Release date:
2026-09-24 16:14:54 UTC
Description:
* SECURITY UPDATE: unrestricted library load during logical decoding, where a user holding the REPLICATION privilege could execute arbitrary code as the operating system user running the database by naming any shared library as the output plugin of a logical replication slot, because output plugin paths were never subject to the LOAD-time restrictions that apply to library loading elsewhere
- debian/patches/CVE-2026-6471.patch: add an output_plugin_libraries GUC
defaulting to "pgoutput, test_decoding" in
src/backend/utils/misc/guc.c, src/include/replication/logical.h and
src/backend/utils/misc/postgresql.conf.sample, check the requested
plugin name against that list in StartupDecodingContext() before
calling LoadOutputPlugin() and reject anything else with "library
... may not be used as an output plugin" in
src/backend/replication/logical/logical.c, quote the new list
parameter correctly in src/bin/pg_dump/dumputils.c, document it in
doc/src/sgml/config.sgml and doc/src/sgml/logical-replication.sgml and
extend the tests in contrib/test_decoding and
src/test/subscription/t/100_bugs.pl. Note that third-party output
plugins other than pgoutput and test_decoding must now be added to
output_plugin_libraries before they can be used
- CVE-2026-6471
* SECURITY UPDATE: integer overflow in the Levenshtein distance functions, where any user could produce nonsensical results or, via levenshtein_less_equal(), trigger out-of-bounds writes, because levenshtein() and levenshtein_less_equal() accept arbitrary 32-bit insertion, deletion and substitution costs but computed the distance with 32-bit arithmetic
- debian/patches/CVE-2026-15742.patch: widen the prev and curr row
arrays and the per-operation costs to int64 and compute the distance
in 64-bit arithmetic throughout varstr_levenshtein() in
src/backend/utils/adt/levenshtein.c, add a levenshtein_result() helper
in src/backend/utils/adt/varlena.c that raises
ERRCODE_NUMERIC_VALUE_OUT_OF_RANGE with "levenshtein distance out of
range" when the result does not fit in the returned int32, route every
return through it, and cover the overflow cases in
contrib/fuzzystrmatch/sql/fuzzystrmatch.sql and
contrib/fuzzystrmatch/expected/fuzzystrmatch.out
- CVE-2026-15742
* SECURITY UPDATE: type confusion via arguments and results of type internal, where any user could execute arbitrary code as the operating system user running the database by calling a function that takes or returns type internal, because type internal stands for a class of mutually incompatible data structures that are not meant to be reachable from SQL and the checks that were supposed to prevent such calls had gaps
- debian/patches/CVE-2026-14680.patch: reject casting to or from type
internal in can_coerce_type() and find_coercion_pathway() in
src/backend/parser/parse_coerce.c, reject resolved argument and result
types of internal in ParseFuncOrColumn() in
src/backend/parser/parse_func.c and in make_op() in
src/backend/parser/parse_oper.c, refuse the I/O coercion fallback for
internal in get_cast_hashentry() in src/pl/plpgsql/src/pl_exec.c, and,
as defence in depth, make numeric_combine(), numeric_avg_combine(),
numeric_poly_combine() and int8_avg_combine() return a real SQL NULL
instead of an unmarked null pointer in
src/backend/utils/adt/numeric.c
- CVE-2026-14680
* SECURITY UPDATE: type confusion between the outer and inner portal of an EXECUTE or FETCH statement, where any user could disclose server memory contents and execute arbitrary code as the operating system user running the database, because nothing checked that the portal created for the EXECUTE or FETCH statement and the portal for the statement being run on its behalf agreed on the tuple descriptor of the rows being returned
- debian/patches/CVE-2026-16239.patch: extend the tuplestore
DestReceiver with an optional target tuple descriptor and mapping
failure message in src/include/executor/tstoreReceiver.h and
src/backend/executor/tstoreReceiver.c, so that it builds a conversion
map with convert_tuples_by_position() and raises an error when the
executor output does not match, update the caller in
PersistHoldablePortal() in src/backend/commands/portalcmds.c, and pass
portal->tupDesc together with "query result type does not match portal
result type" from FillPortalStore() in src/backend/tcop/pquery.c
- CVE-2026-16239
Updated packages:
-
libecpg-compat3-11_11.22-1~bookworm+tuxcare.els17_amd64.deb
sha:ecfb5316cb1ca682ae85f14c39ffa717aeda0af8
-
libecpg-dev-11_11.22-1~bookworm+tuxcare.els17_amd64.deb
sha:f1df7d8cb8ab167c7039f5a60f3eaefb0147560d
-
libecpg6-11_11.22-1~bookworm+tuxcare.els17_amd64.deb
sha:e31d85d27c8d9e656371839e2b50af1081e2b960
-
libpgtypes3-11_11.22-1~bookworm+tuxcare.els17_amd64.deb
sha:0156b5fc42b5cdc1d4584893ea8c6885aba4f78d
-
libpq-dev-11_11.22-1~bookworm+tuxcare.els17_amd64.deb
sha:826ce15dce37f9cd19e0cad332833d0d4bea29dc
-
libpq5-11_11.22-1~bookworm+tuxcare.els17_amd64.deb
sha:dff8d9865b606ccbc2242a60de9e5b13e42d4129
-
postgresql11_11.22-1~bookworm+tuxcare.els17_amd64.deb
sha:c75b8585477ba6e3ea85b83f59b65051f8eefa27
-
postgresql11-client_11.22-1~bookworm+tuxcare.els17_amd64.deb
sha:de9d5c0ebbd0f186cdc182839861ee173bb2b20e
-
postgresql11-doc_11.22-1~bookworm+tuxcare.els17_all.deb
sha:5f8a2b8e4f28dd782fd96c41938f4e4a555a3682
-
postgresql11-plperl_11.22-1~bookworm+tuxcare.els17_amd64.deb
sha:da056f4b1eeebba3bbaf5632db2443171716d4d2
-
postgresql11-plpython3_11.22-1~bookworm+tuxcare.els17_amd64.deb
sha:1ca2f6641eefeeef382f686f7ad1d102734021a1
-
postgresql11-pltcl_11.22-1~bookworm+tuxcare.els17_amd64.deb
sha:a7134cfc17426d1df4ac8278c83d6bc8bd573be3
-
postgresql11-server-dev_11.22-1~bookworm+tuxcare.els17_amd64.deb
sha:882712e85dcc176c89fa1a17473572aaf507fa89
-
libecpg-compat3-11_11.22-1~bookworm+tuxcare.els17_arm64.deb
sha:1588e89124392680f8d7948c4b29d9dd9805b322
-
libecpg-dev-11_11.22-1~bookworm+tuxcare.els17_arm64.deb
sha:8c2b042dac5a8293e47c7cfe9cab4351e7e8de85
-
libecpg6-11_11.22-1~bookworm+tuxcare.els17_arm64.deb
sha:42268e084f7595a3c61e625790b5a0fab272e0b2
-
libpgtypes3-11_11.22-1~bookworm+tuxcare.els17_arm64.deb
sha:436f63ffaa39cbcd36001dc0505ea9d6cf30edc0
-
libpq-dev-11_11.22-1~bookworm+tuxcare.els17_arm64.deb
sha:8e8b16b3c3f6a036d9efdd45954a7b47329f90ca
-
libpq5-11_11.22-1~bookworm+tuxcare.els17_arm64.deb
sha:019bea22807d65ca191856228f07a952fc1a4ece
-
postgresql11_11.22-1~bookworm+tuxcare.els17_arm64.deb
sha:b7bc76aa117ff21100b5c96f50ff3aab495469bc
-
postgresql11-client_11.22-1~bookworm+tuxcare.els17_arm64.deb
sha:caeaffe8ec6d88c81e359aa3ebfdf195caebefd0
-
postgresql11-plperl_11.22-1~bookworm+tuxcare.els17_arm64.deb
sha:440eb68c9a6f0e8fa6c21f87e70a4eab86b59a24
-
postgresql11-plpython3_11.22-1~bookworm+tuxcare.els17_arm64.deb
sha:c377643ff8e0cd9ac6a66526623b51dd75b54e56
-
postgresql11-pltcl_11.22-1~bookworm+tuxcare.els17_arm64.deb
sha:f730a35c15ca016a43f73bcf4a805985e13603aa
-
postgresql11-server-dev_11.22-1~bookworm+tuxcare.els17_arm64.deb
sha:3d3d83b74764ce0f729e4bfa03b4dcd01699c84e
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.