Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2025-1094 - Requires update PostgreSQL 17.3 #497

Open
gonzalezge opened this issue Feb 20, 2025 · 9 comments
Open

CVE-2025-1094 - Requires update PostgreSQL 17.3 #497

gonzalezge opened this issue Feb 20, 2025 · 9 comments

Comments

@gonzalezge
Copy link

What is the bug or the crash?

PostgreSQL that is vulnerable to a critical security flaw (CVE-2025-1094). That was already patched by Postgresql. A lot of organizations/users use kartozar/postgis.

https://www.postgresql.org/about/news/postgresql-173-167-1511-1416-and-1319-released-3015/

To patch it, you need to update to 17.3,

It would be highly appreciated if you could release the updated in the docker hub registry. Just required a build and re-upload.

Thank you

Steps to reproduce the issue

Run the 17.3-5 to see the vulnerability

Versions

17.3-5

Additional context

No response

@gonzalezge gonzalezge changed the title CVE-2025-1094 CVE-2025-1094 - Requires update PostgreSQL 17.3 Feb 20, 2025
@NyakudyaA
Copy link
Collaborator

@gonzalezge Please feel free to submit a PR, GitHub action will push a new image when we merge the PR

@gonzalezge
Copy link
Author

gonzalezge commented Feb 20, 2025

Thank you, but in this case is not necessary a PR. Is just rebuilding the image, and automatic will pick up the 17.3. I tried in locally and works.

Image

@NyakudyaA
Copy link
Collaborator

Ok, will check if I can trigger the action manually

@gonzalezge
Copy link
Author

Thank you! I think will be the same case for 16, 15, and 14, just rebuilding and updating to the latest version

https://www.postgresql.org/support/security/CVE-2025-1094/

@javeddc
Copy link

javeddc commented Feb 20, 2025

Agree this would be super useful if it's possible to have an image with the patched version 🙏

@lupiyamujalaunimelb
Copy link

My organisation also needs this update. When could we have this?

@NyakudyaA
Copy link
Collaborator

Pushed a new update, please pull

@NyakudyaA
Copy link
Collaborator

Thank you! I think will be the same case for 16, 15, and 14, just rebuilding and updating to the latest version

https://www.postgresql.org/support/security/CVE-2025-1094/

This will need a PR where we adjust the GitHub action with the build matrix for those versions

@gonzalezge
Copy link
Author

Thank you!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants