Release date:
2026-09-24 16:20:27 UTC
Description:
* SECURITY UPDATE: out-of-bounds reads in ascii(), where the function assumed the input string was long enough to hold a character of the length implied by its leading byte and relied on assertions to validate the remaining bytes, so crafted invalid multibyte input could read past the end of the string and disclose a few bytes of server memory
- debian/patches/CVE-2026-18024.patch: check the character length against
the bytes actually left in the input and replace the assertions on the
byte values with ereport(ERROR, ...) reports in ascii() in
src/backend/utils/adt/oracle_compat.c
- CVE-2026-18024
* SECURITY UPDATE: stale cached plans after role changes, where role membership, role attribute and database ownership changes did not invalidate plans whose behaviour depends on the current role, so a cached plan could keep applying row-level security policies as they stood before the change
- debian/patches/CVE-2026-14666.patch: add a PlanCacheRoleCallback() that
invalidates the role-dependent saved plans and register it on the
pg_auth_members, pg_authid and pg_database syscaches from
InitPlanCache() in src/backend/utils/cache/plancache.c, and record the
current database's syscache hash in cached_db_hash in
src/backend/utils/adt/acl.c, exposed through src/include/utils/acl.h,
so pg_database changes for other databases are ignored
- CVE-2026-14666
* SECURITY UPDATE: silently disabled encryption in the pgcrypto PGP code, where the return value of px_cipher_encrypt() was never checked, so when OpenSSL ran in FIPS mode or without the legacy provider and could not initialise one of the ciphers the PGP code supports, the CFB layer XORed an unencrypted block with the plaintext and left the data effectively unencrypted
- debian/patches/CVE-2026-14663.patch: check the px_cipher_encrypt()
return value in cfb_process() and give pgp_cfb_create() an
ignore_decrypt_cipher_failure argument in contrib/pgcrypto/pgp-cfb.c,
pgp-decrypt.c, pgp-encrypt.c, pgp-pubkey.c, pgp.c and pgp.h, and add
the ignore-cipher-failure decryption option in
contrib/pgcrypto/pgp-pgsql.c so a message written by an already broken
encryption can still be stripped back and re-encrypted, with matching
doc/src/sgml/pgcrypto.sgml and regression test updates
- CVE-2026-14663
* SECURITY UPDATE: out-of-bounds read in the pg_trgm GiST picksplit function, where the CACHESIGN sign field, which is a BITVECP rather than a TRGM, was passed through the GETSIGN() macro whose cast hid the mistake, so the signature size was computed from memory past the end of the buffer, giving bad split decisions or a crash
- debian/patches/CVE-2026-14678.patch: pass cache[j].sign straight to
sizebitvec() instead of wrapping it in GETSIGN() in gtrgm_picksplit()
in contrib/pg_trgm/trgm_gist.c
- CVE-2026-14678
Updated packages:
-
libecpg-compat3-11_11.22-1~bookworm+tuxcare.els20_amd64.deb
sha:fd21be528c8df3b3fe0c6dc97e60afbca2944db0
-
libecpg-dev-11_11.22-1~bookworm+tuxcare.els20_amd64.deb
sha:0711385c7e98cd25e14d8b54ecee30e2f90bafd5
-
libecpg6-11_11.22-1~bookworm+tuxcare.els20_amd64.deb
sha:f0f2e04ed71cb20736f8a921be66cc6b3690479e
-
libpgtypes3-11_11.22-1~bookworm+tuxcare.els20_amd64.deb
sha:652eb2282377dd80c93f1b5a55acbedb2c047c94
-
libpq-dev-11_11.22-1~bookworm+tuxcare.els20_amd64.deb
sha:cb4bf9cc40ad0ee70fbbcfb59212a7478ae89f30
-
libpq5-11_11.22-1~bookworm+tuxcare.els20_amd64.deb
sha:3729d9cb9546ee9f299c9bae1c3317814feba087
-
postgresql11_11.22-1~bookworm+tuxcare.els20_amd64.deb
sha:5114d84251950aca6fcb7fa8e8ca8b2cdae4baa1
-
postgresql11-client_11.22-1~bookworm+tuxcare.els20_amd64.deb
sha:1e1672c34881abdc67d41bd27d185a15c56048f9
-
postgresql11-doc_11.22-1~bookworm+tuxcare.els20_all.deb
sha:7feae8fe66f40da1815edf0e7064635dd04bc652
-
postgresql11-plperl_11.22-1~bookworm+tuxcare.els20_amd64.deb
sha:1f1989ea8e8d125bcfdb9be151c87a68b530bea0
-
postgresql11-plpython3_11.22-1~bookworm+tuxcare.els20_amd64.deb
sha:8543869690ce8f7741a5d67fa4de5600d40bc75a
-
postgresql11-pltcl_11.22-1~bookworm+tuxcare.els20_amd64.deb
sha:fa2685d9f5e05a569f4794d49f63436cef2d8169
-
postgresql11-server-dev_11.22-1~bookworm+tuxcare.els20_amd64.deb
sha:9a5a92c066ad75487476735cc0eb5a89611ff47e
-
libecpg-compat3-11_11.22-1~bookworm+tuxcare.els20_arm64.deb
sha:8bf61a7d488df2b9a10da71bcb02b8c72ba58dd3
-
libecpg-dev-11_11.22-1~bookworm+tuxcare.els20_arm64.deb
sha:c446b4244c726bfcea5c384661ef1f84ce0e5fd1
-
libecpg6-11_11.22-1~bookworm+tuxcare.els20_arm64.deb
sha:2eda4007ba98f9a1fc81bdd3f9b077cde24e218f
-
libpgtypes3-11_11.22-1~bookworm+tuxcare.els20_arm64.deb
sha:6d76fc6d440a44cfdfbb59656f27fee0e3c145da
-
libpq-dev-11_11.22-1~bookworm+tuxcare.els20_arm64.deb
sha:2a7766231f7c7da367e40afa8a5ec441c360568c
-
libpq5-11_11.22-1~bookworm+tuxcare.els20_arm64.deb
sha:c14d330a18548b0f175e45b00a96463b4bb4ef67
-
postgresql11_11.22-1~bookworm+tuxcare.els20_arm64.deb
sha:595f553a0c104f706a41cd25ed609dc54a5100b9
-
postgresql11-client_11.22-1~bookworm+tuxcare.els20_arm64.deb
sha:f9b5acdf25e86c784b43c06b2f80c6f6651a98d6
-
postgresql11-plperl_11.22-1~bookworm+tuxcare.els20_arm64.deb
sha:e595868d34961aa3e2d6e4c447a786204ff6aeeb
-
postgresql11-plpython3_11.22-1~bookworm+tuxcare.els20_arm64.deb
sha:0e91cfd5c8201e603ae58d4753d8ce34c716e4fb
-
postgresql11-pltcl_11.22-1~bookworm+tuxcare.els20_arm64.deb
sha:36cd53212b3668b65490da61a93d488d08123f3d
-
postgresql11-server-dev_11.22-1~bookworm+tuxcare.els20_arm64.deb
sha:8f9fc26bcb18a9dbf430b267f5eebe901144fd11
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.