[CLSA-2026:1790267104] Fix of 12 CVEs
Type:
security
Severity:
Important
Release date:
2026-09-24 16:25:25 UTC
Description:
* SECURITY UPDATE: out-of-bounds reads in ascii(), where the function assumed the input string was long enough to hold a character of the length implied by its leading byte and relied on assertions to validate the remaining bytes, so crafted invalid multibyte input could read past the end of the string and disclose a few bytes of server memory - debian/patches/CVE-2026-18024.patch: check the character length against the bytes actually left in the input and replace the assertions on the byte values with ereport(ERROR, ...) reports in ascii() in src/backend/utils/adt/oracle_compat.c - CVE-2026-18024 * SECURITY UPDATE: stale cached plans after role changes, where role membership, role attribute and database ownership changes did not invalidate plans whose behaviour depends on the current role, so a cached plan could keep applying row-level security policies as they stood before the change - debian/patches/CVE-2026-14666.patch: add a PlanCacheRoleCallback() that invalidates the role-dependent saved plans and register it on the pg_auth_members, pg_authid and pg_database syscaches from InitPlanCache() in src/backend/utils/cache/plancache.c, and record the current database's syscache hash in cached_db_hash in src/backend/utils/adt/acl.c, exposed through src/include/utils/acl.h, so pg_database changes for other databases are ignored - CVE-2026-14666 * SECURITY UPDATE: silently disabled encryption in the pgcrypto PGP code, where the return value of px_cipher_encrypt() was never checked, so when OpenSSL ran in FIPS mode or without the legacy provider and could not initialise one of the ciphers the PGP code supports, the CFB layer XORed an unencrypted block with the plaintext and left the data effectively unencrypted - debian/patches/CVE-2026-14663.patch: check the px_cipher_encrypt() return value in cfb_process() and give pgp_cfb_create() an ignore_decrypt_cipher_failure argument in contrib/pgcrypto/pgp-cfb.c, pgp-decrypt.c, pgp-encrypt.c, pgp-pubkey.c, pgp.c and pgp.h, and add the ignore-cipher-failure decryption option in contrib/pgcrypto/pgp-pgsql.c so a message written by an already broken encryption can still be stripped back and re-encrypted, with matching doc/src/sgml/pgcrypto.sgml and regression test updates - CVE-2026-14663 * SECURITY UPDATE: out-of-bounds read in the pg_trgm GiST picksplit function, where the CACHESIGN sign field, which is a BITVECP rather than a TRGM, was passed through the GETSIGN() macro whose cast hid the mistake, so the signature size was computed from memory past the end of the buffer, giving bad split decisions or a crash - debian/patches/CVE-2026-14678.patch: pass cache[j].sign straight to sizebitvec() instead of wrapping it in GETSIGN() in gtrgm_picksplit() in contrib/pg_trgm/trgm_gist.c - CVE-2026-14678
Updated packages:
  • libecpg-compat3-11_11.22-1~trixie+tuxcare.els20_amd64.deb
    sha:f16b392b4ef1966f9df508a3767c403cc4a57576
  • libecpg-dev-11_11.22-1~trixie+tuxcare.els20_amd64.deb
    sha:e6663463ff60048a3575627fcee3efde759048ac
  • libecpg6-11_11.22-1~trixie+tuxcare.els20_amd64.deb
    sha:afeb34d2ec4c468edbdb74d28b63b0f5f833197f
  • libpgtypes3-11_11.22-1~trixie+tuxcare.els20_amd64.deb
    sha:f66fccb32fd41ebd3c922a6c5a7731a99bed1192
  • libpq-dev-11_11.22-1~trixie+tuxcare.els20_amd64.deb
    sha:75b03ebde0bc172383537229d190bdc3ffdce501
  • libpq5-11_11.22-1~trixie+tuxcare.els20_amd64.deb
    sha:c49c53eb7a5ae3c0cd5809b582b3f0be0aea73bc
  • postgresql11_11.22-1~trixie+tuxcare.els20_amd64.deb
    sha:26312a22805d9bd672546683d07ea8b3864777e4
  • postgresql11-client_11.22-1~trixie+tuxcare.els20_amd64.deb
    sha:01519f8b90aebe0a7fae19a23a42b5df8319d811
  • postgresql11-doc_11.22-1~trixie+tuxcare.els20_all.deb
    sha:c9af7bd0dc1a997d68125cd3015f178e600d83d2
  • postgresql11-plperl_11.22-1~trixie+tuxcare.els20_amd64.deb
    sha:072082d4c2c2f7d174af8529fa0ad5250482a3c8
  • postgresql11-plpython3_11.22-1~trixie+tuxcare.els20_amd64.deb
    sha:78c5959be100172a3ba941e0f691d8e02a5ccbef
  • postgresql11-pltcl_11.22-1~trixie+tuxcare.els20_amd64.deb
    sha:12d2522b541d473d4188c7c73cf3929a77c395ec
  • postgresql11-server-dev_11.22-1~trixie+tuxcare.els20_amd64.deb
    sha:0d1906a62bb22ad74d0dc2ff57f64d3d0300d5c8
  • libecpg-compat3-11_11.22-1~trixie+tuxcare.els20_arm64.deb
    sha:00fa271b3097e6130b1e7b31903e0b5b113dfa22
  • libecpg-dev-11_11.22-1~trixie+tuxcare.els20_arm64.deb
    sha:b8c9d666895d11d55fb5b9e34a4674a872ebd994
  • libecpg6-11_11.22-1~trixie+tuxcare.els20_arm64.deb
    sha:e81786999003af6ef6482e04edb09ede7458bde1
  • libpgtypes3-11_11.22-1~trixie+tuxcare.els20_arm64.deb
    sha:f8881e98dc84bbfb2c284e4d3acbec9dc11999ff
  • libpq-dev-11_11.22-1~trixie+tuxcare.els20_arm64.deb
    sha:c9dd8fd99ea29ec04f8e31722eaa1abf99be61c5
  • libpq5-11_11.22-1~trixie+tuxcare.els20_arm64.deb
    sha:819cdd51fe85622ca94436bddcb5dbe096c678aa
  • postgresql11_11.22-1~trixie+tuxcare.els20_arm64.deb
    sha:0f9cc33eedd8c48fff358f810f24117c833aca00
  • postgresql11-client_11.22-1~trixie+tuxcare.els20_arm64.deb
    sha:ab64c80ac5d6f95cc61171929c6e6fe07e774392
  • postgresql11-plperl_11.22-1~trixie+tuxcare.els20_arm64.deb
    sha:fbac7ad110c57e9555a28cbf0ef51ad31f449761
  • postgresql11-plpython3_11.22-1~trixie+tuxcare.els20_arm64.deb
    sha:a9728ceea66c5b2f9092281fac82be463050990d
  • postgresql11-pltcl_11.22-1~trixie+tuxcare.els20_arm64.deb
    sha:592d93fe5058458421f040cdd8159c97899e2538
  • postgresql11-server-dev_11.22-1~trixie+tuxcare.els20_arm64.deb
    sha:b18adfff799e6857ad97da3031e312e45a76cad6
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.