USN-6802-1: PostgreSQL vulnerability

Published May 30, 2024
·
Updated

Lukas Fittl discovered that PostgreSQL incorrectly performed authorization in the built-in pgstatsext and pgstatsextexprs views. An unprivileged database user can use this issue to read most common values and other statistics from CREATE STATISTICS commands of other users. NOTE: This update will only fix fresh PostgreSQL installations. Current PostgreSQL installations will remain vulnerable to this issue until manual steps are performed. Please see the instructions in the changelog located at /usr/share/doc/postgresql-/changelog.Debian.gz after the updated packages have been installed, or in the PostgreSQL release notes located here: https://www.postgresql.org/docs/16/release-16-3.html https://www.postgresql.org/docs/15/release-15-7.html https://www.postgresql.org/docs/14/release-14-12.html

Affected Software

12 affected componentsFixes available
All of the following
ubuntu/postgresql-16<16.3-0ubuntu0.24.04.1
16.3-0ubuntu0.24.04.1
Ubuntu Ubuntu=24.04
All of the following
ubuntu/postgresql-client-16<16.3-0ubuntu0.24.04.1
16.3-0ubuntu0.24.04.1
Ubuntu Ubuntu=24.04
All of the following
ubuntu/postgresql-15<15.7-0ubuntu0.23.10.1
15.7-0ubuntu0.23.10.1
Ubuntu Ubuntu=23.10
All of the following
ubuntu/postgresql-client-15<15.7-0ubuntu0.23.10.1
15.7-0ubuntu0.23.10.1
Ubuntu Ubuntu=23.10
All of the following
ubuntu/postgresql-14<14.12-0ubuntu0.22.04.1
14.12-0ubuntu0.22.04.1
Ubuntu Ubuntu=22.04
All of the following
ubuntu/postgresql-client-14<14.12-0ubuntu0.22.04.1
14.12-0ubuntu0.22.04.1
Ubuntu Ubuntu=22.04

Event History

May 30, 2024
Advisory Published
via Ubuntu·12:00 AM

Child vulnerabilities

Contains the following vulnerabilities.

Frequently Asked Questions

1

What is the severity of USN-6802-1?

The severity of USN-6802-1 is considered high due to the potential for unauthorized data access.

2

How do I fix USN-6802-1?

To fix USN-6802-1, upgrade to the specified remedial package versions: postgresql-16 to 16.3-0ubuntu0.24.04.1, postgresql-client-16 to 16.3-0ubuntu0.24.04.1, postgresql-15 to 15.7-0ubuntu0.23.10.1, or their respective client versions.

3

Who is affected by USN-6802-1?

USN-6802-1 affects unprivileged database users in PostgreSQL versions prior to the remedial updates.

4

What issue does USN-6802-1 address?

USN-6802-1 addresses an authorization vulnerability in PostgreSQL that allows unprivileged users to read statistics from CREATE STATISTICS commands of other users.

5

When was USN-6802-1 reported?

USN-6802-1 was reported in relation to CVE-2024-4317, highlighting a critical flaw in PostgreSQL's authorization mechanism.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203