Release date:
2026-09-24 08:26:45 UTC
Description:
* SECURITY UPDATE: arbitrary code execution as the server operating system
user via type confusion in functions that take or return the "internal"
pseudo-type, which the parser failed to block from SQL level calls
- debian/patches/CVE-2026-14680.patch: reject INTERNALOID in
can_coerce_type() and find_coercion_pathway(), raise an error when a
function or operator accepts or returns internal in ParseFuncOrColumn()
and make_op(), and refuse an I/O coercion to or from internal in
get_cast_hashentry(), in src/backend/parser/parse_coerce.c,
parse_func.c, parse_oper.c and src/pl/plpgsql/src/pl_exec.c
- CVE-2026-14680
* SECURITY UPDATE: out of bounds write on 32-bit builds of plperl and pltcl
where an object creator can wrap the size_t multiplication of an
allocation and undersize it via a crafted function body
- debian/patches/CVE-2026-14677.patch: route every element count times
element size allocation through palloc_array(), palloc0_array(),
palloc0_object() and the add_size()/mul_size() overflow guards, in
src/pl/plperl/SPI.xs, src/pl/plperl/plperl.c and src/pl/tcl/pltcl.c
- CVE-2026-14677
* SECURITY UPDATE: arbitrary code execution as the server operating system
user via type confusion in the refint contrib module, whose plan cache
reused a saved plan keyed only by trigger name and relation
- debian/patches/CVE-2026-14671.patch: remove the refint plan cache
entirely, dropping the EPlan struct, the FPlans and PPlans statics and
find_plan(), and prepare the plan on every invocation into SPI context
memory, in contrib/spi/refint.c plus the matching regression test
updates in src/test/regress/sql/triggers.sql and expected/triggers.out
- CVE-2026-14671
* SECURITY UPDATE: heap buffer overflow when a plperl function returns a
"tied" Perl hash or array whose reported length changes between the
count and the iteration
- debian/patches/CVE-2026-14670.patch: stop trusting hv_iterinit() in
plperl_to_hstore() by starting from a guessed capacity and growing the
pairs array with repalloc_array() while passing the real filled count
to hstoreUniquePairs(), and read the caller supplied
dims[cur_depth - 1] instead of calling av_len() a second time in
array_to_datum_internal(); additionally backport the follow-up
hardening that stops plperl_func_handler() from looping forever on a
tied array returned by a SETOF function by counting with av_count() and
bounding it through the new av_count_limit() overflow guard, and that
defends every plperl module against NULL "SV *" pointers returned by
tied hashes and arrays, in contrib/hstore_plperl/hstore_plperl.c,
contrib/jsonb_plperl/jsonb_plperl.c and src/pl/plperl/plperl.c
- CVE-2026-14670
* SECURITY UPDATE: server memory disclosure through the ctid selectivity
estimator, which dereferenced an arbitrary constant as an ItemPointer
when an object creator supplied a non-ctid input
- debian/patches/CVE-2026-14668.patch: require consttype == TIDOID before
taking the SelfItemPointerAttributeNumber fast path in scalarineqsel(),
in src/backend/utils/adt/selfuncs.c
- CVE-2026-14668
Updated packages:
-
libecpg-compat3-12_12.22-2~trixie+tuxcare.els13_amd64.deb
sha:2082e304844f043eaa7902101b518d3b415d1d34
-
libecpg-dev-12_12.22-2~trixie+tuxcare.els13_amd64.deb
sha:57ba97e8ab76fc837300d92ebc45e1e7e7b554dc
-
libecpg6-12_12.22-2~trixie+tuxcare.els13_amd64.deb
sha:0ed55009e2ec071b0e291b5d9b0327835f9aa6ca
-
libpgtypes3-12_12.22-2~trixie+tuxcare.els13_amd64.deb
sha:972717e82d76647737a421d652e3ce9081881e9d
-
libpq-dev-12_12.22-2~trixie+tuxcare.els13_amd64.deb
sha:da4b6e4f77a1ce0da173a27ac8fca67d1e2dcbea
-
libpq5-12_12.22-2~trixie+tuxcare.els13_amd64.deb
sha:65c50402556835ccc785c6a3979552e018cc7498
-
postgresql12_12.22-2~trixie+tuxcare.els13_amd64.deb
sha:13e4b89f81150efe08011e976da76a088a9a814b
-
postgresql12-client_12.22-2~trixie+tuxcare.els13_amd64.deb
sha:1403c20ad257feee3ca0061b4c0751c6dcd24fa0
-
postgresql12-doc_12.22-2~trixie+tuxcare.els13_all.deb
sha:58c71460254429ad85fcaeabe0a8de4685635e0b
-
postgresql12-plperl_12.22-2~trixie+tuxcare.els13_amd64.deb
sha:0d6f1ba146debcd4ea9fcef16bd1806ae1ccd9ce
-
postgresql12-plpython3_12.22-2~trixie+tuxcare.els13_amd64.deb
sha:56d1f70c10e78ccad4f195109b635176d3b5c4f0
-
postgresql12-pltcl_12.22-2~trixie+tuxcare.els13_amd64.deb
sha:afbbf03924d39539928984ea6b4c630fccc1014d
-
postgresql12-server-dev_12.22-2~trixie+tuxcare.els13_amd64.deb
sha:c58057d28aaebac8c032210b7a8fe26b708f52dd
-
libecpg-compat3-12_12.22-2~trixie+tuxcare.els13_arm64.deb
sha:dbabc2d052e16a4dd2144ca93cd3a41068ce20af
-
libecpg-dev-12_12.22-2~trixie+tuxcare.els13_arm64.deb
sha:5eaa435b32730258d4b8a26dd324da78d530733f
-
libecpg6-12_12.22-2~trixie+tuxcare.els13_arm64.deb
sha:289563b7f9f0dc6b44cc6e97173658fece0ee2ac
-
libpgtypes3-12_12.22-2~trixie+tuxcare.els13_arm64.deb
sha:3cd6c561056061057c2383994ce2b147c996a08e
-
libpq-dev-12_12.22-2~trixie+tuxcare.els13_arm64.deb
sha:f46ac27cbf6d7f2d737c34af5b351fd3a2ee2ef8
-
libpq5-12_12.22-2~trixie+tuxcare.els13_arm64.deb
sha:272da4c6aed5a2dd58166963f8325e82657bbfb4
-
postgresql12_12.22-2~trixie+tuxcare.els13_arm64.deb
sha:1bfe2f823dba400047a22ce693a0f72db6217403
-
postgresql12-client_12.22-2~trixie+tuxcare.els13_arm64.deb
sha:21168285c4b7abf163d1fd88436a354dae44fe7a
-
postgresql12-plperl_12.22-2~trixie+tuxcare.els13_arm64.deb
sha:005c9c39b9d97f0c104b9f47a37f9a00c82aba3a
-
postgresql12-plpython3_12.22-2~trixie+tuxcare.els13_arm64.deb
sha:7c7a93e95f4ae6f0184361ffed13103a8156f03d
-
postgresql12-pltcl_12.22-2~trixie+tuxcare.els13_arm64.deb
sha:72ba75085e10e904eca21dfd3bde09569900cc74
-
postgresql12-server-dev_12.22-2~trixie+tuxcare.els13_arm64.deb
sha:e0bdb80225e44f0bb16b949bc70934f983b1785d
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.