PT-2021-3134 · Unknown+10 · Postgresql+9
Andres Freund
·
Published
2021-05-12
·
Updated
2026-04-03
·
CVE-2021-32028
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
postgresql (affected versions not specified)
Description
A flaw was found in postgresql. Using an
INSERT ... ON CONFLICT ... DO UPDATE command on a purpose-crafted table, an authenticated database user could read arbitrary bytes of server memory. The highest threat from this issue is to data confidentiality. This issue is related to memory disclosure errors in the implementation of the INSERT ... ON CONFLICT ... DO UPDATE command.Recommendations
At the moment, there is no information about a newer version that contains a fix for this issue.
Fix
Memory Leak
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Postgresql
Red Hat
Rocky Linux
Suse
Ubuntu