We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-4207

PostgreSQL GB18030 encoding validation can read one byte past end of allocation for text that fails validation



Description

Buffer over-read in PostgreSQL GB18030 encoding validation allows a database input provider to achieve temporary denial of service on platforms where a 1-byte over-read can elicit process termination. This affects the database server and also libpq. Versions before PostgreSQL 17.5, 16.9, 15.13, 14.18, and 13.21 are affected.

Reserved 2025-05-02 | Published 2025-05-08 | Updated 2025-05-09 | Assigner PostgreSQL


MEDIUM: 5.9CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Problem types

Buffer Over-read

References

www.postgresql.org/support/security/CVE-2025-4207/

cve.org (CVE-2025-4207)

nvd.nist.gov (CVE-2025-4207)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-4207

Support options

Helpdesk Chat, Email, Knowledgebase