Massive PostgreSQL Update: 11 Vulnerabilities Patched as Version 14 Hits End-of-Life Warning
ID: f376cddb-cd29-5bf2-9a62-56b0cbbe5768
STIX ID: report--f376cddb-cd29-5bf2-9a62-56b0cbbe5768
Feed Name: securityonline.info
PostgreSQL published synchronized security updates (18.4, 17.10, 16.14, 15.18, 14.23) that address 11 vulnerabilities and 60+ bugs across supported branches; four issues score 8.8 CVSS and notable flaws include a refint stack overflow permitting OS-level code execution, libpq large-object client memory corruption enabling psql/pg_dump exploitation, integer wraparounds causing server crashes, and symlink validation bugs in backup utilities allowing host file overwrite. Administrators are urged to install the minor releases and finalize migrations off PostgreSQL 14 ahead of its November 12, 2026 EOL.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
