CVE-2023-2455: Row security policies disregard user ID changes after inlining. Versions Affected: 11 - 15. This problem is quite old. While CVE-2016-2193 fixed most interaction between row security and user ID changes, it missed a scenario involving function inlining. This leads to potentially incorrect policies being applied in cases where role-specific policies are used and a given query is planned under one role and then executed under other roles. This scenario can happen under security definer functions or when a common user and query is planned initially and then re-used across multiple SET ROLEs. Applying an incorrect policy may permit a user to complete otherwise-forbidden reads and modifications. This affects only databases that have used CREATE POLICY to define a row security policy. http://www.postgresql.org/support/security/CVE-2023-2455/
Created mingw-postgresql tracking bugs for this issue: Affects: fedora-all [bug 2207582] Created postgresql tracking bugs for this issue: Affects: fedora-all [bug 2207580] Created postgresql:10/postgresql tracking bugs for this issue: Affects: fedora-all [bug 2207584] Created postgresql:11/postgresql tracking bugs for this issue: Affects: fedora-all [bug 2207586] Created postgresql:12/postgresql tracking bugs for this issue: Affects: fedora-all [bug 2207587] Created postgresql:13/postgresql tracking bugs for this issue: Affects: fedora-all [bug 2207588] Created postgresql:14/postgresql tracking bugs for this issue: Affects: fedora-all [bug 2207589] Created postgresql:15/postgresql tracking bugs for this issue: Affects: fedora-all [bug 2207590]
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2023:3714 http://access.redhat.com/errata/RHSA-2023:3714
This issue has been addressed in the following products: Red Hat Software Collections for Red Hat Enterprise Linux 7 Via RHSA-2023:4313 http://access.redhat.com/errata/RHSA-2023:4313
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2023:4327 http://access.redhat.com/errata/RHSA-2023:4327
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2023:4527 http://access.redhat.com/errata/RHSA-2023:4527
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2023:4535 http://access.redhat.com/errata/RHSA-2023:4535
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2023:4539 http://access.redhat.com/errata/RHSA-2023:4539
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2023:5269 http://access.redhat.com/errata/RHSA-2023:5269
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Extended Update Support Via RHSA-2023:7545 http://access.redhat.com/errata/RHSA-2023:7545
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Extended Update Support Via RHSA-2023:7580 http://access.redhat.com/errata/RHSA-2023:7580
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Advanced Update Support Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions Red Hat Enterprise Linux 8.2 Telecommunications Update Service Via RHSA-2023:7667 http://access.redhat.com/errata/RHSA-2023:7667
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Extended Update Support Via RHSA-2023:7666 http://access.redhat.com/errata/RHSA-2023:7666
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions Red Hat Enterprise Linux 8.4 Telecommunications Update Service Via RHSA-2023:7694 http://access.redhat.com/errata/RHSA-2023:7694
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions Red Hat Enterprise Linux 8.4 Telecommunications Update Service Via RHSA-2023:7695 http://access.redhat.com/errata/RHSA-2023:7695
This issue has been addressed in the following products: Red Hat Software Collections for Red Hat Enterprise Linux 7 Via RHSA-2023:7772 http://access.redhat.com/errata/RHSA-2023:7772