CVE-2017-15098: Debian Linux
High severity, CVSS 8.1. EPSS: 3.7% chance of exploitation in the next 30 days.
Invalid json_populate_recordset or jsonb_populate_recordset function calls in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, 9.5.x before 9.5.10, 9.4.x before 9.4.15, and 9.3.x before 9.3.20 can crash the server or disclose a few bytes of server memory.
Affected products
- Debian Debian Linux: version 8.0 only
- PostgreSQL PostgreSQL: version 9.3 only; version 9.3.1 only; version 9.3.2 only; version 9.3.3 only; version 9.3.4 only; version 9.3.5 only; …
Published 2017-11-22. Last modified 2026-06-17.