CVE-2025-12817
Public on 2025-11-13
Modified on 2025-11-13
Description
Missing authorization in PostgreSQL CREATE STATISTICS command allows a table owner to achieve denial of service against other CREATE STATISTICS users by creating in any schema. A later CREATE STATISTICS for the same name, from a user having the CREATE privilege, would then fail. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.
Severity
See what this means
CVSS v3 Base Score
See breakdown
Affected Packages
| Platform | Package | Release Date | Advisory | Status |
|---|---|---|---|---|
| Amazon Linux 2 - Core | postgresql | Not Affected | ||
| Amazon Linux 2 - Postgresql14 Extra | postgresql | 2025-12-08 | ALAS2POSTGRESQL14-2025-021 | Fixed |
| Amazon Linux 2023 | postgresql15 | 2025-12-08 | ALAS2023-2025-1313 | Fixed |
| Amazon Linux 2023 | postgresql16 | 2025-12-08 | ALAS2023-2025-1314 | Fixed |
| Amazon Linux 2023 | postgresql17 | 2025-12-08 | ALAS2023-2025-1300 | Fixed |
CVSS Scores
| Score Type | Score | Vector | |
|---|---|---|---|
| Amazon Linux | CVSSv3 | 3.1 | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L |