PostgreSQL relation replacement during pg_dump executes arbitrary SQL
Published Aug 8, 2024
8.8
HIGHCVSS 3.1
EPSS 1.57%
Description
Time-of-check Time-of-use (TOCTOU) race condition in pg_dump in PostgreSQL allows an object creator to execute arbitrary SQL functions as the user running pg_dump, which is often a superuser. The attack involves replacing another relation type with a view or foreign table. The attack requires waiting for pg_dump to start, but winning the race condition is trivial if the attacker retains an open transaction. Versions before PostgreSQL 16.4, 15.8, 14.13, 13.16, and 12.20 are affected.
Affected products
- Vendor n/a Product PostgreSQL Defaultunaffected
- Version 0StatusaffectedConstraints<12.20
- Version 13StatusaffectedConstraints<13.16
- Version 14StatusaffectedConstraints<14.13
- Version 15StatusaffectedConstraints<15.8
- Version 16StatusaffectedConstraints<16.4
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| n/a | PostgreSQL | unaffected |
|
- ≥ 12.0 · < 12.20
- ≥ 13.0 · < 13.16
- ≥ 14.0 · < 14.13
- ≥ 15.0 · < 15.8
- ≥ 16.0 · < 16.4
-
- Version 0StatusaffectedConstraints<12.20
- Version 13StatusaffectedConstraints<13.16
- Version 14StatusaffectedConstraints<14.13
- Version 15StatusaffectedConstraints<15.8
- Version 16StatusaffectedConstraints<16.4
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| PostgreSQL | PostgreSQL | n/a |
|
Red Hat Enterprise Linux 7 Extended Lifecycle Support
postgresql-0:9.2.24-9.el7_9.1
Fixed · RHSA-2024:8495
Red Hat Enterprise Linux 8
postgresql:12-8100020240814102525.489197e6
Fixed · RHSA-2024:6000
Red Hat Enterprise Linux 8
postgresql:13-8100020240814102212.489197e6
Fixed · RHSA-2024:6018
Red Hat Enterprise Linux 8
postgresql:15-8100020240814101911.489197e6
Fixed · RHSA-2024:6001
Red Hat Enterprise Linux 8
postgresql:16-8100020240814094432.489197e6
Fixed · RHSA-2024:5927
Red Hat Enterprise Linux 8.2 Advanced Update Support
postgresql:12-8020020240828083606.4cda2c84
Fixed · RHSA-2024:6138
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
postgresql:12-8040020240827125019.522a0ee4
Fixed · RHSA-2024:6139
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
postgresql:13-8040020240830114010.522a0ee4
Fixed · RHSA-2024:6557
Red Hat Enterprise Linux 8.4 Telecommunications Update Service
postgresql:12-8040020240827125019.522a0ee4
Fixed · RHSA-2024:6139
Red Hat Enterprise Linux 8.4 Telecommunications Update Service
postgresql:13-8040020240830114010.522a0ee4
Fixed · RHSA-2024:6557
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions
postgresql:12-8040020240827125019.522a0ee4
Fixed · RHSA-2024:6139
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions
postgresql:13-8040020240830114010.522a0ee4
Fixed · RHSA-2024:6557
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
postgresql:12-8060020240903093929.ad008a3a
Fixed · RHSA-2024:6559
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
postgresql:13-8060020240903094008.ad008a3a
Fixed · RHSA-2024:6558
Red Hat Enterprise Linux 8.6 Telecommunications Update Service
postgresql:12-8060020240903093929.ad008a3a
Fixed · RHSA-2024:6559
Red Hat Enterprise Linux 8.6 Telecommunications Update Service
postgresql:13-8060020240903094008.ad008a3a
Fixed · RHSA-2024:6558
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
postgresql:12-8060020240903093929.ad008a3a
Fixed · RHSA-2024:6559
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
postgresql:13-8060020240903094008.ad008a3a
Fixed · RHSA-2024:6558
Red Hat Enterprise Linux 8.8 Extended Update Support
postgresql:12-8080020240828084611.63b34585
Fixed · RHSA-2024:6137
Red Hat Enterprise Linux 8.8 Extended Update Support
postgresql:13-8080020240830064706.63b34585
Fixed · RHSA-2024:6141
Red Hat Enterprise Linux 8.8 Extended Update Support
postgresql:15-8080020240826125709.63b34585
Fixed · RHSA-2024:6142
Red Hat Enterprise Linux 9
postgresql-0:13.16-1.el9_4
Fixed · RHSA-2024:5999
Red Hat Enterprise Linux 9
postgresql:15-9040020240812115436.rhel9
Fixed · RHSA-2024:6020
Red Hat Enterprise Linux 9
postgresql:16-9040020240812093225.rhel9
Fixed · RHSA-2024:5929
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions
postgresql-0:13.16-1.el9_0
Fixed · RHSA-2024:6144
Red Hat Enterprise Linux 9.2 Extended Update Support
postgresql-0:13.16-1.el9_2
Fixed · RHSA-2024:6145
Red Hat Enterprise Linux 9.2 Extended Update Support
postgresql:15-9020020240827093843.rhel9
Fixed · RHSA-2024:6140
Red Hat Enterprise Linux 10
postgresql16
Not affected
Red Hat Enterprise Linux 6
postgresql
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | postgresql-0:9.2.24-9.el7_9.1 | Fixed | RHSA-2024:8495 |
| Red Hat Enterprise Linux 8 | postgresql:12-8100020240814102525.489197e6 | Fixed | RHSA-2024:6000 |
| Red Hat Enterprise Linux 8 | postgresql:13-8100020240814102212.489197e6 | Fixed | RHSA-2024:6018 |
| Red Hat Enterprise Linux 8 | postgresql:15-8100020240814101911.489197e6 | Fixed | RHSA-2024:6001 |
| Red Hat Enterprise Linux 8 | postgresql:16-8100020240814094432.489197e6 | Fixed | RHSA-2024:5927 |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | postgresql:12-8020020240828083606.4cda2c84 | Fixed | RHSA-2024:6138 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | postgresql:12-8040020240827125019.522a0ee4 | Fixed | RHSA-2024:6139 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | postgresql:13-8040020240830114010.522a0ee4 | Fixed | RHSA-2024:6557 |
| Red Hat Enterprise Linux 8.4 Telecommunications Update Service | postgresql:12-8040020240827125019.522a0ee4 | Fixed | RHSA-2024:6139 |
| Red Hat Enterprise Linux 8.4 Telecommunications Update Service | postgresql:13-8040020240830114010.522a0ee4 | Fixed | RHSA-2024:6557 |
| Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions | postgresql:12-8040020240827125019.522a0ee4 | Fixed | RHSA-2024:6139 |
| Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions | postgresql:13-8040020240830114010.522a0ee4 | Fixed | RHSA-2024:6557 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | postgresql:12-8060020240903093929.ad008a3a | Fixed | RHSA-2024:6559 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | postgresql:13-8060020240903094008.ad008a3a | Fixed | RHSA-2024:6558 |
| Red Hat Enterprise Linux 8.6 Telecommunications Update Service | postgresql:12-8060020240903093929.ad008a3a | Fixed | RHSA-2024:6559 |
| Red Hat Enterprise Linux 8.6 Telecommunications Update Service | postgresql:13-8060020240903094008.ad008a3a | Fixed | RHSA-2024:6558 |
| Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | postgresql:12-8060020240903093929.ad008a3a | Fixed | RHSA-2024:6559 |
| Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | postgresql:13-8060020240903094008.ad008a3a | Fixed | RHSA-2024:6558 |
| Red Hat Enterprise Linux 8.8 Extended Update Support | postgresql:12-8080020240828084611.63b34585 | Fixed | RHSA-2024:6137 |
| Red Hat Enterprise Linux 8.8 Extended Update Support | postgresql:13-8080020240830064706.63b34585 | Fixed | RHSA-2024:6141 |
| Red Hat Enterprise Linux 8.8 Extended Update Support | postgresql:15-8080020240826125709.63b34585 | Fixed | RHSA-2024:6142 |
| Red Hat Enterprise Linux 9 | postgresql-0:13.16-1.el9_4 | Fixed | RHSA-2024:5999 |
| Red Hat Enterprise Linux 9 | postgresql:15-9040020240812115436.rhel9 | Fixed | RHSA-2024:6020 |
| Red Hat Enterprise Linux 9 | postgresql:16-9040020240812093225.rhel9 | Fixed | RHSA-2024:5929 |
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | postgresql-0:13.16-1.el9_0 | Fixed | RHSA-2024:6144 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | postgresql-0:13.16-1.el9_2 | Fixed | RHSA-2024:6145 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | postgresql:15-9020020240827093843.rhel9 | Fixed | RHSA-2024:6140 |
| Red Hat Enterprise Linux 10 | postgresql16 | Not affected | n/a |
| Red Hat Enterprise Linux 6 | postgresql | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Satellite PostgreSQL is pulled through a base layered OS product and/or appstream repository and it is not shipped through this offering. This TOCTOU race condition in pg_dump is a important severity issue because it enables a non-privileged database user to escalate their privileges and execute arbitrary SQL functions as the superuser, compromising the entire database system. The exploitation of this vulnerability is particularly dangerous due to the inherent privilege level associated with the pg_dump process, which typically operates with elevated rights to ensure comprehensive backups. The ease of exploitation—due to the trivial nature of winning the race condition by holding an open transaction—further amplifies the risk, making it a significant threat in environments running affected PostgreSQL versions.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (7)
- http://www.openwall.com/lists/oss-security/2024/08/11/1
- https://access.redhat.com/security/cve/CVE-2024-7348 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2303682 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2024-7348
- https://security.netapp.com/advisory/ntap-20240822-0002/
- https://www.cve.org/CVERecord?id=CVE-2024-7348
- https://www.postgresql.org/support/security/CVE-2024-7348/ Vendor Advisory
Change history (0)
No recorded changes yet.