CVE-2018-16850: Canonical Ubuntu Linux

Critical severity, CVSS 9.8. EPSS: 5.2% chance of exploitation in the next 30 days.

postgresql before versions 11.1, 10.6 is vulnerable to a to SQL injection in pg_upgrade and pg_dump via CREATE TRIGGER ... REFERENCING. Using a purpose-crafted trigger definition, an attacker can cause arbitrary SQL statements to run, with superuser privileges.

Affected products

  • Canonical Ubuntu Linux: version 18.04 only; version 18.10 only
  • PostgreSQL PostgreSQL: from 10.0, before 10.6 (fixed in 10.6); from 11.0, before 11.1 (fixed in 11.1)
  • Red Hat Enterprise Linux: version 7.0 only; version 7.4 only; version 7.5 only; version 7.6 only

Published 2018-11-13. Last modified 2026-06-17.