CVE-2021-32029
Summary
| CVE | CVE-2021-32029 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-10-08 17:15:00 UTC |
| Updated | 2022-08-05 12:22:00 UTC |
| Description | A flaw was found in postgresql. Using an UPDATE ... RETURNING command on a purpose-crafted table, an authenticated database user could read arbitrary bytes of server memory. The highest threat from this vulnerability is to data confidentiality. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| PostgreSQL: CVE-2021-32029: Memory disclosure in partitioned-table UPDATE ... RETURNING |
MISC |
www.postgresql.org |
|
| 1956883 – (CVE-2021-32029) CVE-2021-32029 postgresql: Memory disclosure in partitioned-table UPDATE ... RETURNING |
MISC |
bugzilla.redhat.com |
|
| October 2021 PostgreSQL Vulnerabilities in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159268 Oracle Enterprise Linux Security Update for postgresql:12 (ELSA-2021-2372)
- 159269 Oracle Enterprise Linux Security Update for postgresql:13 (ELSA-2021-2375)
- 178617 Debian Security Update for postgresql-11 (DSA 4915-1)
- 180057 Debian Security Update for postgresql-13 (CVE-2021-32029)
- 198391 Ubuntu Security Notification for PostgreSQL vulnerabilities (USN-4972-1)
- 239382 Red Hat Update for postgresql:13 (RHSA-2021:2375)
- 239383 Red Hat Update for postgresql:12 (RHSA-2021:2372)
- 239435 Red Hat Update for rh-postgresql13-postgresql (RHSA-2021:2396)
- 239437 Red Hat Update for rh-postgresql12-postgresql (RHSA-2021:2394)
- 239442 Red Hat Update for postgresql:12 (RHSA-2021:2389)
- 356175 Amazon Linux Security Advisory for postgresql : ALASPOSTGRESQL12-2023-004
- 356295 Amazon Linux Security Advisory for postgresql : ALASPOSTGRESQL13-2023-003
- 377098 Alibaba Cloud Linux Security Update for postgresql:13 (ALINUX3-SA-2021:0043)
- 500542 Alpine Linux Security Update for postgresql
- 501470 Alpine Linux Security Update for postgresql
- 501993 Alpine Linux Security Update for postgresql13
- 502010 Alpine Linux Security Update for postgresql14
- 502776 Alpine Linux Security Update for postgresql15
- 504309 Alpine Linux Security Update for postgresql14
- 505668 Alpine Linux Security Update for postgresql15
- 690136 Free Berkeley Software Distribution (FreeBSD) Security Update for postgresql (76e0bb86-b4cb-11eb-b9c9-6cc21735f730)
- 750050 SUSE Enterprise Linux Security Update for postgresql13 (SUSE-SU-2021:1784-1)
- 750052 SUSE Enterprise Linux Security Update for postgresql13 (SUSE-SU-2021:1785-1)
- 750053 SUSE Enterprise Linux Security Update for postgresql12 (SUSE-SU-2021:1783-1)
- 750068 SUSE Enterprise Linux Security Update for postgresql13 (SUSE-SU-2021:1785-1)
- 750657 SUSE Enterprise Linux Security Update for postgresql12 (SUSE-SU-2021:1994-1)
- 750776 OpenSUSE Security Update for postgresql13 (openSUSE-SU-2021:1785-1)
- 750816 OpenSUSE Security Update for postgresql12 (openSUSE-SU-2021:1994-1)
- 752529 SUSE Enterprise Linux Security Update for postgresql12 (SUSE-SU-2022:2958-1)
- 940218 AlmaLinux Security Update for postgresql:13 (ALSA-2021:2375)
- 940413 AlmaLinux Security Update for postgresql:12 (ALSA-2021:2372)
- 960091 Rocky Linux Security Update for postgresql:13 (RLSA-2021:2375)
- 960093 Rocky Linux Security Update for postgresql:12 (RLSA-2021:2372)