Update Info

SUSE-SLE-Module-Packagehub-Subpackages-15-SP6-2024-4118


Security update for postgresql14


Type: security
Severity: important
Issued: 2024-11-29
Description:
This update for postgresql14 fixes the following issues:

- CVE-2024-10976: Ensure cached plans are marked as dependent on the calling role when RLS applies to a non-top-level table reference (bsc#1233323).
- CVE-2024-10977: Make libpq discard error messages received during SSL or GSS protocol negotiation (bsc#1233325).
- CVE-2024-10978: Fix unintended interactions between SET SESSION AUTHORIZATION and SET ROLE (bsc#1233326).
- CVE-2024-10979: Prevent trusted PL/Perl code from changing environment variables (bsc#1233327).


              

Packages


  • postgresql14-14.15-150600.16.9.1