PostgreSQL update addressing vulnerabilities

Correction updates have been released for all supported branches of PostgreSQL: 13.3, 12.7, 11.12, 10.17, and 9.6.22. Updates for the 9.6 branch will continue until November 2021, for 10 until November 2022, for 11 until November 2023, for 12 until November 2024, and for 13 until November 2025. The new releases address three vulnerabilities and fix accumulated bugs.

The vulnerability CVE-2021-32027 can lead to writing data beyond the buffer due to integer overflow when calculating array index values. By manipulating array values in SQL queries, an attacker with access to execute SQL queries can write arbitrary data to any memory area of the process, potentially executing their code with the rights of the database. server Two other vulnerabilities (CVE-2021-32028, CVE-2021-32029) cause memory content leaks when manipulating with the "INSERT … ON CONFLICT … DO UPDATE" and "UPDATE … RETURNING" queries.

Among the unrelated fixes, the following can be highlighted:

  • Fixes incorrect calculations when executing "UPDATE … RETURNING" to update combined segmented tables.
  • Fixes errors in the command "ALTER TABLE … ALTER CONSTRAINT" when there are constraints for foreign keys in combination with the use of segmented tables.
  • The functionality of "COMMIT AND CHAIN" has been restored.
  • For new releases of FreeBSD, the fdatasync mode is set by default in thatwal_sync_method.
  • The vacuum_cleanup_index_scale_factor parameter is disabled by default.
  • Memory leaks occurring during TLS connection initialization have been fixed.
  • Additional checks have been added in pg_upgrade for data types in user tables that are not eligible for upgrade.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster