1183168,1185924,1185925,1185926,1185952,1187751,1189748,1190740,1192516,1195680,1198166,1199475,1202368 CVE References: CVE-2021-23214,CVE-2021-23222,CVE-2021-32027,CVE-2021-32028,CVE-2021-32029,CVE-2021-3677,CVE-2022-1552,CVE-2022-2625 JIRA References: Sources used: SUSE Linux Enterprise Server for SAP 15-SP1 (src): postgresql12-12.12-150100.3.33.1 SUSE Linux Enterprise Server 15-SP1-LTSS (src): postgresql12-12.12-150100.3.33.1 SUSE Linux Enterprise Server 15-SP1-BCL (src): postgresql12-12.12-150100.3.33.1 SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (src): postgresql12-12.12-150100.3.33.1 SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (src): postgresql12-12.12-150100.3.33.1 SUSE Enterprise Storage 6 (src): postgresql12-12.12-150100.3.33.1 SUSE CaaS Platform 4.0 (src): postgresql12-12.12-150100.3.33.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.