Release date:
2026-09-24 08:21:25 UTC
Description:
* SECURITY UPDATE: arbitrary code execution as the server operating system
user via type confusion in functions that take or return the "internal"
pseudo-type, which the parser failed to block from SQL level calls
- debian/patches/CVE-2026-14680.patch: reject INTERNALOID in
can_coerce_type() and find_coercion_pathway(), raise an error when a
function or operator accepts or returns internal in ParseFuncOrColumn()
and make_op(), and refuse an I/O coercion to or from internal in
get_cast_hashentry(), in src/backend/parser/parse_coerce.c,
parse_func.c, parse_oper.c and src/pl/plpgsql/src/pl_exec.c
- CVE-2026-14680
* SECURITY UPDATE: out of bounds write on 32-bit builds of plperl and pltcl
where an object creator can wrap the size_t multiplication of an
allocation and undersize it via a crafted function body
- debian/patches/CVE-2026-14677.patch: route every element count times
element size allocation through palloc_array(), palloc0_array(),
palloc0_object() and the add_size()/mul_size() overflow guards, in
src/pl/plperl/SPI.xs, src/pl/plperl/plperl.c and src/pl/tcl/pltcl.c
- CVE-2026-14677
* SECURITY UPDATE: arbitrary code execution as the server operating system
user via type confusion in the refint contrib module, whose plan cache
reused a saved plan keyed only by trigger name and relation
- debian/patches/CVE-2026-14671.patch: remove the refint plan cache
entirely, dropping the EPlan struct, the FPlans and PPlans statics and
find_plan(), and prepare the plan on every invocation into SPI context
memory, in contrib/spi/refint.c plus the matching regression test
updates in src/test/regress/sql/triggers.sql and expected/triggers.out
- CVE-2026-14671
* SECURITY UPDATE: heap buffer overflow when a plperl function returns a
"tied" Perl hash or array whose reported length changes between the
count and the iteration
- debian/patches/CVE-2026-14670.patch: stop trusting hv_iterinit() in
plperl_to_hstore() by starting from a guessed capacity and growing the
pairs array with repalloc_array() while passing the real filled count
to hstoreUniquePairs(), and read the caller supplied
dims[cur_depth - 1] instead of calling av_len() a second time in
array_to_datum_internal(); additionally backport the follow-up
hardening that stops plperl_func_handler() from looping forever on a
tied array returned by a SETOF function by counting with av_count() and
bounding it through the new av_count_limit() overflow guard, and that
defends every plperl module against NULL "SV *" pointers returned by
tied hashes and arrays, in contrib/hstore_plperl/hstore_plperl.c,
contrib/jsonb_plperl/jsonb_plperl.c and src/pl/plperl/plperl.c
- CVE-2026-14670
* SECURITY UPDATE: server memory disclosure through the ctid selectivity
estimator, which dereferenced an arbitrary constant as an ItemPointer
when an object creator supplied a non-ctid input
- debian/patches/CVE-2026-14668.patch: require consttype == TIDOID before
taking the SelfItemPointerAttributeNumber fast path in scalarineqsel(),
in src/backend/utils/adt/selfuncs.c
- CVE-2026-14668
Updated packages:
-
libecpg-compat3-12_12.22-2~bookworm+tuxcare.els13_amd64.deb
sha:1977f4f1f4a28ee58a03366294eed118e95b5bf6
-
libecpg-dev-12_12.22-2~bookworm+tuxcare.els13_amd64.deb
sha:5ab34c750169806be1ab4862dbb79dc830d7ff5b
-
libecpg6-12_12.22-2~bookworm+tuxcare.els13_amd64.deb
sha:2d2f9f3f4cf577d1917548607a777623d264dbe3
-
libpgtypes3-12_12.22-2~bookworm+tuxcare.els13_amd64.deb
sha:583efdf5a9d92d89ac99e934dec1797ff62c5dc2
-
libpq-dev-12_12.22-2~bookworm+tuxcare.els13_amd64.deb
sha:7384fc2e92e75aad49d2a91b76984479d66b00bf
-
libpq5-12_12.22-2~bookworm+tuxcare.els13_amd64.deb
sha:5af0329c30c3befe137db197e30f6a140f64e50e
-
postgresql12_12.22-2~bookworm+tuxcare.els13_amd64.deb
sha:8960010329f705d877d5198147faf3ef1cac4442
-
postgresql12-client_12.22-2~bookworm+tuxcare.els13_amd64.deb
sha:00821e0d7a73e75d4a7c1f049e1ca6c9d38d854e
-
postgresql12-doc_12.22-2~bookworm+tuxcare.els13_all.deb
sha:aaca10e61c035925be82aff603d55d2fa2cba39a
-
postgresql12-plperl_12.22-2~bookworm+tuxcare.els13_amd64.deb
sha:a432dd102325fd8443cae6a102a36a5b8249ed79
-
postgresql12-plpython3_12.22-2~bookworm+tuxcare.els13_amd64.deb
sha:28fa72f5e5e19602bd9f83773652e08dd260b304
-
postgresql12-pltcl_12.22-2~bookworm+tuxcare.els13_amd64.deb
sha:dac534b473f778c041cadd37cff53dbaa979514c
-
postgresql12-server-dev_12.22-2~bookworm+tuxcare.els13_amd64.deb
sha:42547c16fbd8f1f98e450f93491754b924e798da
-
libecpg-compat3-12_12.22-2~bookworm+tuxcare.els13_arm64.deb
sha:f037e22072ab08abce5902b3d9879c18c68f5e04
-
libecpg-dev-12_12.22-2~bookworm+tuxcare.els13_arm64.deb
sha:bea86d8e4772b2eeecf18e4f7ad454afb96f2ede
-
libecpg6-12_12.22-2~bookworm+tuxcare.els13_arm64.deb
sha:f6c14274692f705815954aa382fe6ed6a7b92e3a
-
libpgtypes3-12_12.22-2~bookworm+tuxcare.els13_arm64.deb
sha:c0dbc9d3f1b36b44add48e26f8b1d96d1a0e356f
-
libpq-dev-12_12.22-2~bookworm+tuxcare.els13_arm64.deb
sha:63db9e7039b80ebe934beb5cce7c969e8a77a6d5
-
libpq5-12_12.22-2~bookworm+tuxcare.els13_arm64.deb
sha:bfcff03bb00c8fb11323f370db04f0bdedf237c7
-
postgresql12_12.22-2~bookworm+tuxcare.els13_arm64.deb
sha:66a0830e3b5e32633b6bf2ea492ac298c569752e
-
postgresql12-client_12.22-2~bookworm+tuxcare.els13_arm64.deb
sha:e1501bd7a1abb89234bc5c940476d31019ec0759
-
postgresql12-plperl_12.22-2~bookworm+tuxcare.els13_arm64.deb
sha:7ffc7b237dc9a5f0e6895555dfc67b22e0e88fe5
-
postgresql12-plpython3_12.22-2~bookworm+tuxcare.els13_arm64.deb
sha:f0d7eaf4666fa14fc14e8ff717fd7a6407b01e62
-
postgresql12-pltcl_12.22-2~bookworm+tuxcare.els13_arm64.deb
sha:080d7fdf606fc3943db3b88bf79ea93036c03089
-
postgresql12-server-dev_12.22-2~bookworm+tuxcare.els13_arm64.deb
sha:50548368ad0bddd0608b7c2cd7421f4a010d73b8
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.