[CLSA-2026:1790238066] Fix of 10 CVEs
Type:
security
Severity:
Critical
Release date:
2026-09-24 08:21:25 UTC
Description:
* SECURITY UPDATE: arbitrary code execution as the server operating system user via type confusion in functions that take or return the "internal" pseudo-type, which the parser failed to block from SQL level calls - debian/patches/CVE-2026-14680.patch: reject INTERNALOID in can_coerce_type() and find_coercion_pathway(), raise an error when a function or operator accepts or returns internal in ParseFuncOrColumn() and make_op(), and refuse an I/O coercion to or from internal in get_cast_hashentry(), in src/backend/parser/parse_coerce.c, parse_func.c, parse_oper.c and src/pl/plpgsql/src/pl_exec.c - CVE-2026-14680 * SECURITY UPDATE: out of bounds write on 32-bit builds of plperl and pltcl where an object creator can wrap the size_t multiplication of an allocation and undersize it via a crafted function body - debian/patches/CVE-2026-14677.patch: route every element count times element size allocation through palloc_array(), palloc0_array(), palloc0_object() and the add_size()/mul_size() overflow guards, in src/pl/plperl/SPI.xs, src/pl/plperl/plperl.c and src/pl/tcl/pltcl.c - CVE-2026-14677 * SECURITY UPDATE: arbitrary code execution as the server operating system user via type confusion in the refint contrib module, whose plan cache reused a saved plan keyed only by trigger name and relation - debian/patches/CVE-2026-14671.patch: remove the refint plan cache entirely, dropping the EPlan struct, the FPlans and PPlans statics and find_plan(), and prepare the plan on every invocation into SPI context memory, in contrib/spi/refint.c plus the matching regression test updates in src/test/regress/sql/triggers.sql and expected/triggers.out - CVE-2026-14671 * SECURITY UPDATE: heap buffer overflow when a plperl function returns a "tied" Perl hash or array whose reported length changes between the count and the iteration - debian/patches/CVE-2026-14670.patch: stop trusting hv_iterinit() in plperl_to_hstore() by starting from a guessed capacity and growing the pairs array with repalloc_array() while passing the real filled count to hstoreUniquePairs(), and read the caller supplied dims[cur_depth - 1] instead of calling av_len() a second time in array_to_datum_internal(); additionally backport the follow-up hardening that stops plperl_func_handler() from looping forever on a tied array returned by a SETOF function by counting with av_count() and bounding it through the new av_count_limit() overflow guard, and that defends every plperl module against NULL "SV *" pointers returned by tied hashes and arrays, in contrib/hstore_plperl/hstore_plperl.c, contrib/jsonb_plperl/jsonb_plperl.c and src/pl/plperl/plperl.c - CVE-2026-14670 * SECURITY UPDATE: server memory disclosure through the ctid selectivity estimator, which dereferenced an arbitrary constant as an ItemPointer when an object creator supplied a non-ctid input - debian/patches/CVE-2026-14668.patch: require consttype == TIDOID before taking the SelfItemPointerAttributeNumber fast path in scalarineqsel(), in src/backend/utils/adt/selfuncs.c - CVE-2026-14668
Updated packages:
  • libecpg-compat3-12_12.22-2~bookworm+tuxcare.els13_amd64.deb
    sha:1977f4f1f4a28ee58a03366294eed118e95b5bf6
  • libecpg-dev-12_12.22-2~bookworm+tuxcare.els13_amd64.deb
    sha:5ab34c750169806be1ab4862dbb79dc830d7ff5b
  • libecpg6-12_12.22-2~bookworm+tuxcare.els13_amd64.deb
    sha:2d2f9f3f4cf577d1917548607a777623d264dbe3
  • libpgtypes3-12_12.22-2~bookworm+tuxcare.els13_amd64.deb
    sha:583efdf5a9d92d89ac99e934dec1797ff62c5dc2
  • libpq-dev-12_12.22-2~bookworm+tuxcare.els13_amd64.deb
    sha:7384fc2e92e75aad49d2a91b76984479d66b00bf
  • libpq5-12_12.22-2~bookworm+tuxcare.els13_amd64.deb
    sha:5af0329c30c3befe137db197e30f6a140f64e50e
  • postgresql12_12.22-2~bookworm+tuxcare.els13_amd64.deb
    sha:8960010329f705d877d5198147faf3ef1cac4442
  • postgresql12-client_12.22-2~bookworm+tuxcare.els13_amd64.deb
    sha:00821e0d7a73e75d4a7c1f049e1ca6c9d38d854e
  • postgresql12-doc_12.22-2~bookworm+tuxcare.els13_all.deb
    sha:aaca10e61c035925be82aff603d55d2fa2cba39a
  • postgresql12-plperl_12.22-2~bookworm+tuxcare.els13_amd64.deb
    sha:a432dd102325fd8443cae6a102a36a5b8249ed79
  • postgresql12-plpython3_12.22-2~bookworm+tuxcare.els13_amd64.deb
    sha:28fa72f5e5e19602bd9f83773652e08dd260b304
  • postgresql12-pltcl_12.22-2~bookworm+tuxcare.els13_amd64.deb
    sha:dac534b473f778c041cadd37cff53dbaa979514c
  • postgresql12-server-dev_12.22-2~bookworm+tuxcare.els13_amd64.deb
    sha:42547c16fbd8f1f98e450f93491754b924e798da
  • libecpg-compat3-12_12.22-2~bookworm+tuxcare.els13_arm64.deb
    sha:f037e22072ab08abce5902b3d9879c18c68f5e04
  • libecpg-dev-12_12.22-2~bookworm+tuxcare.els13_arm64.deb
    sha:bea86d8e4772b2eeecf18e4f7ad454afb96f2ede
  • libecpg6-12_12.22-2~bookworm+tuxcare.els13_arm64.deb
    sha:f6c14274692f705815954aa382fe6ed6a7b92e3a
  • libpgtypes3-12_12.22-2~bookworm+tuxcare.els13_arm64.deb
    sha:c0dbc9d3f1b36b44add48e26f8b1d96d1a0e356f
  • libpq-dev-12_12.22-2~bookworm+tuxcare.els13_arm64.deb
    sha:63db9e7039b80ebe934beb5cce7c969e8a77a6d5
  • libpq5-12_12.22-2~bookworm+tuxcare.els13_arm64.deb
    sha:bfcff03bb00c8fb11323f370db04f0bdedf237c7
  • postgresql12_12.22-2~bookworm+tuxcare.els13_arm64.deb
    sha:66a0830e3b5e32633b6bf2ea492ac298c569752e
  • postgresql12-client_12.22-2~bookworm+tuxcare.els13_arm64.deb
    sha:e1501bd7a1abb89234bc5c940476d31019ec0759
  • postgresql12-plperl_12.22-2~bookworm+tuxcare.els13_arm64.deb
    sha:7ffc7b237dc9a5f0e6895555dfc67b22e0e88fe5
  • postgresql12-plpython3_12.22-2~bookworm+tuxcare.els13_arm64.deb
    sha:f0d7eaf4666fa14fc14e8ff717fd7a6407b01e62
  • postgresql12-pltcl_12.22-2~bookworm+tuxcare.els13_arm64.deb
    sha:080d7fdf606fc3943db3b88bf79ea93036c03089
  • postgresql12-server-dev_12.22-2~bookworm+tuxcare.els13_arm64.deb
    sha:50548368ad0bddd0608b7c2cd7421f4a010d73b8
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.