Postgresql: role pg_signal_backend can signal certain superuser processes.
Published Dec 10, 2023
4.4
MEDIUMCVSS 3.1
EPSS 2.56%
Description
A flaw was found in PostgreSQL involving the pg_cancel_backend role that signals background workers, including the logical replication launcher, autovacuum workers, and the autovacuum launcher. Successful exploitation requires a non-core extension with a less-resilient background worker and would affect that specific background worker only. This issue may allow a remote high privileged user to launch a denial of service (DoS) attack.
Affected products
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 7 | affected |
| |||
| Red Hat | Red Hat Enterprise Linux 8 | affected |
| |||
| Red Hat | Red Hat Software Collections | affected |
|
Configuration 1
- ≥ 11.0 · < 11.22
- ≥ 12.0 · < 12.17
- ≥ 13.0 · < 13.13
- ≥ 14.0 · < 14.10
- ≥ 15.0 · < 15.5
- 16.0
Configuration 2
- 9.2
- 9.0_ppc64le
- 9.2_ppc64le
- 8.6_aarch64
- 9.0_aarch64
- 9.2_aarch64
- 9.0_s390x
- 9.2_s390x
- 9.0_ppc64le
- 9.2_ppc64le
- 1.0
- 8.0
- 9.0
- 8.6
- 8.8
- 9.0
- 9.2
- 8.0
- 8.8_aarch64
- 8.0_s390x
- 8.6_s390x
- 8.8_s390x
- 9.0_s390x
- 9.2_s390x
- 8.0_ppc64le
- 8.6_ppc64le
- 8.8_ppc64le
- 9.0_ppc64le
- 9.2_ppc64le
- 8.2
- 8.4
- 8.6
- 9.2
- 8.2
- 8.4
- 8.6
No data.
RHACS-3.74-RHEL-8
advanced-cluster-security/rhacs-central-db-rhel8:3.74.8-9
Fixed · RHSA-2024:0304
RHACS-3.74-RHEL-8
advanced-cluster-security/rhacs-main-rhel8:3.74.8-9
Fixed · RHSA-2024:0304
RHACS-3.74-RHEL-8
advanced-cluster-security/rhacs-operator-bundle:3.74.8-7
Fixed · RHSA-2024:0304
RHACS-3.74-RHEL-8
advanced-cluster-security/rhacs-scanner-db-rhel8:3.74.8-9
Fixed · RHSA-2024:0304
RHACS-3.74-RHEL-8
advanced-cluster-security/rhacs-scanner-db-slim-rhel8:3.74.8-9
Fixed · RHSA-2024:0304
RHACS-4.1-RHEL-8
advanced-cluster-security/rhacs-central-db-rhel8:4.1.6-6
Fixed · RHSA-2024:0332
RHACS-4.1-RHEL-8
advanced-cluster-security/rhacs-main-rhel8:4.1.6-6
Fixed · RHSA-2024:0332
RHACS-4.1-RHEL-8
advanced-cluster-security/rhacs-operator-bundle:4.1.6-6
Fixed · RHSA-2024:0332
RHACS-4.1-RHEL-8
advanced-cluster-security/rhacs-scanner-db-rhel8:4.1.6-6
Fixed · RHSA-2024:0332
RHACS-4.1-RHEL-8
advanced-cluster-security/rhacs-scanner-db-slim-rhel8:4.1.6-6
Fixed · RHSA-2024:0332
Red Hat Advanced Cluster Security 4.2
advanced-cluster-security/rhacs-central-db-rhel8:4.2.4-6
Fixed · RHSA-2024:0337
Red Hat Advanced Cluster Security 4.2
advanced-cluster-security/rhacs-main-rhel8:4.2.4-6
Fixed · RHSA-2024:0337
Red Hat Advanced Cluster Security 4.2
advanced-cluster-security/rhacs-operator-bundle:4.2.4-7
Fixed · RHSA-2024:0337
Red Hat Advanced Cluster Security 4.2
advanced-cluster-security/rhacs-scanner-db-rhel8:4.2.4-6
Fixed · RHSA-2024:0337
Red Hat Advanced Cluster Security 4.2
advanced-cluster-security/rhacs-scanner-db-slim-rhel8:4.2.4-7
Fixed · RHSA-2024:0337
Red Hat Enterprise Linux 8
postgresql:12-8090020231128173330.a75119d5
Fixed · RHSA-2023:7714
Red Hat Enterprise Linux 8
postgresql:13-8090020231114113712.a75119d5
Fixed · RHSA-2023:7581
Red Hat Enterprise Linux 8
postgresql:15-8090020231114113548.a75119d5
Fixed · RHSA-2023:7884
Red Hat Enterprise Linux 8.2 Advanced Update Support
postgresql:12-8020020231128165246.4cda2c84
Fixed · RHSA-2023:7667
Red Hat Enterprise Linux 8.2 Telecommunications Update Service
postgresql:12-8020020231128165246.4cda2c84
Fixed · RHSA-2023:7667
Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions
postgresql:12-8020020231128165246.4cda2c84
Fixed · RHSA-2023:7667
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
postgresql:12-8040020231127153301.522a0ee4
Fixed · RHSA-2023:7694
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
postgresql:13-8040020231127154806.522a0ee4
Fixed · RHSA-2023:7695
Red Hat Enterprise Linux 8.4 Telecommunications Update Service
postgresql:12-8040020231127153301.522a0ee4
Fixed · RHSA-2023:7694
Red Hat Enterprise Linux 8.4 Telecommunications Update Service
postgresql:13-8040020231127154806.522a0ee4
Fixed · RHSA-2023:7695
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions
postgresql:12-8040020231127153301.522a0ee4
Fixed · RHSA-2023:7694
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions
postgresql:13-8040020231127154806.522a0ee4
Fixed · RHSA-2023:7695
Red Hat Enterprise Linux 8.6 Extended Update Support
postgresql:12-8060020231128165328.ad008a3a
Fixed · RHSA-2023:7666
Red Hat Enterprise Linux 8.6 Extended Update Support
postgresql:13-8060020231114115246.ad008a3a
Fixed · RHSA-2023:7580
Red Hat Enterprise Linux 8.8 Extended Update Support
postgresql:12-8080020231128165335.63b34585
Fixed · RHSA-2023:7656
Red Hat Enterprise Linux 8.8 Extended Update Support
postgresql:13-8080020231114105206.63b34585
Fixed · RHSA-2023:7579
Red Hat Enterprise Linux 8.8 Extended Update Support
postgresql:15-8080020231113134015.63b34585
Fixed · RHSA-2023:7883
Red Hat Enterprise Linux 9
postgresql-0:13.13-1.el9_3
Fixed · RHSA-2023:7784
Red Hat Enterprise Linux 9
postgresql:15-9030020231120082734.rhel9
Fixed · RHSA-2023:7785
Red Hat Enterprise Linux 9.0 Extended Update Support
postgresql-0:13.13-1.el9_0
Fixed · RHSA-2023:7545
Red Hat Enterprise Linux 9.2 Extended Update Support
postgresql-0:13.13-1.el9_2
Fixed · RHSA-2023:7616
Red Hat Enterprise Linux 9.2 Extended Update Support
postgresql:15-9020020231115020618.rhel9
Fixed · RHSA-2023:7885
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-postgresql12-postgresql-0:12.17-1.el7
Fixed · RHSA-2023:7770
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-postgresql13-postgresql-0:13.13-1.el7
Fixed · RHSA-2023:7772
Red Hat Enterprise Linux 6
postgresql
Out of support scope
Red Hat Enterprise Linux 7
postgresql
Fix deferred
Red Hat Enterprise Linux 8
postgresql:10/postgresql
Fix deferred
Red Hat Enterprise Linux 8
postgresql:16/postgresql
Not affected
Red Hat Enterprise Linux 9
postgresql:16/postgresql
Not affected
Red Hat Software Collections
rh-postgresql10-postgresql
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| RHACS-3.74-RHEL-8 | advanced-cluster-security/rhacs-central-db-rhel8:3.74.8-9 | Fixed | RHSA-2024:0304 |
| RHACS-3.74-RHEL-8 | advanced-cluster-security/rhacs-main-rhel8:3.74.8-9 | Fixed | RHSA-2024:0304 |
| RHACS-3.74-RHEL-8 | advanced-cluster-security/rhacs-operator-bundle:3.74.8-7 | Fixed | RHSA-2024:0304 |
| RHACS-3.74-RHEL-8 | advanced-cluster-security/rhacs-scanner-db-rhel8:3.74.8-9 | Fixed | RHSA-2024:0304 |
| RHACS-3.74-RHEL-8 | advanced-cluster-security/rhacs-scanner-db-slim-rhel8:3.74.8-9 | Fixed | RHSA-2024:0304 |
| RHACS-4.1-RHEL-8 | advanced-cluster-security/rhacs-central-db-rhel8:4.1.6-6 | Fixed | RHSA-2024:0332 |
| RHACS-4.1-RHEL-8 | advanced-cluster-security/rhacs-main-rhel8:4.1.6-6 | Fixed | RHSA-2024:0332 |
| RHACS-4.1-RHEL-8 | advanced-cluster-security/rhacs-operator-bundle:4.1.6-6 | Fixed | RHSA-2024:0332 |
| RHACS-4.1-RHEL-8 | advanced-cluster-security/rhacs-scanner-db-rhel8:4.1.6-6 | Fixed | RHSA-2024:0332 |
| RHACS-4.1-RHEL-8 | advanced-cluster-security/rhacs-scanner-db-slim-rhel8:4.1.6-6 | Fixed | RHSA-2024:0332 |
| Red Hat Advanced Cluster Security 4.2 | advanced-cluster-security/rhacs-central-db-rhel8:4.2.4-6 | Fixed | RHSA-2024:0337 |
| Red Hat Advanced Cluster Security 4.2 | advanced-cluster-security/rhacs-main-rhel8:4.2.4-6 | Fixed | RHSA-2024:0337 |
| Red Hat Advanced Cluster Security 4.2 | advanced-cluster-security/rhacs-operator-bundle:4.2.4-7 | Fixed | RHSA-2024:0337 |
| Red Hat Advanced Cluster Security 4.2 | advanced-cluster-security/rhacs-scanner-db-rhel8:4.2.4-6 | Fixed | RHSA-2024:0337 |
| Red Hat Advanced Cluster Security 4.2 | advanced-cluster-security/rhacs-scanner-db-slim-rhel8:4.2.4-7 | Fixed | RHSA-2024:0337 |
| Red Hat Enterprise Linux 8 | postgresql:12-8090020231128173330.a75119d5 | Fixed | RHSA-2023:7714 |
| Red Hat Enterprise Linux 8 | postgresql:13-8090020231114113712.a75119d5 | Fixed | RHSA-2023:7581 |
| Red Hat Enterprise Linux 8 | postgresql:15-8090020231114113548.a75119d5 | Fixed | RHSA-2023:7884 |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | postgresql:12-8020020231128165246.4cda2c84 | Fixed | RHSA-2023:7667 |
| Red Hat Enterprise Linux 8.2 Telecommunications Update Service | postgresql:12-8020020231128165246.4cda2c84 | Fixed | RHSA-2023:7667 |
| Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions | postgresql:12-8020020231128165246.4cda2c84 | Fixed | RHSA-2023:7667 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | postgresql:12-8040020231127153301.522a0ee4 | Fixed | RHSA-2023:7694 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | postgresql:13-8040020231127154806.522a0ee4 | Fixed | RHSA-2023:7695 |
| Red Hat Enterprise Linux 8.4 Telecommunications Update Service | postgresql:12-8040020231127153301.522a0ee4 | Fixed | RHSA-2023:7694 |
| Red Hat Enterprise Linux 8.4 Telecommunications Update Service | postgresql:13-8040020231127154806.522a0ee4 | Fixed | RHSA-2023:7695 |
| Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions | postgresql:12-8040020231127153301.522a0ee4 | Fixed | RHSA-2023:7694 |
| Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions | postgresql:13-8040020231127154806.522a0ee4 | Fixed | RHSA-2023:7695 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | postgresql:12-8060020231128165328.ad008a3a | Fixed | RHSA-2023:7666 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | postgresql:13-8060020231114115246.ad008a3a | Fixed | RHSA-2023:7580 |
| Red Hat Enterprise Linux 8.8 Extended Update Support | postgresql:12-8080020231128165335.63b34585 | Fixed | RHSA-2023:7656 |
| Red Hat Enterprise Linux 8.8 Extended Update Support | postgresql:13-8080020231114105206.63b34585 | Fixed | RHSA-2023:7579 |
| Red Hat Enterprise Linux 8.8 Extended Update Support | postgresql:15-8080020231113134015.63b34585 | Fixed | RHSA-2023:7883 |
| Red Hat Enterprise Linux 9 | postgresql-0:13.13-1.el9_3 | Fixed | RHSA-2023:7784 |
| Red Hat Enterprise Linux 9 | postgresql:15-9030020231120082734.rhel9 | Fixed | RHSA-2023:7785 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | postgresql-0:13.13-1.el9_0 | Fixed | RHSA-2023:7545 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | postgresql-0:13.13-1.el9_2 | Fixed | RHSA-2023:7616 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | postgresql:15-9020020231115020618.rhel9 | Fixed | RHSA-2023:7885 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-postgresql12-postgresql-0:12.17-1.el7 | Fixed | RHSA-2023:7770 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-postgresql13-postgresql-0:13.13-1.el7 | Fixed | RHSA-2023:7772 |
| Red Hat Enterprise Linux 6 | postgresql | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | postgresql | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | postgresql:10/postgresql | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | postgresql:16/postgresql | Not affected | n/a |
| Red Hat Enterprise Linux 9 | postgresql:16/postgresql | Not affected | n/a |
| Red Hat Software Collections | rh-postgresql10-postgresql | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Red Hat statement
Although the NVD assigns this issue a Moderate rating, Red Hat classifies it as Low severity because the practical impact is limited and requires multiple specific conditions. The vulnerability allows a privileged database role (pg_signal_backend) to send signals to certain background worker processes. However, PostgreSQL’s core background workers are designed to safely handle such signals and automatically recover without disrupting the database service. For a denial-of-service condition to occur, the system must be running a non-core extension that introduces a custom background worker which is not designed to restart safely after receiving a signal. In other words, the issue does not affect standard PostgreSQL installations and only impacts specialized configurations using third-party extensions. Even in affected scenarios, the impact is limited to disruption of a specific auxiliary background task and does not result in complete database failure, data loss, or compromise of confidentiality or integrity. Because exploitation requires a high-privileged user and affects only certain non-default configurations with limited operational impact, Red Hat considers the real-world risk to be Low.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H
1 other source (Red Hat) ▾
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Dec 19, 2023 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2023–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (10 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 2.56% (0.02555) | 84.50th | v5 (v2026.06.15) |
| Jun 15, 2026 | 2.56% (0.02555) | 82.97th | v5 (v2026.06.15) |
| Nov 21, 2025 | 0.65% (0.00645) | 69.92th | v4 (v2025.03.14) |
| Nov 18, 2025 | 6.00% (0.06005) | 89.77th | v4 (v2025.03.14) |
| Apr 15, 2025 | 0.49% (0.00489) | 64.15th | v4 (v2025.03.14) |
| Mar 19, 2025 | 6.00% (0.06005) | 89.49th | v4 (v2025.03.14) |
| Mar 17, 2025 | 7.22% (0.07221) | 90.95th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.14% (0.00136) | 50.65th | v3 (v2023.03.01) |
| Dec 14, 2023 | 0.12% (0.00120) | 45.91th | v3 (v2023.03.01) |
| Dec 11, 2023 | 0.05% (0.00046) | 12.90th | v3 (v2023.03.01) |
References (29)
- https://access.redhat.com/errata/RHSA-2023:7545 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2023:7579 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2023:7580 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2023:7581 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2023:7616 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2023:7656 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2023:7666 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2023:7667 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2023:7694 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2023:7695 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2023:7714 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2023:7770 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2023:7772 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2023:7784 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2023:7785 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2023:7883 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2023:7884 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2023:7885 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:0304 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:0332 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:0337 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2023-5870 vdb-entryx_refsource_REDHATThird Party AdvisoryVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2247170 issue-trackingx_refsource_REDHATIssue Tracking
- https://lists.debian.org/debian-lts-announce/2023/11/msg00007.html
- https://nvd.nist.gov/vuln/detail/CVE-2023-5870
- https://security.netapp.com/advisory/ntap-20240119-0003/
- https://www.cve.org/CVERecord?id=CVE-2023-5870
- https://www.postgresql.org/about/news/postgresql-161-155-1410-1313-1217-and-1122-released-2749/ Release Notes
- https://www.postgresql.org/support/security/CVE-2023-5870/ Vendor Advisory
Change history (0)
No recorded changes yet.