New Debian postgresql-15 15.13-0+deb12u1A~5.2.1.202505191416 fixes: This update addresses the following issue: 15.13-0+deb12u1 (Tue, 06 May 2025 17:55:19 +0200) * New upstream version 15.13. + Avoid one-byte buffer overread when examining invalidly-encoded strings that are claimed to be in GB18030 encoding (Noah Misch, Andres Freund) While unlikely, a SIGSEGV crash could occur if an incomplete multibyte character appeared at the end of memory. This was possible both in the server and in libpq-using applications. (CVE-2025-4207)
--- mirror/ftp/pool/main/p/postgresql-15/postgresql-15_15.12-0+deb12u2A~5.2.1.202503241435.dsc +++ apt/ucs_5.2-0-errata5.2-1/source/postgresql-15_15.13-0+deb12u1A~5.2.1.202505191944.dsc @@ -1,7 +1,18 @@ -15.12-0+deb12u2A~5.2.1.202503241435 [Mon, 24 Mar 2025 14:59:18 -0000] Univention builddaemon <buildd@univention.de>: +15.13-0+deb12u1A~5.2.1.202505191944 [Mon, 19 May 2025 19:44:36 -0000] Univention builddaemon <buildd@univention.de>: * UCS auto build. The following patches have been applied to the original source package 00_version_bump.patch + +15.13-0+deb12u1 [Tue, 06 May 2025 17:55:19 +0200] Christoph Berg <myon@debian.org>: + + * New upstream version 15.13. + + + Avoid one-byte buffer overread when examining invalidly-encoded strings + that are claimed to be in GB18030 encoding (Noah Misch, Andres Freund) + + While unlikely, a SIGSEGV crash could occur if an incomplete multibyte + character appeared at the end of memory. This was possible both in the + server and in libpq-using applications. (CVE-2025-4207) 15.12-0+deb12u2 [Thu, 06 Mar 2025 11:38:37 +0100] Christoph Berg <myon@debian.org>: <http://piuparts.knut.univention.de/5.2-1/#8091095866781299462>
OK: bug OK: yaml OK: announce_errata OK: patch OK: piuparts [5.2-1] c581afe320 Bug #58291: postgresql-15 15.13-0+deb12u1A~5.2.1.202505191944 doc/errata/staging/postgresql-15.yaml | 13 +++++++++++++ 1 file changed, 13 insertions(+)
<https://errata.software-univention.de/#/?erratum=5.2x108>