cbcvebase.
CVE-2023-5870
published 2023-12-10

CVE-2023-5870: A flaw was found in PostgreSQL involving the pg_cancel_backend role that signals background workers, including the logical replication launcher, autovacuum…

medium4.4CVSS 3.1
AVNACHPRHUINSUCNINAH
A flaw was found in PostgreSQL involving the pg_cancel_backend role that signals background workers, including the logical replication launcher, autovacuum workers, and the autovacuum launcher. Successful exploitation requires a non-core extension with a less-resilient background worker and would affect that specific background worker only. This issue may allow a remote high privileged user to launch a denial of service (DoS) attack.

Affected

48 ranges· showing 25
VendorProductVersion rangeFixed in
debianpostgresql-13< postgresql-13 13.13-0+deb11u1 (bullseye)postgresql-13 13.13-0+deb11u1 (bullseye)
debianpostgresql-15< postgresql-13 13.13-0+deb11u1 (bullseye)postgresql-13 13.13-0+deb11u1 (bullseye)
msrcazl3_postgresql_16.7-1_on_azure_linux_3.0
msrccbl2_postgresql_14.14-1_on_cbl_mariner_2.0
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
postgresqlpostgresql
postgresqlpostgresql>= 11.0 < 11.2211.22
postgresqlpostgresql>= 12.0 < 12.1712.17
postgresqlpostgresql>= 13.0 < 13.1313.13
postgresqlpostgresql>= 14.0 < 14.1014.10
postgresqlpostgresql>= 15.0 < 15.515.5
redhatcodeready_linux_builder_eus
redhatcodeready_linux_builder_eus_for_power_little_endian_eus
redhatcodeready_linux_builder_eus_for_power_little_endian_eus
redhatcodeready_linux_builder_for_arm64_eus
redhatcodeready_linux_builder_for_arm64_eus
redhatcodeready_linux_builder_for_arm64_eus
redhatcodeready_linux_builder_for_ibm_z_systems_eus
redhatcodeready_linux_builder_for_ibm_z_systems_eus
redhatcodeready_linux_builder_for_power_little_endian_eus
redhatcodeready_linux_builder_for_power_little_endian_eus
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux_eus

CVSS provenance

nvdv3.14.4MEDIUMCVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH