Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2023:7772 - Security Advisory
Issued:
2023-12-13
Updated:
2023-12-13

RHSA-2023:7772 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: rh-postgresql13-postgresql security update

Type/Severity

Security Advisory: Important

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for rh-postgresql13-postgresql is now available for Red Hat Software Collections.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

PostgreSQL is an advanced object-relational database management system (DBMS).

Security Fix(es):

  • postgresql: schema_element defeats protective search_path changes (CVE-2023-2454)
  • postgresql: Buffer overrun from integer overflow in array modification (CVE-2023-5869)
  • postgresql: row security policies disregard user ID changes after inlining. (CVE-2023-2455)
  • postgresql: Memory disclosure in aggregate function calls (CVE-2023-5868)
  • postgresql: extension script @substitutions@ within quoting allow SQL injection (CVE-2023-39417)
  • postgresql: Client memory disclosure when connecting with Kerberos to modified server (CVE-2022-41862)
  • postgresql: Role pg_signal_backend can signal certain superuser processes. (CVE-2023-5870)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

If the postgresql service is running, it will be automatically restarted after installing this update.

Affected Products

  • Red Hat Software Collections (for RHEL Server) 1 for RHEL 7 x86_64
  • Red Hat Software Collections (for RHEL Server for System Z) 1 for RHEL 7 s390x
  • Red Hat Software Collections (for RHEL Server for IBM Power LE) 1 for RHEL 7 ppc64le
  • Red Hat Software Collections (for RHEL Workstation) 1 for RHEL 7 x86_64

Fixes

  • BZ - 2165722 - CVE-2022-41862 postgresql: Client memory disclosure when connecting with Kerberos to modified server
  • BZ - 2207568 - CVE-2023-2454 postgresql: schema_element defeats protective search_path changes
  • BZ - 2207569 - CVE-2023-2455 postgresql: row security policies disregard user ID changes after inlining.
  • BZ - 2228111 - CVE-2023-39417 postgresql: extension script @substitutions@ within quoting allow SQL injection
  • BZ - 2247168 - CVE-2023-5868 postgresql: Memory disclosure in aggregate function calls
  • BZ - 2247169 - CVE-2023-5869 postgresql: Buffer overrun from integer overflow in array modification
  • BZ - 2247170 - CVE-2023-5870 postgresql: Role pg_signal_backend can signal certain superuser processes.

CVEs

  • CVE-2022-41862
  • CVE-2023-2454
  • CVE-2023-2455
  • CVE-2023-5868
  • CVE-2023-5869
  • CVE-2023-5870
  • CVE-2023-39417

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Software Collections (for RHEL Server) 1 for RHEL 7

SRPM
rh-postgresql13-postgresql-13.13-1.el7.src.rpm SHA-256: 4a93f7c98319cba930801a4930bcc3126cca90e48d3d62266e421022f9ffc928
x86_64
rh-postgresql13-postgresql-13.13-1.el7.x86_64.rpm SHA-256: 7a15de30ee410fff83ed9f17521483396b9a49d19a918f6cf4cc6937c116ae1f
rh-postgresql13-postgresql-contrib-13.13-1.el7.x86_64.rpm SHA-256: 950ab7bdd1f8d1f56786079ff6f1ab1e5286b8160d20c14acfa43592ec184ad3
rh-postgresql13-postgresql-contrib-syspaths-13.13-1.el7.x86_64.rpm SHA-256: 12cc99762cf081a28bb11d1cf5f1b2504f9604bf06ba6e270523ce2dd04d9dbc
rh-postgresql13-postgresql-debuginfo-13.13-1.el7.x86_64.rpm SHA-256: bc853da405b073e4418fc82d003b7bdee0c2540fd186ce65787866e4afa81b1e
rh-postgresql13-postgresql-devel-13.13-1.el7.x86_64.rpm SHA-256: 98eff2c7c17e88fab577854a31de106876fafa72d75fc3d9c5a31d0451709048
rh-postgresql13-postgresql-docs-13.13-1.el7.x86_64.rpm SHA-256: 26e8c4b03919053c4de784deded98d5fe28f46e2b07665c21373ead7c78e1bf2
rh-postgresql13-postgresql-libs-13.13-1.el7.x86_64.rpm SHA-256: 7ee7b5b12a55857480676b740d9e6974b4e658e2877c776b161dcb57b065892c
rh-postgresql13-postgresql-plperl-13.13-1.el7.x86_64.rpm SHA-256: 895157270bd001f441c180bb0a7a01db8532ca5846c2b5c1027aca966c23963b
rh-postgresql13-postgresql-plpython-13.13-1.el7.x86_64.rpm SHA-256: b85045e64617131ae1379774a5245cd92ffbd72b64f5d5397d18143356a7805e
rh-postgresql13-postgresql-plpython3-13.13-1.el7.x86_64.rpm SHA-256: 79909894687d57b8d327d6bf02ed54ffb55a56d3607e2808126e369ae2bc3c66
rh-postgresql13-postgresql-pltcl-13.13-1.el7.x86_64.rpm SHA-256: 226f0926b0f09e6b1bb4d34b3ea0f7c9873b1651484cba326d95f1bbd8631243
rh-postgresql13-postgresql-server-13.13-1.el7.x86_64.rpm SHA-256: fcc78da55556fefcf170135eeee8f41aaf8f7a5379ef53c8c0311ef1f0bfb287
rh-postgresql13-postgresql-server-syspaths-13.13-1.el7.x86_64.rpm SHA-256: 3d671470c86dd8d70f83aafdc7937774eee378c8348b58881fca0650a0cbf0b9
rh-postgresql13-postgresql-static-13.13-1.el7.x86_64.rpm SHA-256: a8bd191c143cafdfef4e291fedafe98777bf5d8685429be3a73f26cd440e0767
rh-postgresql13-postgresql-syspaths-13.13-1.el7.x86_64.rpm SHA-256: 69af370dce38bba456390999a2da3df0a672f00d97006ffdf3d325ac267db068
rh-postgresql13-postgresql-test-13.13-1.el7.x86_64.rpm SHA-256: b6cf883bf9f59f91ca111bd49e6c5c237d341270371969ac45e32aa7422ee522

Red Hat Software Collections (for RHEL Server for System Z) 1 for RHEL 7

SRPM
rh-postgresql13-postgresql-13.13-1.el7.src.rpm SHA-256: 4a93f7c98319cba930801a4930bcc3126cca90e48d3d62266e421022f9ffc928
s390x
rh-postgresql13-postgresql-13.13-1.el7.s390x.rpm SHA-256: c450da0f2a42ac08a831b9c54a3db393b9b66f33970b42d08036885c46e2f03a
rh-postgresql13-postgresql-contrib-13.13-1.el7.s390x.rpm SHA-256: 14ed0f38016fdaae6d184f5c9ee1eb15955928572eff23a2a54751824f185041
rh-postgresql13-postgresql-contrib-syspaths-13.13-1.el7.s390x.rpm SHA-256: 4b51bf0f764689fec16aecb87050fe87c6bfa0f573df2db5a21e373c461fba9a
rh-postgresql13-postgresql-debuginfo-13.13-1.el7.s390x.rpm SHA-256: 58b9b52e0f7663368bfc023033afafa10b2dda0de3a49a5cd90945f41130ed96
rh-postgresql13-postgresql-devel-13.13-1.el7.s390x.rpm SHA-256: e1de59dcf02798b32857c52ba6a64addfcbd06bd6750f3946fb73672b8fea998
rh-postgresql13-postgresql-docs-13.13-1.el7.s390x.rpm SHA-256: d84a211ceae534b0748b96e2ed21578aa1653f0ff71b7d679cce6daa773ee65c
rh-postgresql13-postgresql-libs-13.13-1.el7.s390x.rpm SHA-256: ed9a02c62dea59881191bbff61dd2020a7fc35cde6eb7377a17b603db4ef6c8f
rh-postgresql13-postgresql-plperl-13.13-1.el7.s390x.rpm SHA-256: 7b2a450484519a2ad3a3672e2bb7f35e6c7ef2c2145a3dce139ea138fb82c293
rh-postgresql13-postgresql-plpython-13.13-1.el7.s390x.rpm SHA-256: 5f8a043b4770bb6e42d1e8a5f859630a400d3c5ea151a3ac66937e61a9f0498e
rh-postgresql13-postgresql-plpython3-13.13-1.el7.s390x.rpm SHA-256: 93002f83c9c7d3adda07ff6398248794560ffa11293c824524c2be2276361c51
rh-postgresql13-postgresql-pltcl-13.13-1.el7.s390x.rpm SHA-256: ba4584e3c71510097dba98f143a35685b9f6bf94d449c60e0ca8c67122207193
rh-postgresql13-postgresql-server-13.13-1.el7.s390x.rpm SHA-256: 40749ffa4ee98192dc51e5fe4b0c10e1a14db73e540fd0bbc115cd83db5b0d40
rh-postgresql13-postgresql-server-syspaths-13.13-1.el7.s390x.rpm SHA-256: aa3f02e763b778f86c5c15d732541a21597289a91a90d6c456e4db808de129c9
rh-postgresql13-postgresql-static-13.13-1.el7.s390x.rpm SHA-256: 2d1ebd42cc4df63f7ced529009342f5afc9f79ddb8a935e075b4ac7a75fb4d24
rh-postgresql13-postgresql-syspaths-13.13-1.el7.s390x.rpm SHA-256: 803e40854b0a18adc90096d043a4e3ca0c9057ba096d46a12d0b75d87c7b7ded
rh-postgresql13-postgresql-test-13.13-1.el7.s390x.rpm SHA-256: 53baf00661ab122551c14d89f602ff1930c28e3e5a6ba660673ced5f81e2070c

Red Hat Software Collections (for RHEL Server for IBM Power LE) 1 for RHEL 7

SRPM
rh-postgresql13-postgresql-13.13-1.el7.src.rpm SHA-256: 4a93f7c98319cba930801a4930bcc3126cca90e48d3d62266e421022f9ffc928
ppc64le
rh-postgresql13-postgresql-13.13-1.el7.ppc64le.rpm SHA-256: 79f1ace7020e63863b8eae0c9eab2054bb92e98991f67a00fec8f0af8aae86ff
rh-postgresql13-postgresql-contrib-13.13-1.el7.ppc64le.rpm SHA-256: 38d9dc9403275dc78165ae6f4bfbc708f3ff99cf086a4cac825f16e7d4615c29
rh-postgresql13-postgresql-contrib-syspaths-13.13-1.el7.ppc64le.rpm SHA-256: af560c97573079e462e7f39b59daa837c5b153fcee2f5df987054638b641aa46
rh-postgresql13-postgresql-debuginfo-13.13-1.el7.ppc64le.rpm SHA-256: f2b4f7f3d5eb973dfdafec44285a1c8aaf43a26640c883522cf3161dd36cf079
rh-postgresql13-postgresql-devel-13.13-1.el7.ppc64le.rpm SHA-256: 717cd00d1e2275ef9dd6be2f80da0fe304185cda46cf99e5fa6d2b3d551be4c1
rh-postgresql13-postgresql-docs-13.13-1.el7.ppc64le.rpm SHA-256: b76b2a331a171dd83c673f2d021e333a9daafc31bb858b806aada53756eb8eac
rh-postgresql13-postgresql-libs-13.13-1.el7.ppc64le.rpm SHA-256: 5a00d9f363f12d11e109e26aea96b964ece4b70e513da9bdf5296b98dd6e5af9
rh-postgresql13-postgresql-plperl-13.13-1.el7.ppc64le.rpm SHA-256: d009cf43ad3f40c01d696e24d7ba75ce343f3b9f9354c7e3255922fb019d11f0
rh-postgresql13-postgresql-plpython-13.13-1.el7.ppc64le.rpm SHA-256: 32624cbed12b1541eee85b7ccf02e06bad47e03c6bfebc7783a5c83b0d3091ef
rh-postgresql13-postgresql-plpython3-13.13-1.el7.ppc64le.rpm SHA-256: d06a0ca8a963296abec4216c9f261d124b4bd6f48586bec2414b195e6e3a43e8
rh-postgresql13-postgresql-pltcl-13.13-1.el7.ppc64le.rpm SHA-256: da3ef38fe314085937c88bcbde22ae85fe527d797402e1c30af1acea07571a21
rh-postgresql13-postgresql-server-13.13-1.el7.ppc64le.rpm SHA-256: eb74765f40795f51ed93fde35e821a3644da4587cc6bb223bb91e205275c885f
rh-postgresql13-postgresql-server-syspaths-13.13-1.el7.ppc64le.rpm SHA-256: 7949dd68c18a9a2d69e2d2bcd7418915976833a2de9728f95a706ba82d6fd155
rh-postgresql13-postgresql-static-13.13-1.el7.ppc64le.rpm SHA-256: 246a592ac3f8101c01f10b49ef04e8f85d13a252bc94326a19549b70948b9cce
rh-postgresql13-postgresql-syspaths-13.13-1.el7.ppc64le.rpm SHA-256: 47a2ca9164bcec9246e85a50ca8d54681750539684871551e1e30a4f507b4132
rh-postgresql13-postgresql-test-13.13-1.el7.ppc64le.rpm SHA-256: 13bdb39ea92fb5a2e691389e1a2b779eba0b3b8aa42fabe6a14c739602cb1263

Red Hat Software Collections (for RHEL Workstation) 1 for RHEL 7

SRPM
rh-postgresql13-postgresql-13.13-1.el7.src.rpm SHA-256: 4a93f7c98319cba930801a4930bcc3126cca90e48d3d62266e421022f9ffc928
x86_64
rh-postgresql13-postgresql-13.13-1.el7.x86_64.rpm SHA-256: 7a15de30ee410fff83ed9f17521483396b9a49d19a918f6cf4cc6937c116ae1f
rh-postgresql13-postgresql-contrib-13.13-1.el7.x86_64.rpm SHA-256: 950ab7bdd1f8d1f56786079ff6f1ab1e5286b8160d20c14acfa43592ec184ad3
rh-postgresql13-postgresql-contrib-syspaths-13.13-1.el7.x86_64.rpm SHA-256: 12cc99762cf081a28bb11d1cf5f1b2504f9604bf06ba6e270523ce2dd04d9dbc
rh-postgresql13-postgresql-debuginfo-13.13-1.el7.x86_64.rpm SHA-256: bc853da405b073e4418fc82d003b7bdee0c2540fd186ce65787866e4afa81b1e
rh-postgresql13-postgresql-devel-13.13-1.el7.x86_64.rpm SHA-256: 98eff2c7c17e88fab577854a31de106876fafa72d75fc3d9c5a31d0451709048
rh-postgresql13-postgresql-docs-13.13-1.el7.x86_64.rpm SHA-256: 26e8c4b03919053c4de784deded98d5fe28f46e2b07665c21373ead7c78e1bf2
rh-postgresql13-postgresql-libs-13.13-1.el7.x86_64.rpm SHA-256: 7ee7b5b12a55857480676b740d9e6974b4e658e2877c776b161dcb57b065892c
rh-postgresql13-postgresql-plperl-13.13-1.el7.x86_64.rpm SHA-256: 895157270bd001f441c180bb0a7a01db8532ca5846c2b5c1027aca966c23963b
rh-postgresql13-postgresql-plpython-13.13-1.el7.x86_64.rpm SHA-256: b85045e64617131ae1379774a5245cd92ffbd72b64f5d5397d18143356a7805e
rh-postgresql13-postgresql-plpython3-13.13-1.el7.x86_64.rpm SHA-256: 79909894687d57b8d327d6bf02ed54ffb55a56d3607e2808126e369ae2bc3c66
rh-postgresql13-postgresql-pltcl-13.13-1.el7.x86_64.rpm SHA-256: 226f0926b0f09e6b1bb4d34b3ea0f7c9873b1651484cba326d95f1bbd8631243
rh-postgresql13-postgresql-server-13.13-1.el7.x86_64.rpm SHA-256: fcc78da55556fefcf170135eeee8f41aaf8f7a5379ef53c8c0311ef1f0bfb287
rh-postgresql13-postgresql-server-syspaths-13.13-1.el7.x86_64.rpm SHA-256: 3d671470c86dd8d70f83aafdc7937774eee378c8348b58881fca0650a0cbf0b9
rh-postgresql13-postgresql-static-13.13-1.el7.x86_64.rpm SHA-256: a8bd191c143cafdfef4e291fedafe98777bf5d8685429be3a73f26cd440e0767
rh-postgresql13-postgresql-syspaths-13.13-1.el7.x86_64.rpm SHA-256: 69af370dce38bba456390999a2da3df0a672f00d97006ffdf3d325ac267db068
rh-postgresql13-postgresql-test-13.13-1.el7.x86_64.rpm SHA-256: b6cf883bf9f59f91ca111bd49e6c5c237d341270371969ac45e32aa7422ee522

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility