↑↓ select↵ open⌫ change scopeOpen full search

PG.CENTER connects PostgreSQL documentation, reference, and ecosystem knowledge. Maintained by Pigsty.

CVE-2021-32027

While modifying certain SQL array values, missing bounds checks let authenticated database users write arbitrary bytes to a wide area of server memory. The PostgreSQL project thanks Tom Lane for reporting this problem.

Version Information

Affected branchIntroducedFixed InFix Published
10—10.172021-05-13
11—11.122021-05-13
12—12.72021-05-13
13—13.32021-05-13
9.6—9.6.222021-05-13

CVSS 3.0

Overall Score6.5
Componentcore server
VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

First published: 2021-05-13

Original security advisory · JSON · All advisories