SUSE-SU-2022:2958-1
Dashboard / Vulnerabilities / SUSE-SU-2022:2958-1
SUSE-SU-2022:2958-1
Summary: Security update for postgresql12
Details: This update for postgresql12 fixes the following issues: - Upgrade to 12.12: - CVE-2022-2625: Fixed an issue where extension scripts would replace objects not belonging to that extension (bsc#1202368). - Upgrade to 12.11: - CVE-2022-1552: Confined additional operations within 'security restricted operation' sandboxes (bsc#1199475). - Upgrade to 12.10 (bsc#1195680) - Add constraints file with 12GB of memory for s390x as a workaround (boo#1190740) - Upgrade to version 12.9 (bsc#1192516): - CVE-2021-23214: Made the server reject extraneous data after an SSL or GSS encryption handshake - CVE-2021-23222: Made libpq reject extraneous data after an SSL or GSS encryption handshake - Upgrade to version 12.8: - CVE-2021-3677: Fixed memory disclosure in certain queries (bsc#1189748). - Upgrade to version 12.7: - CVE-2021-32027: Fixed integer overflows in array subscripting calculations (bsc#1185924). - CVE-2021-32028: Fixed mishandling of junk columns in INSERT ... ON CONFLICT ... UPDATE target lists (bsc#1185925). - CVE-2021-32029: Fixed possibly-incorrect computation of UPDATE ... RETURNING 'pg_psql_temporary_savepoint' does not exist (bsc#1185926). - Fixed build with llvm12 on s390x (bsc#1185952). - Re-enabled icu for PostgreSQL 10 (bsc#1179945). - Made the dependency of postgresqlXX-server-devel on llvm and clang optional (bsc#1187751). - llvm12 breaks PostgreSQL 11 and 12 on s390x. Use llvm11 as a workaround (bsc#1185952). - Don't use %_stop_on_removal, because it was meant to be private and got removed from openSUSE. %_restart_on_update is also private, but still supported and needed for now (bsc#1183168).
References: https://www.suse.com/support/update/announcement/2022/suse-su-20222958-1/, https://bugzilla.suse.com/1179945, https://bugzilla.suse.com/1183168, https://bugzilla.suse.com/1185924, https://bugzilla.suse.com/1185925, https://bugzilla.suse.com/1185926, https://bugzilla.suse.com/1185952, https://bugzilla.suse.com/1187751, https://bugzilla.suse.com/1189748, https://bugzilla.suse.com/1190740, https://bugzilla.suse.com/1192516, https://bugzilla.suse.com/1195680, https://bugzilla.suse.com/1198166, https://bugzilla.suse.com/1199475, https://bugzilla.suse.com/1202368, https://www.suse.com/security/cve/CVE-2021-23214, https://www.suse.com/security/cve/CVE-2021-23222, https://www.suse.com/security/cve/CVE-2021-32027, https://www.suse.com/security/cve/CVE-2021-32028, https://www.suse.com/security/cve/CVE-2021-32029, https://www.suse.com/security/cve/CVE-2021-3677, https://www.suse.com/security/cve/CVE-2022-1552, https://www.suse.com/security/cve/CVE-2022-2625
Affected packages
Package
Name: postgresql12
Purl: pkg:rpm/suse/postgresql12&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-ESPOS
Affected ranges
Type: ECOSYSTEM
Events:
