CVE-2025-8715

high
Published 2025-08-28 Β· Modified 2025-09-03
CVSS v3
β€”
CVSS v4 NEW
β€”
not yet in upstream
VIR risk
8.0

Description

RHSA-2025:15115: postgresql:12 security update (Important)

Predictions

Exploit likelihood
20%
Patch ETA
β€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata β€” Red Hat Inc. Β· View original β†— Β· Open-Errata-API

Description postgresql: PostgreSQL executes arbitrary code in restore operation Red Hat statement To exploit this flaw, a malicious PostgreSQL user needs to inject arbitrary code or the SQL injection payload in a database object name. The malicious code will only be executed on the client machine when a user restore the crafted dump file. Due to these reasons, this vulnerability has been rated…

Description

postgresql: PostgreSQL executes arbitrary code in restore operation

Red Hat statement

To exploit this flaw, a malicious PostgreSQL user needs to inject arbitrary code or the SQL injection payload in a database object name. The malicious code will only be executed on the client machine when a user restore the crafted dump file. Due to these reasons, this vulnerability has been rated with an Important severity.

CVSS v3: 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Enterprise Linux 10postgresql16-0:16.10-1.el10_0RHSA-2025:148262025-08-28T00:00:00Z
Red Hat Enterprise Linux 8postgresql:16-8100020250818110346.489197e6RHSA-2025:148992025-08-28T00:00:00Z
Red Hat Enterprise Linux 8postgresql:13-8100020250818110147.489197e6RHSA-2025:150212025-09-02T00:00:00Z
Red Hat Enterprise Linux 8postgresql:15-8100020250818110305.489197e6RHSA-2025:150222025-09-02T00:00:00Z
Red Hat Enterprise Linux 8postgresql:12-8100020250829093521.489197e6RHSA-2025:151152025-09-03T00:00:00Z
Red Hat Enterprise Linux 8.2 Advanced Update Supportpostgresql:12-8020020250826135918.4cda2c84RHSA-2025:153612025-09-04T00:00:00Z
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Supportpostgresql:12-8040020250820054803.522a0ee4RHSA-2025:150342025-09-02T00:00:00Z
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Supportpostgresql:13-8040020250818170654.522a0ee4RHSA-2025:150572025-09-02T00:00:00Z
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Supportpostgresql:12-8060020250820072728.ad008a3aRHSA-2025:150062025-09-02T00:00:00Z
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Supportpostgresql:13-8060020250825094024.ad008a3aRHSA-2025:153592025-09-04T00:00:00Z
Red Hat Enterprise Linux 8.6 Telecommunications Update Servicepostgresql:12-8060020250820072728.ad008a3aRHSA-2025:150062025-09-02T00:00:00Z
Red Hat Enterprise Linux 8.6 Telecommunications Update Servicepostgresql:13-8060020250825094024.ad008a3aRHSA-2025:153592025-09-04T00:00:00Z
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutionspostgresql:12-8060020250820072728.ad008a3aRHSA-2025:150062025-09-02T00:00:00Z
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutionspostgresql:13-8060020250825094024.ad008a3aRHSA-2025:153592025-09-04T00:00:00Z
Red Hat Enterprise Linux 8.8 Telecommunications Update Servicepostgresql:12-8080020250819150429.63b34585RHSA-2025:150122025-09-02T00:00:00Z
Red Hat Enterprise Linux 8.8 Telecommunications Update Servicepostgresql:13-8080020250819150623.63b34585RHSA-2025:150132025-09-02T00:00:00Z
Red Hat Enterprise Linux 8.8 Telecommunications Update Servicepostgresql:15-8080020250815150643.63b34585RHSA-2025:150312025-09-02T00:00:00Z
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutionspostgresql:12-8080020250819150429.63b34585RHSA-2025:150122025-09-02T00:00:00Z
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutionspostgresql:13-8080020250819150623.63b34585RHSA-2025:150132025-09-02T00:00:00Z
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutionspostgresql:15-8080020250815150643.63b34585RHSA-2025:150312025-09-02T00:00:00Z
Red Hat Enterprise Linux 9postgresql:16-9060020250817200213.rhel9RHSA-2025:148272025-08-28T00:00:00Z
Red Hat Enterprise Linux 9postgresql:15-9060020250817180313.rhel9RHSA-2025:148622025-08-28T00:00:00Z
Red Hat Enterprise Linux 9postgresql-0:13.22-1.el9_6RHSA-2025:148782025-08-28T00:00:00Z
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutionspostgresql-0:13.22-1.el9_0RHSA-2025:148702025-08-28T00:00:00Z
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutionspostgresql-0:13.22-1.el9_2RHSA-2025:148692025-08-28T00:00:00Z
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutionspostgresql:15-9020020250815141744.rhel9RHSA-2025:150622025-09-02T00:00:00Z
Red Hat Enterprise Linux 9.4 Extended Update Supportpostgresql:15-9040020250818140154.rhel9RHSA-2025:150142025-09-02T00:00:00Z
Red Hat Enterprise Linux 9.4 Extended Update Supportpostgresql:16-9040020250818135852.rhel9RHSA-2025:150152025-09-02T00:00:00Z
Red Hat Enterprise Linux 9.4 Extended Update Supportpostgresql-0:13.22-1.el9_4RHSA-2025:151142025-09-03T00:00:00Z

Package state

ProductPackageState
Red Hat Enterprise Linux 6postgresqlOut of support scope
Red Hat Enterprise Linux 7postgresqlNot affected

Apply commands

bash fix
Apply RHSA-2025:14826 for Red Hat Enterprise Linux 10
yum update -y postgresql16
# or:
dnf upgrade -y postgresql16

Affected

VendorProductVersion
redhatRed Hat Enterprise Linux 7Not affected

OS impact

OSVersionStatusFixed in
redhat rhel9fixed
rockylinux rocky8fixed
suse slesaffected
rockylinux rocky9fixed
debian debianbookwormfixed15.14-0+deb12u1
debian debiantrixiefixed17.6-0+deb13u1
debian debianbullseyefixed13.22-0+deb11u1
almalinux almalinux9fixedpgaudit-16.0-1.module_el9.4.0+66+eb9878bc.aarch64.rpm
redhat rhel8fixed

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.