7.1 HIGH
- CVSS version (CVSS): 4.0
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Attack Requirement (AT): None (N)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Vulnerable System Impact Confidentiality (VC): None (N)
- Vulnerable System Impact Integrity (VI): None (N)
- Vulnerable System Impact Availability (VA): High (H)
- Subsequent System Impact Confidentiality (SC): None (N)
- Subsequent System Impact Integrity (SI): None (N)
- Subsequent System Impact Availability (SA): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Attack Requirement (MAT): None (N)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Vulnerable System Impact Confidentiality (MVC): None (N)
- Modified Vulnerable System Impact Integrity (MVI): None (N)
- Modified Vulnerable System Impact Availability (MVA): High (H)
- Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
- Modified Subsequent System Impact Integrity (MSI): Negligible (N)
- Modified Subsequent System Impact Availability (MSA): Negligible (N)
- Safety (S): Not Defined (X)
- Automatable (AU): Not Defined (X)
- Recovery (R): Not Defined (X)
- Value Density (V): Not Defined (X)
- Vulnerability Response Effort (RE): Not Defined (X)
- Provider Urgency (U): Not Defined (X)
- Confidentiality Req. (CR): Not Defined (X)
- Integrity Req. (IR): Not Defined (X)
- Availability Req. (AR): Not Defined (X)
- Exploit Maturity (E): Not Defined (X)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
12 packages
- timescaledb-parallel-copy
- timescaledb-tune
- postgresqlPackages.timescaledb-apache
- postgresqlPackages.timescaledb_toolkit
- postgresql15Packages.timescaledb-apache
- postgresql16Packages.timescaledb-apache
- postgresql17Packages.timescaledb-apache
- postgresql18Packages.timescaledb-apache
- postgresql15Packages.timescaledb_toolkit
- postgresql16Packages.timescaledb_toolkit
- postgresql17Packages.timescaledb_toolkit
- postgresql18Packages.timescaledb_toolkit
- @LeSuisse accepted
- @LeSuisse published on GitHub
TimescaleDB 2.29.1 Out-of-Bounds Read DoS via Gorilla Compression Reverse Iterator
TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read vulnerability in the Gorilla compression reverse row iterator that allows authenticated attackers to cause a denial of service by storing a crafted compressed datum with an internally inconsistent BitArray. Attackers with DML access to a compressed hypertable can trigger an unsigned integer wraparound in the reverse iterator bucket index computation, causing a read beyond the end of the bucket array, resulting in a SIGSEGV crash that can be repeatedly triggered on each subsequent reverse-order scan.
References
-
Pull Request issue-tracking
-
Patch Commit patch
Affected products
- ==517c13e7cc6afadb4a7deaa7a5a5a29065e5b5a3
- =<2.29.1
Matching in nixpkgs
pkgs.postgresqlPackages.timescaledb
Scales PostgreSQL for time-series data via automatic partitioning across time and space
pkgs.postgresql15Packages.timescaledb
None
pkgs.postgresql16Packages.timescaledb
Scales PostgreSQL for time-series data via automatic partitioning across time and space
pkgs.postgresql17Packages.timescaledb
Scales PostgreSQL for time-series data via automatic partitioning across time and space
Ignored packages (12)
pkgs.timescaledb-tune
Tool for tuning your TimescaleDB for better performance
pkgs.timescaledb-parallel-copy
Bulk, parallel insert of CSV records into PostgreSQL
pkgs.postgresqlPackages.timescaledb-apache
Scales PostgreSQL for time-series data via automatic partitioning across time and space
pkgs.postgresqlPackages.timescaledb_toolkit
Provide additional tools to ease all things analytic when using TimescaleDB
pkgs.postgresql15Packages.timescaledb-apache
None
pkgs.postgresql16Packages.timescaledb-apache
Scales PostgreSQL for time-series data via automatic partitioning across time and space
pkgs.postgresql17Packages.timescaledb-apache
Scales PostgreSQL for time-series data via automatic partitioning across time and space
pkgs.postgresql18Packages.timescaledb-apache
Scales PostgreSQL for time-series data via automatic partitioning across time and space
pkgs.postgresql15Packages.timescaledb_toolkit
Provide additional tools to ease all things analytic when using TimescaleDB
pkgs.postgresql16Packages.timescaledb_toolkit
Provide additional tools to ease all things analytic when using TimescaleDB
pkgs.postgresql17Packages.timescaledb_toolkit
Provide additional tools to ease all things analytic when using TimescaleDB
pkgs.postgresql18Packages.timescaledb_toolkit
Provide additional tools to ease all things analytic when using TimescaleDB
Package maintainers
-
@kirillrdy Kirill Radzikhovskyy <kirillrdy@gmail.com>
7.2 HIGH
- CVSS version (CVSS): 4.0
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Attack Requirement (AT): None (N)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Vulnerable System Impact Confidentiality (VC): High (H)
- Vulnerable System Impact Integrity (VI): None (N)
- Vulnerable System Impact Availability (VA): High (H)
- Subsequent System Impact Confidentiality (SC): None (N)
- Subsequent System Impact Integrity (SI): None (N)
- Subsequent System Impact Availability (SA): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Attack Requirement (MAT): None (N)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Vulnerable System Impact Confidentiality (MVC): High (H)
- Modified Vulnerable System Impact Integrity (MVI): None (N)
- Modified Vulnerable System Impact Availability (MVA): High (H)
- Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
- Modified Subsequent System Impact Integrity (MSI): Negligible (N)
- Modified Subsequent System Impact Availability (MSA): Negligible (N)
- Safety (S): Not Defined (X)
- Automatable (AU): Not Defined (X)
- Recovery (R): Not Defined (X)
- Value Density (V): Not Defined (X)
- Vulnerability Response Effort (RE): Not Defined (X)
- Provider Urgency (U): Not Defined (X)
- Confidentiality Req. (CR): Not Defined (X)
- Integrity Req. (IR): Not Defined (X)
- Availability Req. (AR): Not Defined (X)
- Exploit Maturity (E): Not Defined (X)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
12 packages
- timescaledb-tune
- timescaledb-parallel-copy
- postgresqlPackages.timescaledb-apache
- postgresqlPackages.timescaledb_toolkit
- postgresql15Packages.timescaledb-apache
- postgresql16Packages.timescaledb-apache
- postgresql17Packages.timescaledb-apache
- postgresql18Packages.timescaledb-apache
- postgresql15Packages.timescaledb_toolkit
- postgresql16Packages.timescaledb_toolkit
- postgresql17Packages.timescaledb_toolkit
- postgresql18Packages.timescaledb_toolkit
- @LeSuisse accepted
- @LeSuisse published on GitHub
TimescaleDB 2.29.1 Out-of-Bounds Read Information Disclosure via Dictionary Compression Reverse Iterator
TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read in the Dictionary compression reverse row iterator (tsl/src/compression/algorithms/dictionary.c). The forward path validates the decoded index; the reverse path uses an assertion compiled out of release builds, leaving the 64-bit Simple8b index unvalidated and the read offset attacker-controlled. Attackers with DML access to a physical compressed relation can store a crafted datum and run a reverse-order scan. With a pass-by-value column type the out-of-bounds Datum is returned to the client as a normal column value, disclosing backend memory including the shared buffer pool, which SQL access control does not cover.
References
-
Pull Request issue-tracking
-
Patch Commit patch
Affected products
- =<2.29.1
- ==517c13e7cc6afadb4a7deaa7a5a5a29065e5b5a3
Matching in nixpkgs
pkgs.postgresqlPackages.timescaledb
Scales PostgreSQL for time-series data via automatic partitioning across time and space
pkgs.postgresql15Packages.timescaledb
None
pkgs.postgresql16Packages.timescaledb
Scales PostgreSQL for time-series data via automatic partitioning across time and space
pkgs.postgresql17Packages.timescaledb
Scales PostgreSQL for time-series data via automatic partitioning across time and space
Ignored packages (12)
pkgs.timescaledb-tune
Tool for tuning your TimescaleDB for better performance
pkgs.timescaledb-parallel-copy
Bulk, parallel insert of CSV records into PostgreSQL
pkgs.postgresqlPackages.timescaledb-apache
Scales PostgreSQL for time-series data via automatic partitioning across time and space
pkgs.postgresqlPackages.timescaledb_toolkit
Provide additional tools to ease all things analytic when using TimescaleDB
pkgs.postgresql15Packages.timescaledb-apache
None
pkgs.postgresql16Packages.timescaledb-apache
Scales PostgreSQL for time-series data via automatic partitioning across time and space
pkgs.postgresql17Packages.timescaledb-apache
Scales PostgreSQL for time-series data via automatic partitioning across time and space
pkgs.postgresql18Packages.timescaledb-apache
Scales PostgreSQL for time-series data via automatic partitioning across time and space
pkgs.postgresql15Packages.timescaledb_toolkit
Provide additional tools to ease all things analytic when using TimescaleDB
pkgs.postgresql16Packages.timescaledb_toolkit
Provide additional tools to ease all things analytic when using TimescaleDB
pkgs.postgresql17Packages.timescaledb_toolkit
Provide additional tools to ease all things analytic when using TimescaleDB
pkgs.postgresql18Packages.timescaledb_toolkit
Provide additional tools to ease all things analytic when using TimescaleDB
Package maintainers
-
@kirillrdy Kirill Radzikhovskyy <kirillrdy@gmail.com>
7.1 HIGH
- CVSS version (CVSS): 4.0
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Attack Requirement (AT): None (N)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Vulnerable System Impact Confidentiality (VC): None (N)
- Vulnerable System Impact Integrity (VI): Low (L)
- Vulnerable System Impact Availability (VA): High (H)
- Subsequent System Impact Confidentiality (SC): None (N)
- Subsequent System Impact Integrity (SI): None (N)
- Subsequent System Impact Availability (SA): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Attack Requirement (MAT): None (N)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Vulnerable System Impact Confidentiality (MVC): None (N)
- Modified Vulnerable System Impact Integrity (MVI): Low (L)
- Modified Vulnerable System Impact Availability (MVA): High (H)
- Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
- Modified Subsequent System Impact Integrity (MSI): Negligible (N)
- Modified Subsequent System Impact Availability (MSA): Negligible (N)
- Safety (S): Not Defined (X)
- Automatable (AU): Not Defined (X)
- Recovery (R): Not Defined (X)
- Value Density (V): Not Defined (X)
- Vulnerability Response Effort (RE): Not Defined (X)
- Provider Urgency (U): Not Defined (X)
- Confidentiality Req. (CR): Not Defined (X)
- Integrity Req. (IR): Not Defined (X)
- Availability Req. (AR): Not Defined (X)
- Exploit Maturity (E): Not Defined (X)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
12 packages
- timescaledb-tune
- timescaledb-parallel-copy
- postgresqlPackages.timescaledb-apache
- postgresqlPackages.timescaledb_toolkit
- postgresql15Packages.timescaledb-apache
- postgresql16Packages.timescaledb-apache
- postgresql17Packages.timescaledb-apache
- postgresql18Packages.timescaledb-apache
- postgresql15Packages.timescaledb_toolkit
- postgresql16Packages.timescaledb_toolkit
- postgresql17Packages.timescaledb_toolkit
- postgresql18Packages.timescaledb_toolkit
- @LeSuisse accepted
- @LeSuisse published on GitHub
TimescaleDB 2.29.1 Out-of-Bounds Read DoS via Bulk Dictionary Decompression Negative Index
TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read vulnerability that allows authenticated attackers to cause query-result integrity failures or backend crashes by supplying a crafted Simple8b selector-11 value, which is stored in the signed int16 Arrow dictionary-index type and bypasses index validation checks in bulk text dictionary decompression. Attackers with direct DML access to a non-frozen physical compressed hypertable relation can trigger an out-of-bounds read before the base of the live offsets array through the VectorAgg single-text hashing strategy, resulting in incorrect aggregation output, backend SIGSEGV, or PostgreSQL crash recovery depending on build configuration.
References
-
Pull Request issue-tracking
-
Patch Commit patch
Affected products
- =<2.29.1
- ==517c13e7cc6afadb4a7deaa7a5a5a29065e5b5a3
Matching in nixpkgs
pkgs.postgresqlPackages.timescaledb
Scales PostgreSQL for time-series data via automatic partitioning across time and space
pkgs.postgresql15Packages.timescaledb
None
pkgs.postgresql16Packages.timescaledb
Scales PostgreSQL for time-series data via automatic partitioning across time and space
pkgs.postgresql17Packages.timescaledb
Scales PostgreSQL for time-series data via automatic partitioning across time and space
Ignored packages (12)
pkgs.timescaledb-tune
Tool for tuning your TimescaleDB for better performance
pkgs.timescaledb-parallel-copy
Bulk, parallel insert of CSV records into PostgreSQL
pkgs.postgresqlPackages.timescaledb-apache
Scales PostgreSQL for time-series data via automatic partitioning across time and space
pkgs.postgresqlPackages.timescaledb_toolkit
Provide additional tools to ease all things analytic when using TimescaleDB
pkgs.postgresql15Packages.timescaledb-apache
None
pkgs.postgresql16Packages.timescaledb-apache
Scales PostgreSQL for time-series data via automatic partitioning across time and space
pkgs.postgresql17Packages.timescaledb-apache
Scales PostgreSQL for time-series data via automatic partitioning across time and space
pkgs.postgresql18Packages.timescaledb-apache
Scales PostgreSQL for time-series data via automatic partitioning across time and space
pkgs.postgresql15Packages.timescaledb_toolkit
Provide additional tools to ease all things analytic when using TimescaleDB
pkgs.postgresql16Packages.timescaledb_toolkit
Provide additional tools to ease all things analytic when using TimescaleDB
pkgs.postgresql17Packages.timescaledb_toolkit
Provide additional tools to ease all things analytic when using TimescaleDB
pkgs.postgresql18Packages.timescaledb_toolkit
Provide additional tools to ease all things analytic when using TimescaleDB
Package maintainers
-
@kirillrdy Kirill Radzikhovskyy <kirillrdy@gmail.com>