Cloud Foundry Logo
blog single gear
Security Advisory

USN-6104-1: PostgreSQL vulnerabilities




Canonical Ubuntu

Versions Affected

  • Canonical Ubuntu 18.04
  • Canonical Ubuntu 22.04


Alexander Lakhin discovered that PostgreSQL incorrectly handled certain CREATE privileges. An authenticated user could possibly use this issue to execute arbitrary code as the bootstrap supervisor. (CVE-2023-2454) Wolfgang Walther discovered that PostgreSQL incorrectly handled certain row security policies. An authenticated user could possibly use this issue to complete otherwise forbidden reads and modifications. (CVE-2023-2455) Update Instructions: Run `sudo pro fix USN-6104-1` to fix the vulnerability. The problem can be corrected by updating your system to the following package versions: postgresql-server-dev-10 – 10.23-0ubuntu0.18.04.2 postgresql-10 – 10.23-0ubuntu0.18.04.2 libecpg6 – 10.23-0ubuntu0.18.04.2 libpq5 – 10.23-0ubuntu0.18.04.2 libpgtypes3 – 10.23-0ubuntu0.18.04.2 postgresql-pltcl-10 – 10.23-0ubuntu0.18.04.2 postgresql-plperl-10 – 10.23-0ubuntu0.18.04.2 libecpg-dev – 10.23-0ubuntu0.18.04.2 postgresql-plpython3-10 – 10.23-0ubuntu0.18.04.2 libpq-dev – 10.23-0ubuntu0.18.04.2 postgresql-plpython-10 – 10.23-0ubuntu0.18.04.2 postgresql-doc-10 – 10.23-0ubuntu0.18.04.2 postgresql-client-10 – 10.23-0ubuntu0.18.04.2 libecpg-compat3 – 10.23-0ubuntu0.18.04.2 No subscription required

CVEs contained in this USN include: CVE-2023-2454, CVE-2023-2455.

Affected Cloud Foundry Products and Versions

Severity is medium unless otherwise noted.

  • cflinuxfs3
    • All versions prior to 0.369.0
  • cflinuxfs4
    • All versions prior to 1.12.0
  • CF Deployment
    • All versions prior to 30.1.0


Users of affected products are strongly encouraged to follow the mitigations below. The Cloud Foundry project recommends upgrading the following releases:

  • cflinuxfs3
    • Upgrade all versions to 0.369.0 or greater
  • cflinuxfs4
    • Upgrade all versions to 1.12.0 or greater
  • CF Deployment
    • Upgrade all versions to 30.1.0 or greater


2023-06-30: Initial vulnerability report published.

Cloud Foundry Foundation Security Team Profile Image

Cloud Foundry Foundation Security Team, AUTHOR