<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 06:52:28 +0000</lastBuildDate>
    <item>
      <title>ALSA-2023:7785 — Important: postgresql:15 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2023:7785</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: pg_repack, AlmaLinux:9: pgaudit, AlmaLinux:9: postgres-decoderbufs, AlmaLinux:9: postgresql, AlmaLinux:9: postgresql-contrib, AlmaLinux:9: postgresql-docs, AlmaLinux:9: postgresql-plperl, AlmaLinux:9: postgresql-plpython3, AlmaLinux:9: postgresql-pltcl, AlmaLinux:9: postgresql-private-devel and 8 more&lt;/p&gt;
&lt;p&gt;PostgreSQL is an advanced object-relational database management system (DBMS).&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* postgresql: Buffer overrun from integer overflow in array modification (CVE-2023-5869)
* postgresql: Memory disclosure in aggregate function calls (CVE-2023-5868)
* postgresql: extension script @substitutions@ within quoting allow SQL injection (CVE-2023-39417)
* postgresql: Role pg_signal_backend can signal certain superuser processes. (CVE-2023-5870)
* postgresql: MERGE fails to enforce UPDATE or SELECT row security policies (CVE-2023-39418)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: pg_repack, AlmaLinux:9: pgaudit, AlmaLinux:9: postgres-decoderbufs, AlmaLinux:9: postgresql, AlmaLinux:9: postgresql-contrib, AlmaLinux:9: postgresql-docs, AlmaLinux:9: postgresql-plperl, AlmaLinux:9: postgresql-plpython3, AlmaLinux:9: postgresql-pltcl, AlmaLinux:9: postgresql-private-devel and 8 more&lt;/p&gt;
&lt;p&gt;PostgreSQL is an advanced object-relational database management system (DBMS).&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* postgresql: Buffer overrun from integer overflow in array modification (CVE-2023-5869)
* postgresql: Memory disclosure in aggregate function calls (CVE-2023-5868)
* postgresql: extension script @substitutions@ within quoting allow SQL injection (CVE-2023-39417)
* postgresql: Role pg_signal_backend can signal certain superuser processes. (CVE-2023-5870)
* postgresql: MERGE fails to enforce UPDATE or SELECT row security policies (CVE-2023-39418)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2023:7785</guid>
    </item>
    <item>
      <title>bdu:2023-04768</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-04768</link>
      <description>bdu:2023-04768</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-04768</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2023-39418 — CVE-2023-39418 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2023-39418</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2023-39418</guid>
    </item>
    <item>
      <title>BIT-postgresql-2023-39418 — Postgresql: merge fails to enforce update or select row security policies</title>
      <link>https://cve.radiocsirt.org/vuln/bit-postgresql-2023-39418</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: postgresql&lt;/p&gt;
&lt;p&gt;A vulnerability was found in PostgreSQL with the use of the MERGE command, which fails to test new rows against row security policies defined for UPDATE and SELECT. If UPDATE and SELECT policies forbid some rows that INSERT policies do not forbid, a user could store such rows.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: postgresql&lt;/p&gt;
&lt;p&gt;A vulnerability was found in PostgreSQL with the use of the MERGE command, which fails to test new rows against row security policies defined for UPDATE and SELECT. If UPDATE and SELECT policies forbid some rows that INSERT policies do not forbid, a user could store such rows.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-postgresql-2023-39418</guid>
    </item>
    <item>
      <title>certfr-2023-avi-0651 — De multiples vulnérabilités ont été découvertes dans PostgreSQL. Elles
permettent à un attaquant de provoquer une exécu…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0651</link>
      <description>certfr-2023-avi-0651</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0651</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-FW42039 — vulnerability was found in PostgreSQL with the use of the MERGE command, which fails to test new rows against row secur…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-fw42039</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: postgresql&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the postgresql package. A vulnerability was found in PostgreSQL with the use of the MERGE command, which fails to test new rows against row security policies defined for UPDATE and SELECT. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: postgresql&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the postgresql package. A vulnerability was found in PostgreSQL with the use of the MERGE command, which fails to test new rows against row security policies defined for UPDATE and SELECT. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-fw42039</guid>
    </item>
    <item>
      <title>EUVD-2026-261624</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-261624</link>
      <description>EUVD-2026-261624</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-261624</guid>
    </item>
    <item>
      <title>fkie_cve-2023-39418</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-39418</link>
      <description>&lt;p&gt;A vulnerability was found in PostgreSQL with the use of the MERGE command, which fails to test new rows against row security policies defined for UPDATE and SELECT. If UPDATE and SELECT policies forbid some rows that INSERT policies do not forbid, a user could store such rows.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability was found in PostgreSQL with the use of the MERGE command, which fails to test new rows against row security policies defined for UPDATE and SELECT. If UPDATE and SELECT policies forbid some rows that INSERT policies do not forbid, a user could store such rows.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-39418</guid>
    </item>
    <item>
      <title>GHSA-chgx-7cw3-hr55</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-chgx-7cw3-hr55</link>
      <description>&lt;p&gt;A vulnerability was found in PostgreSQL with the use of the MERGE command, which fails to test new rows against row security policies defined for UPDATE and SELECT. If UPDATE and SELECT policies forbid some rows that INSERT policies do not forbid, a user could store such rows.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability was found in PostgreSQL with the use of the MERGE command, which fails to test new rows against row security policies defined for UPDATE and SELECT. If UPDATE and SELECT policies forbid some rows that INSERT policies do not forbid, a user could store such rows.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-chgx-7cw3-hr55</guid>
    </item>
    <item>
      <title>gsd-2023-39418</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-39418</link>
      <description>gsd-2023-39418</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-39418</guid>
    </item>
    <item>
      <title>ICSA-24-046-15 — Siemens SINEC NMS</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-24-046-15</link>
      <description>&lt;p&gt;A read buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification and requires either a CA to have signed the malicious certificate or for the application to continue certificate verification despite failure to construct a path to a trusted issuer. The read buffer overrun might result in a crash which could lead to a denial of service attack. In theory it could also result in the disclosure of private memory contents (such as private keys, or sensitive plaintext) although we are not aware of any working exploit leading to memory contents disclosure as of the time of release of this advisory. In a TLS client, this can be triggered by connecting to a malicious server. In a TLS server, this can be triggered if the server requests client authentication and a malicious client connects. A timing based side channel exists in the OpenSSL RSA Decryption implementation which could be sufficient to recover a plaintext across a network in a Bleichenbacher style attack. To achieve a successful decryption an attacker would have to be able to send a very large number of trial messages for decryption. The vulnerability affects all RSA padding modes: PKCS#1 v1.5, RSA-OEAP and RSASVE. For example, in a TLS connection, RSA is commonly used by a client to send an encrypted pre-master secret to the server. An attacker that had observed a genuine connection between a client and a…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A read buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification and requires either a CA to have signed the malicious certificate or for the application to continue certificate verification despite failure to construct a path to a trusted issuer. The read buffer overrun might result in a crash which could lead to a denial of service attack. In theory it could also result in the disclosure of private memory contents (such as private keys, or sensitive plaintext) although we are not aware of any working exploit leading to memory contents disclosure as of the time of release of this advisory. In a TLS client, this can be triggered by connecting to a malicious server. In a TLS server, this can be triggered if the server requests client authentication and a malicious client connects. A timing based side channel exists in the OpenSSL RSA Decryption implementation which could be sufficient to recover a plaintext across a network in a Bleichenbacher style attack. To achieve a successful decryption an attacker would have to be able to send a very large number of trial messages for decryption. The vulnerability affects all RSA padding modes: PKCS#1 v1.5, RSA-OEAP and RSASVE. For example, in a TLS connection, RSA is commonly used by a client to send an encrypted pre-master secret to the server. An attacker that had observed a genuine connection between a client and a…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-24-046-15</guid>
    </item>
    <item>
      <title>OESA-2023-1567 — libpq security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2023-1567</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP1: libpq&lt;/p&gt;
&lt;p&gt;PostgreSQL is a powerful, open source object-relational database system that uses and extends the SQL language combined with many features that safely store and scale the most complicated data workloads. This package provides the essential shared library for any PostgreSQL client program or interface.&#13;
&#13;
&#13;
&#13;
Security Fix(es):&#13;
&#13;
** DISPUTED ** An issue was discovered in PostgreSQL 12.2 allows attackers to cause a denial of service via repeatedly sending SIGHUP signals. NOTE: this is disputed by the vendor because untrusted users cannot send SIGHUP signals; they can only be sent by a PostgreSQL superuser, a user with pg_reload_conf access, or a user with sufficient privileges at the OS level (the postgres account or the root account).(CVE-2020-21469)&#13;
&#13;
schema_element defeats protective search_path changes; It was found that certain database calls in PostgreSQL could permit an authed attacker with elevated database-level privileges to execute arbitrary code.(CVE-2023-2454)&#13;
&#13;
Row security policies disregard user ID changes after inlining; PostgreSQL could permit incorrect policies to be applied in certain cases where role-specific policies are used and a given query is planned under one role and then executed under other roles. This scenario can happen under security definer functions or when a common user and query is planned initially and then re-used across multiple SET ROLEs. Applying an incorrect policy may permit a user to complete otherwise-forbidden reads and modifica…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP1: libpq&lt;/p&gt;
&lt;p&gt;PostgreSQL is a powerful, open source object-relational database system that uses and extends the SQL language combined with many features that safely store and scale the most complicated data workloads. This package provides the essential shared library for any PostgreSQL client program or interface.&#13;
&#13;
&#13;
&#13;
Security Fix(es):&#13;
&#13;
** DISPUTED ** An issue was discovered in PostgreSQL 12.2 allows attackers to cause a denial of service via repeatedly sending SIGHUP signals. NOTE: this is disputed by the vendor because untrusted users cannot send SIGHUP signals; they can only be sent by a PostgreSQL superuser, a user with pg_reload_conf access, or a user with sufficient privileges at the OS level (the postgres account or the root account).(CVE-2020-21469)&#13;
&#13;
schema_element defeats protective search_path changes; It was found that certain database calls in PostgreSQL could permit an authed attacker with elevated database-level privileges to execute arbitrary code.(CVE-2023-2454)&#13;
&#13;
Row security policies disregard user ID changes after inlining; PostgreSQL could permit incorrect policies to be applied in certain cases where role-specific policies are used and a given query is planned under one role and then executed under other roles. This scenario can happen under security definer functions or when a common user and query is planned initially and then re-used across multiple SET ROLEs. Applying an incorrect policy may permit a user to complete otherwise-forbidden reads and modifica…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2023-1567</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:13134-1 — libecpg6-15.4-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13134-1</link>
      <description>&lt;p&gt;libecpg6-15.4-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libecpg6-15.4-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:13134-1</guid>
    </item>
    <item>
      <title>RHSA-2023:7883 — Red Hat Security Advisory: postgresql:15 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:7883</link>
      <description>&lt;p&gt;postgresql: Memory disclosure in aggregate function calls postgresql: Buffer overrun from integer overflow in array modification postgresql: Role pg_signal_backend can signal certain superuser processes. postgresql: extension script @substitutions@ within quoting allow SQL injection postgresql: MERGE fails to enforce UPDATE or SELECT row security policies&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;postgresql: Memory disclosure in aggregate function calls postgresql: Buffer overrun from integer overflow in array modification postgresql: Role pg_signal_backend can signal certain superuser processes. postgresql: extension script @substitutions@ within quoting allow SQL injection postgresql: MERGE fails to enforce UPDATE or SELECT row security policies&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:7883</guid>
    </item>
    <item>
      <title>SUSE-SU-2023:3342-1 — Security update for postgresql15</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2023:3342-1</link>
      <description>&lt;p&gt;Security update for postgresql15&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for postgresql15&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2023:3342-1</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-2038 — PostgreSQL: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2038</link>
      <description>&lt;p&gt;Ein entfernter authentifizierter Angreifer kann mehrere Schwachstellen in PostgreSQL ausnutzen, um beliebigen Code auszuführen oder Sicherheitsmaßnahmen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter authentifizierter Angreifer kann mehrere Schwachstellen in PostgreSQL ausnutzen, um beliebigen Code auszuführen oder Sicherheitsmaßnahmen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2038</guid>
    </item>
  </channel>
</rss>
