[CLSA-2026:1790238386] Fix of 10 CVEs
Type:
security
Severity:
Critical
Release date:
2026-09-24 08:26:45 UTC
Description:
* SECURITY UPDATE: arbitrary code execution as the server operating system user via type confusion in functions that take or return the "internal" pseudo-type, which the parser failed to block from SQL level calls - debian/patches/CVE-2026-14680.patch: reject INTERNALOID in can_coerce_type() and find_coercion_pathway(), raise an error when a function or operator accepts or returns internal in ParseFuncOrColumn() and make_op(), and refuse an I/O coercion to or from internal in get_cast_hashentry(), in src/backend/parser/parse_coerce.c, parse_func.c, parse_oper.c and src/pl/plpgsql/src/pl_exec.c - CVE-2026-14680 * SECURITY UPDATE: out of bounds write on 32-bit builds of plperl and pltcl where an object creator can wrap the size_t multiplication of an allocation and undersize it via a crafted function body - debian/patches/CVE-2026-14677.patch: route every element count times element size allocation through palloc_array(), palloc0_array(), palloc0_object() and the add_size()/mul_size() overflow guards, in src/pl/plperl/SPI.xs, src/pl/plperl/plperl.c and src/pl/tcl/pltcl.c - CVE-2026-14677 * SECURITY UPDATE: arbitrary code execution as the server operating system user via type confusion in the refint contrib module, whose plan cache reused a saved plan keyed only by trigger name and relation - debian/patches/CVE-2026-14671.patch: remove the refint plan cache entirely, dropping the EPlan struct, the FPlans and PPlans statics and find_plan(), and prepare the plan on every invocation into SPI context memory, in contrib/spi/refint.c plus the matching regression test updates in src/test/regress/sql/triggers.sql and expected/triggers.out - CVE-2026-14671 * SECURITY UPDATE: heap buffer overflow when a plperl function returns a "tied" Perl hash or array whose reported length changes between the count and the iteration - debian/patches/CVE-2026-14670.patch: stop trusting hv_iterinit() in plperl_to_hstore() by starting from a guessed capacity and growing the pairs array with repalloc_array() while passing the real filled count to hstoreUniquePairs(), and read the caller supplied dims[cur_depth - 1] instead of calling av_len() a second time in array_to_datum_internal(); additionally backport the follow-up hardening that stops plperl_func_handler() from looping forever on a tied array returned by a SETOF function by counting with av_count() and bounding it through the new av_count_limit() overflow guard, and that defends every plperl module against NULL "SV *" pointers returned by tied hashes and arrays, in contrib/hstore_plperl/hstore_plperl.c, contrib/jsonb_plperl/jsonb_plperl.c and src/pl/plperl/plperl.c - CVE-2026-14670 * SECURITY UPDATE: server memory disclosure through the ctid selectivity estimator, which dereferenced an arbitrary constant as an ItemPointer when an object creator supplied a non-ctid input - debian/patches/CVE-2026-14668.patch: require consttype == TIDOID before taking the SelfItemPointerAttributeNumber fast path in scalarineqsel(), in src/backend/utils/adt/selfuncs.c - CVE-2026-14668
Updated packages:
  • libecpg-compat3-12_12.22-2~trixie+tuxcare.els13_amd64.deb
    sha:2082e304844f043eaa7902101b518d3b415d1d34
  • libecpg-dev-12_12.22-2~trixie+tuxcare.els13_amd64.deb
    sha:57ba97e8ab76fc837300d92ebc45e1e7e7b554dc
  • libecpg6-12_12.22-2~trixie+tuxcare.els13_amd64.deb
    sha:0ed55009e2ec071b0e291b5d9b0327835f9aa6ca
  • libpgtypes3-12_12.22-2~trixie+tuxcare.els13_amd64.deb
    sha:972717e82d76647737a421d652e3ce9081881e9d
  • libpq-dev-12_12.22-2~trixie+tuxcare.els13_amd64.deb
    sha:da4b6e4f77a1ce0da173a27ac8fca67d1e2dcbea
  • libpq5-12_12.22-2~trixie+tuxcare.els13_amd64.deb
    sha:65c50402556835ccc785c6a3979552e018cc7498
  • postgresql12_12.22-2~trixie+tuxcare.els13_amd64.deb
    sha:13e4b89f81150efe08011e976da76a088a9a814b
  • postgresql12-client_12.22-2~trixie+tuxcare.els13_amd64.deb
    sha:1403c20ad257feee3ca0061b4c0751c6dcd24fa0
  • postgresql12-doc_12.22-2~trixie+tuxcare.els13_all.deb
    sha:58c71460254429ad85fcaeabe0a8de4685635e0b
  • postgresql12-plperl_12.22-2~trixie+tuxcare.els13_amd64.deb
    sha:0d6f1ba146debcd4ea9fcef16bd1806ae1ccd9ce
  • postgresql12-plpython3_12.22-2~trixie+tuxcare.els13_amd64.deb
    sha:56d1f70c10e78ccad4f195109b635176d3b5c4f0
  • postgresql12-pltcl_12.22-2~trixie+tuxcare.els13_amd64.deb
    sha:afbbf03924d39539928984ea6b4c630fccc1014d
  • postgresql12-server-dev_12.22-2~trixie+tuxcare.els13_amd64.deb
    sha:c58057d28aaebac8c032210b7a8fe26b708f52dd
  • libecpg-compat3-12_12.22-2~trixie+tuxcare.els13_arm64.deb
    sha:dbabc2d052e16a4dd2144ca93cd3a41068ce20af
  • libecpg-dev-12_12.22-2~trixie+tuxcare.els13_arm64.deb
    sha:5eaa435b32730258d4b8a26dd324da78d530733f
  • libecpg6-12_12.22-2~trixie+tuxcare.els13_arm64.deb
    sha:289563b7f9f0dc6b44cc6e97173658fece0ee2ac
  • libpgtypes3-12_12.22-2~trixie+tuxcare.els13_arm64.deb
    sha:3cd6c561056061057c2383994ce2b147c996a08e
  • libpq-dev-12_12.22-2~trixie+tuxcare.els13_arm64.deb
    sha:f46ac27cbf6d7f2d737c34af5b351fd3a2ee2ef8
  • libpq5-12_12.22-2~trixie+tuxcare.els13_arm64.deb
    sha:272da4c6aed5a2dd58166963f8325e82657bbfb4
  • postgresql12_12.22-2~trixie+tuxcare.els13_arm64.deb
    sha:1bfe2f823dba400047a22ce693a0f72db6217403
  • postgresql12-client_12.22-2~trixie+tuxcare.els13_arm64.deb
    sha:21168285c4b7abf163d1fd88436a354dae44fe7a
  • postgresql12-plperl_12.22-2~trixie+tuxcare.els13_arm64.deb
    sha:005c9c39b9d97f0c104b9f47a37f9a00c82aba3a
  • postgresql12-plpython3_12.22-2~trixie+tuxcare.els13_arm64.deb
    sha:7c7a93e95f4ae6f0184361ffed13103a8156f03d
  • postgresql12-pltcl_12.22-2~trixie+tuxcare.els13_arm64.deb
    sha:72ba75085e10e904eca21dfd3bde09569900cc74
  • postgresql12-server-dev_12.22-2~trixie+tuxcare.els13_arm64.deb
    sha:e0bdb80225e44f0bb16b949bc70934f983b1785d
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.