Opened 5 months ago

Closed 4 months ago

#23302 closed enhancement (fixed)

postgresql-18.4

Reported by: Douglas R. Reno Owned by: SecurityAdvisory
Priority: high Milestone: 13.1
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New minor version

Change History (6)

comment:1 by Douglas R. Reno, 5 months ago

Priority: normal → high

comment:2 by Bruce Dubbs, 4 months ago

Owner: changed from blfs-book to Bruce Dubbs
Status: new → assigned

comment:3 by Bruce Dubbs, 4 months ago

Release notes are at ​https://www.postgresql.org/docs/current/release-18-4.html

See especially:

  • Prevent unbounded recursion while processing startup packets
    • A malicious client could crash the connected backend by alternating rejected SSL and GSS encryption requests indefinitely.
    • The PostgreSQL Project thanks Calif.io (in collaboration with Claude and Anthropic Research) for reporting this problem. (CVE-2026-6479)

comment:4 by Bruce Dubbs, 4 months ago

Owner: changed from Bruce Dubbs to SecurityAdvisory
Status: assigned → new

Fixed at commit ac8307dd03. Leaving open for SA.

comment:6 by Douglas R. Reno, 4 months ago

Resolution: → fixed
Status: new → closed

SA-13.0-108 issued.

Recommended that users update immediately as superusers on a server can overwrite stack memory in client systems!

Note: See TracTickets for help on using tickets.