CVE-2025-4207
published 2025-05-08CVE-2025-4207: Buffer over-read in PostgreSQL GB18030 encoding validation allows a database input provider to achieve temporary denial of service on platforms where a 1-byte…
PriorityP430medium5.9CVSS 3.1
AVNACHPRNUINSUCNINAH
EPSS
0.64%
46.6th percentile
Buffer over-read in PostgreSQL GB18030 encoding validation allows a database input provider to achieve temporary denial of service on platforms where a 1-byte over-read can elicit process termination. This affects the database server and also libpq. Versions before PostgreSQL 17.5, 16.9, 15.13, 14.18, and 13.21 are affected.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | postgresql-13 | < postgresql-13 13.21-0+deb11u1 (bullseye) | postgresql-13 13.21-0+deb11u1 (bullseye) |
| debian | postgresql-15 | < postgresql-13 13.21-0+deb11u1 (bullseye) | postgresql-13 13.21-0+deb11u1 (bullseye) |
| debian | postgresql-17 | < postgresql-13 13.21-0+deb11u1 (bullseye) | postgresql-13 13.21-0+deb11u1 (bullseye) |
| msrc | azl3_postgresql_16.7-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_postgresql_16.9-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_rust_1.75.0-22_on_azure_linux_3.0 | — | — |
| msrc | azl3_rust_1.90.0-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_rust_1.90.0-3_on_azure_linux_3.0 | — | — |
| msrc | azl3_rust_1.90.0-4_on_azure_linux_3.0 | — | — |
| msrc | cbl2_kernel_5.15.131.1-2_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_postgresql_14.16-1_on_cbl_mariner_2.0 | — | — |
| msrc | cm2_postgresql_14.18-1_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
osv5.9MEDIUM
vendor_msrc7.8HIGH
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6x46-2273-xjjf: Buffer over-read in PostgreSQL GB18030 encoding validation allows a database input provider to achieve temporary denial of service on platforms where
ghsa_unreviewed·2025-05-08
CVE-2025-4207 [MEDIUM] CWE-126 GHSA-6x46-2273-xjjf: Buffer over-read in PostgreSQL GB18030 encoding validation allows a database input provider to achieve temporary denial of service on platforms where
Buffer over-read in PostgreSQL GB18030 encoding validation allows a database input provider to achieve temporary denial of service on platforms where a 1-byte over-read can elicit process termination. This affects the database server and also libpq. Versions before PostgreSQL 17.5, 16.9, 15.13, 14.18, and 13.21 are affected.
OSV
CVE-2025-4207: Buffer over-read in PostgreSQL GB18030 encoding validation allows a database input provider to achieve temporary denial of service on platforms where
osv·2025-05-08·CVSS 5.9
CVE-2025-4207 [MEDIUM] CVE-2025-4207: Buffer over-read in PostgreSQL GB18030 encoding validation allows a database input provider to achieve temporary denial of service on platforms where
Buffer over-read in PostgreSQL GB18030 encoding validation allows a database input provider to achieve temporary denial of service on platforms where a 1-byte over-read can elicit process termination. This affects the database server and also libpq. Versions before PostgreSQL 17.5, 16.9, 15.13, 14.18, and 13.21 are affected.
Ubuntu
PostgreSQL vulnerability
vendor_ubuntu·2025-05-21
CVE-2025-4207 PostgreSQL vulnerability
Title: PostgreSQL vulnerability
Summary: PostgreSQL could be made to crash if it received specially crafted network
traffic.
USN-7520-1 fixed a vulnerability in PostgreSQL. This update provides the
corresponding updates for Ubuntu 25.04.
Original advisory details:
It was discovered that PostgreSQL incorrectly handled the GB18030
encoding. An attacker could possibly use this issue to cause PostgreSQL to
crash, resulting in a denial of service.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart PostgreSQL to
make all the necessary changes.
Ubuntu
PostgreSQL vulnerability
vendor_ubuntu·2025-05-20
CVE-2025-4207 PostgreSQL vulnerability
Title: PostgreSQL vulnerability
Summary: PostgreSQL could be made to crash if it received specially crafted network
traffic.
It was discovered that PostgreSQL incorrectly handled the GB18030 encoding.
An attacker could possibly use this issue to cause PostgreSQL to crash,
resulting in a denial of service.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart PostgreSQL to
make all the necessary changes.
Microsoft
PostgreSQL GB18030 encoding validation can read one byte past end of allocation for text that fails validation
vendor_msrc·2025-05-13·CVSS 5.9
CVE-2025-4207 [MEDIUM] CWE-126 PostgreSQL GB18030 encoding validation can read one byte past end of allocation for text that fails validation
PostgreSQL GB18030 encoding validation can read one byte past end of allocation for text that fails validation
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
PostgreSQL: PostgreSQL
Customer Action Required:
Red Hat
postgresql: PostgreSQL GB18030 encoding validation can read one byte past end of allocation for text that fails validation
vendor_redhat·2025-05-08·CVSS 5.9
CVE-2025-4207 [MEDIUM] CWE-126 postgresql: PostgreSQL GB18030 encoding validation can read one byte past end of allocation for text that fails validation
postgresql: PostgreSQL GB18030 encoding validation can read one byte past end of allocation for text that fails validation
Buffer over-read in PostgreSQL GB18030 encoding validation allows a database input provider to achieve temporary denial of service on platforms where a 1-byte over-read can elicit process termination. This affects the database server and also libpq. Versions before PostgreSQL 17.5, 16.9, 15.13, 14.18, and 13.21 are affected.
A flaw was found in PostgreSQL. A buffer over-read in PostgreSQL GB18030 encoding validation allows a database input provider to achieve temporary denial of service on platforms where a 1-byte over-read can lead to process termination.
Package: libpq (Red Hat Enterprise Linux 10) - Fix deferred
Package: postgresql (Red Hat Enterprise Linux 6) -
Debian
CVE-2025-4207: postgresql-13 - Buffer over-read in PostgreSQL GB18030 encoding validation allows a database inp...
vendor_debian·2025·CVSS 5.9
CVE-2025-4207 [MEDIUM] CVE-2025-4207: postgresql-13 - Buffer over-read in PostgreSQL GB18030 encoding validation allows a database inp...
Buffer over-read in PostgreSQL GB18030 encoding validation allows a database input provider to achieve temporary denial of service on platforms where a 1-byte over-read can elicit process termination. This affects the database server and also libpq. Versions before PostgreSQL 17.5, 16.9, 15.13, 14.18, and 13.21 are affected.
Scope: local
bullseye: resolved (fixed in 13.21-0+deb11u1)
Microsoft
Use-after-free in Linux kernel's net/sched: cls_fw component
vendor_msrc·2023-09-12·CVSS 7.8
CVE-2023-4207 [HIGH] CWE-416 Use-after-free in Linux kernel's net/sched: cls_fw component
Use-after-free in Linux kernel's net/sched: cls_fw component
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
Google: Google
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https:
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-4207 postgresql17: PostgreSQL GB18030 encoding validation can read one byte past end of allocation for text that fails validation [fedora-42]
bugzilla·2025-05-09·CVSS 5.9
CVE-2025-4207 [MEDIUM] CVE-2025-4207 postgresql17: PostgreSQL GB18030 encoding validation can read one byte past end of allocation for text that fails validation [fedora-42]
CVE-2025-4207 postgresql17: PostgreSQL GB18030 encoding validation can read one byte past end of allocation for text that fails validation [fedora-42]
More information about this security flaw is available in the following bug:
https://bugzilla.redhat.com/show_bug.cgi?id=2365111
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will
Bugzilla
CVE-2025-4207 mingw-postgresql: PostgreSQL GB18030 encoding validation can read one byte past end of allocation for text that fails validation [fedora-42]
bugzilla·2025-05-09·CVSS 5.9
CVE-2025-4207 [MEDIUM] CVE-2025-4207 mingw-postgresql: PostgreSQL GB18030 encoding validation can read one byte past end of allocation for text that fails validation [fedora-42]
CVE-2025-4207 mingw-postgresql: PostgreSQL GB18030 encoding validation can read one byte past end of allocation for text that fails validation [fedora-42]
More information about this security flaw is available in the following bug:
https://bugzilla.redhat.com/show_bug.cgi?id=2365111
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug w
Bugzilla
CVE-2025-4207 postgresql16: PostgreSQL GB18030 encoding validation can read one byte past end of allocation for text that fails validation [fedora-42]
bugzilla·2025-05-09·CVSS 5.9
CVE-2025-4207 [MEDIUM] CVE-2025-4207 postgresql16: PostgreSQL GB18030 encoding validation can read one byte past end of allocation for text that fails validation [fedora-42]
CVE-2025-4207 postgresql16: PostgreSQL GB18030 encoding validation can read one byte past end of allocation for text that fails validation [fedora-42]
More information about this security flaw is available in the following bug:
https://bugzilla.redhat.com/show_bug.cgi?id=2365111
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will
Bugzilla
CVE-2025-4207 libpq: PostgreSQL GB18030 encoding validation can read one byte past end of allocation for text that fails validation [fedora-42]
bugzilla·2025-05-09·CVSS 5.9
CVE-2025-4207 [MEDIUM] CVE-2025-4207 libpq: PostgreSQL GB18030 encoding validation can read one byte past end of allocation for text that fails validation [fedora-42]
CVE-2025-4207 libpq: PostgreSQL GB18030 encoding validation can read one byte past end of allocation for text that fails validation [fedora-42]
More information about this security flaw is available in the following bug:
https://bugzilla.redhat.com/show_bug.cgi?id=2365111
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be clos
2025-05-08
Published