Updated postgresql18 & postgresql15 packages fix security vulnerabilities
Publication date: 31 Aug 2026Modification date: 31 Aug 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-6464 , CVE-2026-6469 , CVE-2026-6470 , CVE-2026-6471 , CVE-2026-14662 , CVE-2026-14663 , CVE-2026-14664 , CVE-2026-14666 , CVE-2026-14668 , CVE-2026-14669 , CVE-2026-14670 , CVE-2026-14671 , CVE-2026-14672 , CVE-2026-14673 , CVE-2026-14676 , CVE-2026-14677 , CVE-2026-14678 , CVE-2026-14679 , CVE-2026-14680 , CVE-2026-14681 , CVE-2026-15741 , CVE-2026-15742 , CVE-2026-16238 , CVE-2026-16239 , CVE-2026-16241 , CVE-2026-18024 , CVE-2026-18408 , CVE-2026-19385
Description
psql COPY FROM STDIN early failure processes data lines as psql
commands. (CVE-2026-6464)
ALTER TABLE ALTER TYPE resets extended statistics ownership.
(CVE-2026-6469)
Fails to check type USAGE privilege. (CVE-2026-6470)
Logical decoding can dlopen arbitrary file. (CVE-2026-6471)
tsvector and tsquery undersize allocations, via integer wraparound.
(CVE-2026-14662)
pgcrypto, for OpenSSL-disabled ciphers, silently encrypts to and
decrypts from cleartext. (CVE-2026-14663)
Regexp heap buffer overflow executes arbitrary code. (CVE-2026-14664)
Row security caching disregards role modifications. (CVE-2026-14666)
ctid type confusion in selectivity estimator discloses derivative of
arbitrary read. (CVE-2026-14668)
to_char heap buffer overflow executes arbitrary code. (CVE-2026-14669)
plperl tied object heap buffer overflow executes arbitrary code.
(CVE-2026-14670)
refint plan cache type confusion executes arbitrary code.
(CVE-2026-14671)
Observable response discrepancy with non-default scram_iterations
provides user existence oracle. (CVE-2026-14672)
amcheck does not clear untrusted search path. (CVE-2026-14673)
pg_stat_statements heap buffer overflow executes arbitrary code.
(CVE-2026-14676)
32-bit pltcl and plperl undersize allocations, via integer wraparound.
(CVE-2026-14677)
pg_trgm picksplit reads past end of buffer. (CVE-2026-14678)
Stack buffer overflow in argument match writes 0x0 and 0x1 to server
memory. (CVE-2026-14679)
Type confusion via "internal" arguments. (CVE-2026-14680)
Improper enforcement of GSSAPI encryption when coupled with SSL.
(CVE-2026-14681)
Expression deparse allows SQL injection via EXTRACT argument.
(CVE-2026-15741)
fuzzystrmatch writes effectively-arbitrary addresses, via integer
wraparound. (CVE-2026-15742)
Type confusion in pg_restore_attribute_stats() executes arbitrary code.
(CVE-2026-16238)
Type confusion in cursor CLOSE + DECLARE executes arbitrary code.
(CVE-2026-16239)
ECPG integer underflow can crash the client. (CVE-2026-16241)
ascii() function reads past end of buffer. (CVE-2026-18024)
psql \unrestrict lets superuser of pg_dump origin server execute
arbitrary code in psql client. (CVE-2026-18408)
pg_dump heap buffer overflow executes arbitrary code. (CVE-2026-19385)
References
- https://bugs.mageia.org/show_bug.cgi?id=36165
- https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
- https://www.cve.org/CVERecord?id=CVE-2026-6464
- https://www.cve.org/CVERecord?id=CVE-2026-6469
- https://www.cve.org/CVERecord?id=CVE-2026-6470
- https://www.cve.org/CVERecord?id=CVE-2026-6471
- https://www.cve.org/CVERecord?id=CVE-2026-14662
- https://www.cve.org/CVERecord?id=CVE-2026-14663
- https://www.cve.org/CVERecord?id=CVE-2026-14664
- https://www.cve.org/CVERecord?id=CVE-2026-14666
- https://www.cve.org/CVERecord?id=CVE-2026-14668
- https://www.cve.org/CVERecord?id=CVE-2026-14669
- https://www.cve.org/CVERecord?id=CVE-2026-14670
- https://www.cve.org/CVERecord?id=CVE-2026-14671
- https://www.cve.org/CVERecord?id=CVE-2026-14672
- https://www.cve.org/CVERecord?id=CVE-2026-14673
- https://www.cve.org/CVERecord?id=CVE-2026-14676
- https://www.cve.org/CVERecord?id=CVE-2026-14677
- https://www.cve.org/CVERecord?id=CVE-2026-14678
- https://www.cve.org/CVERecord?id=CVE-2026-14679
- https://www.cve.org/CVERecord?id=CVE-2026-14680
- https://www.cve.org/CVERecord?id=CVE-2026-14681
- https://www.cve.org/CVERecord?id=CVE-2026-15741
- https://www.cve.org/CVERecord?id=CVE-2026-15742
- https://www.cve.org/CVERecord?id=CVE-2026-16238
- https://www.cve.org/CVERecord?id=CVE-2026-16239
- https://www.cve.org/CVERecord?id=CVE-2026-16241
- https://www.cve.org/CVERecord?id=CVE-2026-18024
- https://www.cve.org/CVERecord?id=CVE-2026-18408
- https://www.cve.org/CVERecord?id=CVE-2026-19385
SRPMS
10/core
- postgresql18-18.6-1.mga10
- postgresql15-15.19-1.mga10
9/core
- postgresql15-15.19-1.mga9