Late privilege drop in REFRESH MATERIALIZED VIEW CONCURRENTLY in PostgreSQL allows an object creator to execute arbitrary SQL functions as the command issuer. The command intends to run SQL functions as the owner of the materialized view, enabling safe refresh of untrusted materialized views. The victim is a superuser or member of one of the attacker's roles. The attack requires luring the victim into running REFRESH MATERIALIZED VIEW CONCURRENTLY on the attacker's materialized view. Versions before PostgreSQL 16.2, 15.6, 14.11, 13.14, and 12.18 are affected.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3764-1 | postgresql-11 security update |
Debian DSA |
DSA-5622-1 | postgresql-13 security update |
Debian DSA |
DSA-5623-1 | postgresql-15 security update |
EUVD |
EUVD-2024-16762 | Late privilege drop in REFRESH MATERIALIZED VIEW CONCURRENTLY in PostgreSQL allows an object creator to execute arbitrary SQL functions as the command issuer. The command intends to run SQL functions as the owner of the materialized view, enabling safe refresh of untrusted materialized views. The victim is a superuser or member of one of the attacker's roles. The attack requires luring the victim into running REFRESH MATERIALIZED VIEW CONCURRENTLY on the attacker's materialized view. Versions before PostgreSQL 16.2, 15.6, 14.11, 13.14, and 12.18 are affected. |
Ubuntu USN |
USN-6656-1 | PostgreSQL vulnerability |
Ubuntu USN |
USN-6656-2 | PostgreSQL vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
Use REFRESH MATERIALIZED VIEW without CONCURRENTLY.
References
History
Fri, 13 Jun 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 20 Dec 2024 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: PostgreSQL
Published:
Updated: 2025-06-13T15:09:30.114Z
Reserved: 2024-01-27T20:47:02.113Z
Link: CVE-2024-0985
Updated: 2024-12-20T13:06:41.461Z
Status : Modified
Published: 2024-02-08T13:15:08.927
Modified: 2024-12-20T13:15:19.070
Link: CVE-2024-0985
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA
EUVD
Ubuntu USN