CVE.RADIO
FREN

CVE-2024-10977

postgresql-15VulnerabilityCVSS 3.1Patched

No public exploitation has been reported so far. A fixed version is available (see the table below).

Recommended action: Update to the fixed version listed for your distribution using the native package manager.

Severity metrics

CVSS 3.1 : 3.1 LOW

Attack vectorNetwork (remote)
Attack complexityHigh
Privileges requiredNone
User interactionRequired
ScopeUnchanged
Confidentiality impactNone
Integrity impactLow
Availability impactNone

Vector: AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N

Affected & fixed versions by distribution

Versions are the native distribution strings (backport-aware): RHEL/Debian/SUSE backport fixes, so compare with the distro version comparator (dpkg / rpm / vercmp), not the upstream version.

DistributionPackageAffectedFixed versionStatus
Debian:12postgresql-15-15.9-0+deb12u1fixed
Ubuntu:24.04:LTSpostgresql-16-16.6-0ubuntu0.24.04.1fixed
SUSE:Linux Enterprise Module for Basesystem 15 SP6postgresql-17-150600.17.6.1fixed
SUSE:Linux Enterprise Module for Package Hub 15 SP6postgresql-17-150600.17.6.1fixed
SUSE:Linux Enterprise Module for Server Applications 15 SP6postgresql-17-150600.17.6.1fixed
openSUSE:Leap 15.6postgresql-17-150600.17.6.1fixed
SUSE:Linux Enterprise Module for Basesystem 15 SP5postgresql-17-150500.10.9.1fixed
SUSE:Linux Enterprise Module for Legacy 15 SP5postgresql-17-150500.10.9.1fixed
SUSE:Linux Enterprise Module for Package Hub 15 SP5postgresql-17-150500.10.9.1fixed
SUSE:Linux Enterprise Module for Server Applications 15 SP5postgresql-17-150500.10.9.1fixed
SUSE:Linux Enterprise High Performance Computing 15 SP2-LTSSpostgresql-17-150200.4.30.1fixed
SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSSpostgresql-17-150300.10.27.1fixed
SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOSpostgresql-17-150400.4.18.1fixed
SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSSpostgresql-17-150400.4.18.1fixed
SUSE:Linux Enterprise Server 15 SP2-LTSSpostgresql-17-150200.4.30.1fixed
SUSE:Linux Enterprise Server 15 SP3-LTSSpostgresql-17-150300.10.27.1fixed
SUSE:Linux Enterprise Server 15 SP4-LTSSpostgresql-17-150400.4.18.1fixed
SUSE:Linux Enterprise Server for SAP Applications 15 SP2postgresql-17-150200.4.30.1fixed
SUSE:Linux Enterprise Server for SAP Applications 15 SP3postgresql-17-150300.10.27.1fixed
SUSE:Linux Enterprise Server for SAP Applications 15 SP4postgresql-17-150400.4.18.1fixed
SUSE:Manager Proxy 4.3postgresql-17-150400.4.18.1fixed
SUSE:Manager Server 4.3postgresql-17-150400.4.18.1fixed
SUSE:Enterprise Storage 7.1postgresql-17-150300.10.27.1fixed
openSUSE:Leap 15.5postgresql-17-150500.10.9.1fixed
SUSE:Linux Enterprise Server 12 SP5-LTSSpostgresql-17-4.29.1fixed
SUSE:Linux Enterprise Server LTSS Extended Security 12 SP5postgresql-17-4.29.1fixed
SUSE:Linux Enterprise Server 12 SP5-LTSSpostgresql15-15.10-3.33.1fixed
SUSE:Linux Enterprise Server LTSS Extended Security 12 SP5postgresql15-15.10-3.33.1fixed
SUSE:Linux Enterprise Module for Legacy 15 SP6postgresql15-15.10-150600.16.9.1fixed
openSUSE:Leap 15.6postgresql15-15.10-150600.16.9.1fixed
SUSE:Linux Enterprise Module for Basesystem 15 SP5postgresql15-15.10-150200.5.33.1fixed
SUSE:Linux Enterprise Module for Server Applications 15 SP5postgresql15-15.10-150200.5.33.1fixed
SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSSpostgresql15-15.10-150200.5.33.1fixed
SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOSpostgresql15-15.10-150200.5.33.1fixed
SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSSpostgresql15-15.10-150200.5.33.1fixed
SUSE:Linux Enterprise Server 15 SP3-LTSSpostgresql15-15.10-150200.5.33.1fixed
SUSE:Linux Enterprise Server 15 SP4-LTSSpostgresql15-15.10-150200.5.33.1fixed
SUSE:Linux Enterprise Server for SAP Applications 15 SP3postgresql15-15.10-150200.5.33.1fixed
SUSE:Linux Enterprise Server for SAP Applications 15 SP4postgresql15-15.10-150200.5.33.1fixed
SUSE:Manager Proxy 4.3postgresql15-15.10-150200.5.33.1fixed
SUSE:Manager Server 4.3postgresql15-15.10-150200.5.33.1fixed
SUSE:Enterprise Storage 7.1postgresql15-15.10-150200.5.33.1fixed
openSUSE:Leap 15.5postgresql15-15.10-150200.5.33.1fixed
SUSE:Linux Enterprise Module for Basesystem 15 SP6postgresql16-16.6-150600.16.10.1fixed
SUSE:Linux Enterprise Module for Package Hub 15 SP6postgresql16-16.6-150600.16.10.1fixed
SUSE:Linux Enterprise Module for Server Applications 15 SP6postgresql16-16.6-150600.16.10.1fixed
openSUSE:Leap 15.6postgresql16-16.6-150600.16.10.1fixed
SUSE:Linux Enterprise Module for Basesystem 15 SP5postgresql16-16.6-150200.5.21.1fixed
SUSE:Linux Enterprise Module for Package Hub 15 SP5postgresql16-16.6-150200.5.21.1fixed
SUSE:Linux Enterprise Module for Server Applications 15 SP5postgresql16-16.6-150200.5.21.1fixed
SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSSpostgresql16-16.6-150200.5.21.1fixed
SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOSpostgresql16-16.6-150200.5.21.1fixed
SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSSpostgresql16-16.6-150200.5.21.1fixed
SUSE:Linux Enterprise Server 15 SP3-LTSSpostgresql16-16.6-150200.5.21.1fixed
SUSE:Linux Enterprise Server 15 SP4-LTSSpostgresql16-16.6-150200.5.21.1fixed
SUSE:Linux Enterprise Server for SAP Applications 15 SP3postgresql16-16.6-150200.5.21.1fixed
SUSE:Linux Enterprise Server for SAP Applications 15 SP4postgresql16-16.6-150200.5.21.1fixed
SUSE:Manager Proxy 4.3postgresql16-16.6-150200.5.21.1fixed
SUSE:Manager Server 4.3postgresql16-16.6-150200.5.21.1fixed
SUSE:Enterprise Storage 7.1postgresql16-16.6-150200.5.21.1fixed
openSUSE:Leap 15.5postgresql16-16.6-150200.5.21.1fixed
SUSE:Linux Enterprise Server 12 SP5-LTSSpostgresql16-16.6-3.21.1fixed
SUSE:Linux Enterprise Server LTSS Extended Security 12 SP5postgresql16-16.6-3.21.1fixed
openSUSE:Tumbleweedpostgresql15-15.9-1.1fixed
openSUSE:Tumbleweedpostgresql16-16.5-1.1fixed

Sources