{"id":"CVE-2025-12818","year":2025,"sequence":12818,"component":"core server","score":5.9,"cvss_version":"3.0","vector":"AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","first_published":"2025-11-13","source_url":"https://www.postgresql.org/support/security/CVE-2025-12818/","facts":{"affected":{"13":"13","14":"14","15":"15","16":"16","17":"17","18":"18"},"affected_ranges":[{"from":"0","until":"13.23"},{"from":"14","until":"14.20"},{"from":"15","until":"15.15"},{"from":"16","until":"16.11"},{"from":"17","until":"17.7"},{"from":"18","until":"18.1"}],"cna_url":"https://cveawg.mitre.org/api/cve/CVE-2025-12818","component":"core server","cvss_version":"3.0","description_en":"Integer wraparound in multiple PostgreSQL libpq client library functions allows an application input provider or network peer to cause libpq to undersize an allocation and write out-of-bounds by hundreds of megabytes. This results in a segmentation fault for the application using libpq. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.","first_published":"2025-11-13","fixed":{"13":"13.23","14":"14.20","15":"15.15","16":"16.11","17":"17.7","18":"18.1"},"id":"CVE-2025-12818","introduced":{},"published":{"13":"2025-11-13","14":"2025-11-13","15":"2025-11-13","16":"2025-11-13","17":"2025-11-13","18":"2025-11-13"},"score":5.9,"title":"PostgreSQL libpq undersizes allocations, via integer wraparound","url":"https://www.postgresql.org/support/security/CVE-2025-12818/","vector":"AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"},"reviewed_hash":"6a65a7884245936f6adaef8709d290d460e999dfce1ad78734fa7c9a324ed325","source_hash":"965b9e2323feab543f3cbeb74c418c3a5b43cbefc6594d2862ff0d24dcf8e6a2","text":{"locale":"zh-Hans","title":"PostgreSQL libpq 因整数回绕导致分配尺寸过小","description":"PostgreSQL libpq 因整数回绕导致分配尺寸过小","details":null,"format":"markdown","provenance":{"identity":"immutable_cve_code","sources":[{"observed_at":"2026-10-03 12:08:35.169032+08","raw":{"component":"core server","cve":"2025-12818","cvenumber":202512818,"description":"PostgreSQL libpq 因整数回绕导致分配尺寸过小","details":null,"detailslink":"https://access.redhat.com/security/cve/CVE-2025-12818","id":6,"legacyscore":"","newspost_id":null,"public":true,"vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"},"source":"center","source_id":6,"source_table_sha256":"b57ee28b2263464208af0ccf7512b31f0c1ab7140d12dda09a0c87de341f1372"},{"observed_at":"2026-10-03 12:08:55.967155+08","raw":{"component":"core server","cve":"2025-12818","cvenumber":202512818,"description":"PostgreSQL libpq 因整数回绕导致分配尺寸过小","details":null,"detailslink":"https://access.redhat.com/security/cve/CVE-2025-12818","id":6,"legacyscore":"","newspost_id":null,"public":true,"vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"},"source":"pgweb","source_id":6,"source_table_sha256":"b57ee28b2263464208af0ccf7512b31f0c1ab7140d12dda09a0c87de341f1372"}]},"text_hash":"bef3bf95c4a2fdfeab4bf5680bb263dc525ff0f5864e043cdac45174ff417e26"},"locales":["en","zh-Hans"],"fixes":[{"major":"13","fixed_version":"13.23","introduced":null,"published_date":"2025-11-13","facts":{"fixed":"13.23","introduced":null,"published":"2025-11-13"}},{"major":"14","fixed_version":"14.20","introduced":null,"published_date":"2025-11-13","facts":{"fixed":"14.20","introduced":null,"published":"2025-11-13"}},{"major":"15","fixed_version":"15.15","introduced":null,"published_date":"2025-11-13","facts":{"fixed":"15.15","introduced":null,"published":"2025-11-13"}},{"major":"16","fixed_version":"16.11","introduced":null,"published_date":"2025-11-13","facts":{"fixed":"16.11","introduced":null,"published":"2025-11-13"}},{"major":"17","fixed_version":"17.7","introduced":null,"published_date":"2025-11-13","facts":{"fixed":"17.7","introduced":null,"published":"2025-11-13"}},{"major":"18","fixed_version":"18.1","introduced":null,"published_date":"2025-11-13","facts":{"fixed":"18.1","introduced":null,"published":"2025-11-13"}}],"legacy":[{"source":"center","source_id":6,"observed_at":"2026-10-03 12:08:35.169032+08","raw":{"id":6,"cve":"2025-12818","public":true,"vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","details":null,"component":"core server","cvenumber":202512818,"description":"PostgreSQL libpq 因整数回绕导致分配尺寸过小","detailslink":"https://access.redhat.com/security/cve/CVE-2025-12818","legacyscore":"","newspost_id":null},"fixes":[{"source_id":22,"source_version_id":31,"major":"18","fixed_minor":1,"raw":{"id":22,"patch_id":6,"version_id":31,"fixed_minor":1},"version_raw":{"id":31,"tree":18.0,"current":true,"docsgit":"","eoldate":"2030-11-14","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":6,"firstreldate":"2025-09-25"}},{"source_id":23,"source_version_id":30,"major":"17","fixed_minor":7,"raw":{"id":23,"patch_id":6,"version_id":30,"fixed_minor":7},"version_raw":{"id":30,"tree":17.0,"current":false,"docsgit":"","eoldate":"2029-11-08","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":11,"firstreldate":"2024-09-26"}},{"source_id":24,"source_version_id":29,"major":"16","fixed_minor":11,"raw":{"id":24,"patch_id":6,"version_id":29,"fixed_minor":11},"version_raw":{"id":29,"tree":16.0,"current":false,"docsgit":"","eoldate":"2028-11-09","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":15,"firstreldate":"2023-09-14"}},{"source_id":25,"source_version_id":28,"major":"15","fixed_minor":15,"raw":{"id":25,"patch_id":6,"version_id":28,"fixed_minor":15},"version_raw":{"id":28,"tree":15.0,"current":false,"docsgit":"","eoldate":"2027-11-11","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":19,"firstreldate":"2022-10-13"}},{"source_id":26,"source_version_id":27,"major":"14","fixed_minor":20,"raw":{"id":26,"patch_id":6,"version_id":27,"fixed_minor":20},"version_raw":{"id":27,"tree":14.0,"current":false,"docsgit":"","eoldate":"2026-11-12","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":24,"firstreldate":"2021-09-30"}},{"source_id":180,"source_version_id":26,"major":"13","fixed_minor":23,"raw":{"id":180,"patch_id":6,"version_id":26,"fixed_minor":23},"version_raw":{"id":26,"tree":13.0,"current":false,"docsgit":"","eoldate":"2025-11-13","reldate":"2025-11-13","testing":0,"supported":false,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":23,"firstreldate":"2020-09-24"}}]},{"source":"pgweb","source_id":6,"observed_at":"2026-10-03 12:08:55.967155+08","raw":{"id":6,"cve":"2025-12818","public":true,"vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","details":null,"component":"core server","cvenumber":202512818,"description":"PostgreSQL libpq 因整数回绕导致分配尺寸过小","detailslink":"https://access.redhat.com/security/cve/CVE-2025-12818","legacyscore":"","newspost_id":null},"fixes":[{"source_id":22,"source_version_id":31,"major":"18","fixed_minor":1,"raw":{"id":22,"patch_id":6,"version_id":31,"fixed_minor":1},"version_raw":{"id":31,"tree":18.0,"current":true,"docsgit":"","eoldate":"2030-11-14","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":6,"firstreldate":"2025-09-25"}},{"source_id":23,"source_version_id":30,"major":"17","fixed_minor":7,"raw":{"id":23,"patch_id":6,"version_id":30,"fixed_minor":7},"version_raw":{"id":30,"tree":17.0,"current":false,"docsgit":"","eoldate":"2029-11-08","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":11,"firstreldate":"2024-09-26"}},{"source_id":24,"source_version_id":29,"major":"16","fixed_minor":11,"raw":{"id":24,"patch_id":6,"version_id":29,"fixed_minor":11},"version_raw":{"id":29,"tree":16.0,"current":false,"docsgit":"","eoldate":"2028-11-09","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":15,"firstreldate":"2023-09-14"}},{"source_id":25,"source_version_id":28,"major":"15","fixed_minor":15,"raw":{"id":25,"patch_id":6,"version_id":28,"fixed_minor":15},"version_raw":{"id":28,"tree":15.0,"current":false,"docsgit":"","eoldate":"2027-11-11","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":19,"firstreldate":"2022-10-13"}},{"source_id":26,"source_version_id":27,"major":"14","fixed_minor":20,"raw":{"id":26,"patch_id":6,"version_id":27,"fixed_minor":20},"version_raw":{"id":27,"tree":14.0,"current":false,"docsgit":"","eoldate":"2026-11-12","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":24,"firstreldate":"2021-09-30"}},{"source_id":180,"source_version_id":26,"major":"13","fixed_minor":23,"raw":{"id":180,"patch_id":6,"version_id":26,"fixed_minor":23},"version_raw":{"id":26,"tree":13.0,"current":false,"docsgit":"","eoldate":"2025-11-13","reldate":"2025-11-13","testing":0,"supported":false,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":23,"firstreldate":"2020-09-24"}}]}]}
