Content area

Abstract

CVE-2025-8713 covers a statistics exposure path that could allow a user to infer sampled data in a view, partition, or child table, potentially bypassing access controls or row-level security; fixes extend to supported releases back to version 13. CVE- 2025-8714 and CVE-2025-8715 both involve restore-time code execution vectors—one via untrusted data crafted by a superuser on the origin server and another via improper newline handling in object names—with implications for client systems running and for the restore target server. Additional items touch WAL retention during checkpoints, GSSAPI authentication stability, the handling of nested character classes in, and regression fixes that restore expected behavior for PL/pgSQL parallelization and certain MERGE edge cases.

Details

1007133
Company / organization
Title
POSTGRESQL SHIPS SECURITY UPDATES
Publication title
Worldwide Databases; Boynton Beach
Volume
37
Issue
9
Publication year
2025
Publication date
Sep 1, 2025
Publisher
Worldwide Videotex
Place of publication
Boynton Beach
Country of publication
United States
Source type
Trade Journal
Language of publication
English
Document type
News
ProQuest document ID
3249726109
Document URL
https://www.proquest.com/trade-journals/postgresql-ships-security-updates/docview/3249726109/se-2?accountid=208611
Copyright
Copyright Worldwide Videotex Sep 1, 2025
Last updated
2025-09-12
Database
ProQuest One Academic