Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2024-27304

Publication date 6 March 2024

Last updated 24 July 2024


Ubuntu priority

pgx is a PostgreSQL driver and toolkit for Go. SQL injection can occur if an attacker can cause a single query or bind message to exceed 4 GB in size. An integer overflow in the calculated message size can cause the one large message to be sent as multiple messages under the attacker's control. The problem is resolved in v4.18.2 and v5.5.4. As a workaround, reject user input large enough to cause a single query or bind message to exceed 4 GB in size.

Status

Package Ubuntu Release Status
golang-github-jackc-pgproto3 24.04 LTS noble
Needs evaluation
23.10 mantic Ignored
22.04 LTS jammy Not in release
20.04 LTS focal Not in release
golang-github-jackc-pgx 24.04 LTS noble
Needs evaluation
23.10 mantic Ignored
22.04 LTS jammy
Needs evaluation
20.04 LTS focal Not in release

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
golang-github-jackc-pgproto3
golang-github-jackc-pgx