CVE-2025-4207: PostgreSQL GB18030 encoding validation can read one byte past end of allocation for text that fails validation
Buffer over-read in PostgreSQL GB18030 encoding validation allows a database input provider to achieve temporary denial of service on platforms where a 1-byte over-read can elicit process termination. This affects the database server and also libpq. Versions before PostgreSQL 17.5, 16.9, 15.13, 14.18, and 13.21 are affected.
Other sources
PostgreSQL GB18030 encoding validation can read one byte past end of allocation for text that fails validation
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.90.0-4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.18-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.9-1 - Upgrade
Upgrade
PostgreSQLto a version that resolves this vulnerability.Fixed in 17.5 - Upgrade
Upgrade
PostgreSQLto a version that resolves this vulnerability.Fixed in 16.9 - Upgrade
Upgrade
PostgreSQLto a version that resolves this vulnerability.Fixed in 15.13 - Upgrade
Upgrade
PostgreSQLto a version that resolves this vulnerability.Fixed in 14.18 - Upgrade
Upgrade
PostgreSQLto a version that resolves this vulnerability.Fixed in 13.21
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4207?
CVE-2025-4207 has a high severity due to its potential to cause a temporary denial of service.
What is affected by CVE-2025-4207?
CVE-2025-4207 affects PostgreSQL versions before 17.5 and libpq versions before 17.5.
How do I fix CVE-2025-4207?
To fix CVE-2025-4207, upgrade PostgreSQL and libpq to version 17.5 or later.
What type of vulnerability is CVE-2025-4207?
CVE-2025-4207 is a buffer over-read vulnerability.
How can CVE-2025-4207 impact my PostgreSQL database?
CVE-2025-4207 can lead to process termination resulting in temporary denial of service for your PostgreSQL database.