76e0bb86-b4cb-11eb-b9c9-6cc21735f730PostgreSQL -- Memory disclosure in partitioned-table UPDATE ... RETURNING

The PostgreSQL project reports:

Using an UPDATE ... RETURNING on a purpose-crafted partitioned table, an attacker can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can create prerequisite objects and complete this attack at will. A user lacking the CREATE and TEMPORARY privileges on all databases and the CREATE privilege on all schemas typically cannot use this attack at will.

Discovery 2021-05-13
Entry 2021-05-14
lt 13.3

lt 12.7

lt 11.12