CVE-2018-10915: Canonical Ubuntu Linux

High severity, CVSS 7.5. EPSS: 5.2% chance of exploitation in the next 30 days.

A vulnerability was found in libpq, the default PostgreSQL client library where libpq failed to properly reset its internal state between connections. If an affected version of libpq was used with "host" or "hostaddr" connection parameters from untrusted input, attackers could bypass client-side connection security features, obtain access to higher privileged connections or potentially cause other impact through SQL injection, by causing the PQescape() functions to malfunction. Postgresql versions before 10.5, 9.6.10, 9.5.14, 9.4.19, and 9.3.24 are affected.

Affected products

  • Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 18.04 only
  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • PostgreSQL PostgreSQL: from 9.3.0, before 9.3.24 (fixed in 9.3.24); from 9.4.0, before 9.4.19 (fixed in 9.4.19); from 9.5.0, before 9.5.14 (fixed in 9.5.14); from 9.6.0, before 9.6.10 (fixed in 9.6.10); from 10.0, before 10.5 (fixed in 10.5)
  • Red Hat Enterprise Linux Desktop: version 7.0 only
  • Red Hat Enterprise Linux Server: version 7.0 only
  • Red Hat Enterprise Linux Server Eus: version 7.5 only
  • Red Hat Enterprise Linux Workstation: version 7.0 only
  • Red Hat Openstack: version 12 only; version 13 only
  • Red Hat Virtualization: version 4.0 only

Published 2018-08-09. Last modified 2026-06-17.