Integer Wraparound Vulnerability in PostgreSQL libpq Client Library
CVE-2025-12818
5.9MEDIUM
What is CVE-2025-12818?
An integer wraparound flaw in multiple functions of the PostgreSQL libpq client library may allow a malicious application input provider or network peer to exploit memory allocation issues. This vulnerability can lead to an undersized allocation, permitting out-of-bounds writes that can disrupt application stability, potentially resulting in segmentation faults. Users are encouraged to update to the latest versions to mitigate these risks.
Affected Version(s)
PostgreSQL 18 < 18.1
PostgreSQL 17 < 17.7
PostgreSQL 16 < 16.11
References
CVSS V3.1
Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
The PostgreSQL project thanks Aleksey Solovev (Positive Technologies) for reporting this problem.