Advisories ยป MGASA-2026-0347

Updated postgresql18 & postgresql15 packages fix security vulnerabilities

Publication date: 31 Aug 2026
Modification date: 31 Aug 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-6464 , CVE-2026-6469 , CVE-2026-6470 , CVE-2026-6471 , CVE-2026-14662 , CVE-2026-14663 , CVE-2026-14664 , CVE-2026-14666 , CVE-2026-14668 , CVE-2026-14669 , CVE-2026-14670 , CVE-2026-14671 , CVE-2026-14672 , CVE-2026-14673 , CVE-2026-14676 , CVE-2026-14677 , CVE-2026-14678 , CVE-2026-14679 , CVE-2026-14680 , CVE-2026-14681 , CVE-2026-15741 , CVE-2026-15742 , CVE-2026-16238 , CVE-2026-16239 , CVE-2026-16241 , CVE-2026-18024 , CVE-2026-18408 , CVE-2026-19385

Description

psql COPY FROM STDIN early failure processes data lines as psql
commands. (CVE-2026-6464)
ALTER TABLE ALTER TYPE resets extended statistics ownership.
(CVE-2026-6469)
Fails to check type USAGE privilege. (CVE-2026-6470)
Logical decoding can dlopen arbitrary file. (CVE-2026-6471)
tsvector and tsquery undersize allocations, via integer wraparound.
(CVE-2026-14662)
pgcrypto, for OpenSSL-disabled ciphers, silently encrypts to and
decrypts from cleartext. (CVE-2026-14663)
Regexp heap buffer overflow executes arbitrary code. (CVE-2026-14664)
Row security caching disregards role modifications. (CVE-2026-14666)
ctid type confusion in selectivity estimator discloses derivative of
arbitrary read. (CVE-2026-14668)
to_char heap buffer overflow executes arbitrary code. (CVE-2026-14669)
plperl tied object heap buffer overflow executes arbitrary code.
(CVE-2026-14670)
refint plan cache type confusion executes arbitrary code.
(CVE-2026-14671)
Observable response discrepancy with non-default scram_iterations
provides user existence oracle. (CVE-2026-14672)
amcheck does not clear untrusted search path. (CVE-2026-14673)
pg_stat_statements heap buffer overflow executes arbitrary code.
(CVE-2026-14676)
32-bit pltcl and plperl undersize allocations, via integer wraparound.
(CVE-2026-14677)
pg_trgm picksplit reads past end of buffer. (CVE-2026-14678)
Stack buffer overflow in argument match writes 0x0 and 0x1 to server
memory. (CVE-2026-14679)
Type confusion via "internal" arguments. (CVE-2026-14680)
Improper enforcement of GSSAPI encryption when coupled with SSL.
(CVE-2026-14681)
Expression deparse allows SQL injection via EXTRACT argument.
(CVE-2026-15741)
fuzzystrmatch writes effectively-arbitrary addresses, via integer
wraparound. (CVE-2026-15742)
Type confusion in pg_restore_attribute_stats() executes arbitrary code.
(CVE-2026-16238)
Type confusion in cursor CLOSE + DECLARE executes arbitrary code.
(CVE-2026-16239)
ECPG integer underflow can crash the client. (CVE-2026-16241)
ascii() function reads past end of buffer. (CVE-2026-18024)
psql \unrestrict lets superuser of pg_dump origin server execute
arbitrary code in psql client. (CVE-2026-18408)
pg_dump heap buffer overflow executes arbitrary code. (CVE-2026-19385)
                

References

SRPMS

10/core

9/core