UbuntuUpdates.org

Package "libpq5"

Name: libpq5

Description:

PostgreSQL C client library

Latest version: 17.7-0ubuntu0.25.10.1
Release: questing (25.10)
Level: updates
Repository: main
Head package: postgresql-17
Homepage: http://www.postgresql.org/

Links


Download "libpq5"


Other versions of "libpq5" in Questing

Repository Area Version
base main 17.6-1build1
security main 17.7-0ubuntu0.25.10.1
PPA: Postgresql 9.4.1-1.pgdg10.4+1
PPA: Postgresql 18.1-1.pgdg22.04+2
PPA: Postgresql 9.6.3-1.pgdg12.4+1
PPA: Postgresql 11.3-1.pgdg14.04+1
PPA: Postgresql 17.5-1.pgdg20.04+1
PPA: Postgresql 13.3-1.pgdg16.04+1
PPA: Postgresql 15.3-1.pgdg18.04+1

Changelog

Version: 17.7-0ubuntu0.25.10.1 2025-12-03 22:25:58 UTC

  postgresql-17 (17.7-0ubuntu0.25.10.1) questing-security; urgency=medium

  * New upstream version (LP: #2127667).

    + A dump/restore is not required for those running 17.X.

    + However, if you are upgrading from a version earlier than 17.6, see
      those release notes as well please.

    + Check for CREATE privileges on the schema in CREATE STATISTICS (Jelte
      Fennema-Nio)

      This omission allowed table owners to create statistics in any schema,
      potentially leading to unexpected naming conflicts. (CVE-2025-12817)

    + Avoid integer overflow in allocation-size calculations within libpq
      (Jacob Champion)

      Several places in libpq were not sufficiently careful about computing
      the required size of a memory allocation. Sufficiently large inputs
      could cause integer overflow, resulting in an undersized buffer, which
      would then lead to writing past the end of the buffer. (CVE-2025-12818)

    + Details about these and many further changes can be found at:
      https://www.postgresql.org/docs/17/release-17-7.html.

  * d/postgresql-17.NEWS: Create NEWS file.

 -- Athos Ribeiro <email address hidden> Wed, 19 Nov 2025 10:23:51 -0300

2127667 New PostgreSQL upstream microreleases 14.20, 16.11, and 17.7
CVE-2025-12817 Missing authorization in PostgreSQL CREATE STATISTICS command allows a table owner to achieve denial of service against other CREATE STATISTICS users
CVE-2025-12818 Integer wraparound in multiple PostgreSQL libpq client library functions allows an application input provider or network peer to cause libpq to under



About   -   Send Feedback to @ubuntu_updates