Vulnerability Scan Report for registry.suse.com/suse/postgres:14.8-22.14
PostgreSQL 15 container based on the SLE Base Container Image.
Last scanned on: June 22, 2025 05:02

PostgreSQL 15 container based on the SLE Base Container Image.
Last scanned on: June 22, 2025 05:02
Package Name | Severity | Status | Description | Reference links | |
---|---|---|---|---|---|
postgresql14-server | HIGH | fixed |
Security update for postgresql14 Vulnerability ID: SUSE-SU-2024:4176-1 Installed Version: 14.8-150200.5.26.1 Fixed Version: 14.15-150200.5.50.1 This update for postgresql14 fixes the following issues: - CVE-2024-10976: Ensure cached plans are marked as dependent on the calling role when RLS applies to a non-top-level table reference (bsc#1233323). - CVE-2024-10977: Make libpq discard error messages received during SSL or GSS protocol negotiation (bsc#1233325). - CVE-2024-10978: Fix unintended interactions between SET SESSION AUTHORIZATION and SET ROLE (bsc#1233326). - CVE-2024-10979: Prevent trusted PL/Perl code from changing environment variables (bsc#1233327). |
||
postgresql14-server | HIGH | fixed |
Security update for postgresql14 Vulnerability ID: SUSE-SU-2025:0632-1 Installed Version: 14.8-150200.5.26.1 Fixed Version: 14.17-150200.5.55.1 This update for postgresql14 fixes the following issues: Upgrade to 14.17: - CVE-2025-1094: Harden PQescapeString and allied functions against invalidly-encoded input strings (bsc#1237093). |
||
postgresql14-server | MEDIUM | fixed |
Security update for postgresql15 Vulnerability ID: SUSE-SU-2023:3348-1 Installed Version: 14.8-150200.5.26.1 Fixed Version: 14.9-150200.5.29.1 This update for postgresql15 fixes the following issues: - Update to 14.9 - CVE-2023-39417: Fixed potential SQL injection for trusted extensions. (bsc#1214059) |
||
postgresql14-server | MEDIUM | fixed |
Security update for postgresql14 Vulnerability ID: SUSE-SU-2025:01786-1 Installed Version: 14.8-150200.5.26.1 Fixed Version: 14.18-150200.5.58.1 This update for postgresql14 fixes the following issues: Upgrade to 14.18: - CVE-2025-4207: Fixed PostgreSQL GB18030 encoding validation can read one byte past end of allocation for text that fails validation (bsc#1242931) |
||
procps | LOW | fixed |
Security update for procps Vulnerability ID: SUSE-SU-2023:3472-1 Installed Version: 3.3.15-150000.7.31.1 Fixed Version: 3.3.15-150000.7.34.1 This update for procps fixes the following issues: - CVE-2023-4016: Fixed ps buffer overflow (bsc#1214290). |