[CLSA-2026:1790238670] Fix of 6 CVEs
Type:
security
Severity:
Critical
Release date:
2026-09-24 08:31:31 UTC
Description:
* SECURITY UPDATE: unrestricted library load during logical decoding, where a user holding the REPLICATION privilege could execute arbitrary code as the operating system user running the database by naming any shared library as the output plugin of a logical replication slot, because output plugin paths were never subject to the LOAD-time restrictions that apply to library loading elsewhere - debian/patches/CVE-2026-6471.patch: add an output_plugin_libraries GUC defaulting to "pgoutput, test_decoding" in src/backend/utils/misc/guc.c, src/include/replication/logical.h and src/backend/utils/misc/postgresql.conf.sample, check the requested plugin name against that list in StartupDecodingContext() before calling LoadOutputPlugin() and reject anything else with "library ... may not be used as an output plugin" in src/backend/replication/logical/logical.c, quote the new list parameter correctly in src/bin/pg_dump/dumputils.c, document it in doc/src/sgml/config.sgml and doc/src/sgml/logical-replication.sgml and extend the tests in contrib/test_decoding and src/test/subscription/t/100_bugs.pl. Note that third-party output plugins other than pgoutput and test_decoding must now be added to output_plugin_libraries before they can be used - CVE-2026-6471 * SECURITY UPDATE: integer overflow in the Levenshtein distance functions, where any user could produce nonsensical results or, via levenshtein_less_equal(), trigger out-of-bounds writes, because levenshtein() and levenshtein_less_equal() accept arbitrary 32-bit insertion, deletion and substitution costs but computed the distance with 32-bit arithmetic - debian/patches/CVE-2026-15742.patch: widen the prev and curr row arrays and the per-operation costs to int64 and compute the distance in 64-bit arithmetic throughout varstr_levenshtein() in src/backend/utils/adt/levenshtein.c, add a levenshtein_result() helper in src/backend/utils/adt/varlena.c that raises ERRCODE_NUMERIC_VALUE_OUT_OF_RANGE with "levenshtein distance out of range" when the result does not fit in the returned int32, route every return through it, and cover the overflow cases in contrib/fuzzystrmatch/sql/fuzzystrmatch.sql and contrib/fuzzystrmatch/expected/fuzzystrmatch.out - CVE-2026-15742 * SECURITY UPDATE: type confusion via arguments and results of type internal, where any user could execute arbitrary code as the operating system user running the database by calling a function that takes or returns type internal, because type internal stands for a class of mutually incompatible data structures that are not meant to be reachable from SQL and the checks that were supposed to prevent such calls had gaps - debian/patches/CVE-2026-14680.patch: reject casting to or from type internal in can_coerce_type() and find_coercion_pathway() in src/backend/parser/parse_coerce.c, reject resolved argument and result types of internal in ParseFuncOrColumn() in src/backend/parser/parse_func.c and in make_op() in src/backend/parser/parse_oper.c, refuse the I/O coercion fallback for internal in get_cast_hashentry() in src/pl/plpgsql/src/pl_exec.c, and, as defence in depth, make numeric_combine(), numeric_avg_combine(), numeric_poly_combine() and int8_avg_combine() return a real SQL NULL instead of an unmarked null pointer in src/backend/utils/adt/numeric.c - CVE-2026-14680 * SECURITY UPDATE: type confusion between the outer and inner portal of an EXECUTE or FETCH statement, where any user could disclose server memory contents and execute arbitrary code as the operating system user running the database, because nothing checked that the portal created for the EXECUTE or FETCH statement and the portal for the statement being run on its behalf agreed on the tuple descriptor of the rows being returned - debian/patches/CVE-2026-16239.patch: extend the tuplestore DestReceiver with an optional target tuple descriptor and mapping failure message in src/include/executor/tstoreReceiver.h and src/backend/executor/tstoreReceiver.c, so that it builds a conversion map with convert_tuples_by_position() and raises an error when the executor output does not match, update the caller in PersistHoldablePortal() in src/backend/commands/portalcmds.c, and pass portal->tupDesc together with "query result type does not match portal result type" from FillPortalStore() in src/backend/tcop/pquery.c - CVE-2026-16239
Updated packages:
  • libecpg-compat3-11_11.22-1~trixie+tuxcare.els17_amd64.deb
    sha:07e96fe5297927b590e6ffd62a594356c72b86bc
  • libecpg-dev-11_11.22-1~trixie+tuxcare.els17_amd64.deb
    sha:4c728c5219bff3979f69d47b9756005af092dc49
  • libecpg6-11_11.22-1~trixie+tuxcare.els17_amd64.deb
    sha:f29ab720ef8f328f106279bac30cd8ac4833c74f
  • libpgtypes3-11_11.22-1~trixie+tuxcare.els17_amd64.deb
    sha:807b45ee43feccfc4de0565df29250134f1213a1
  • libpq-dev-11_11.22-1~trixie+tuxcare.els17_amd64.deb
    sha:233bee4b17008cd8b4bac68b0c4352b4439a7698
  • libpq5-11_11.22-1~trixie+tuxcare.els17_amd64.deb
    sha:ad397d98300977364614aded6df4142ffa87f590
  • postgresql11_11.22-1~trixie+tuxcare.els17_amd64.deb
    sha:fd56e0637e23ac69e30c3a23ca8498c94a8e9488
  • postgresql11-client_11.22-1~trixie+tuxcare.els17_amd64.deb
    sha:25da3ef8b86e4c6e4c7e40eb45fe12e5b2d2b3fc
  • postgresql11-doc_11.22-1~trixie+tuxcare.els17_all.deb
    sha:d7edf6ddc1fd85fe0e0fffa042f237adab6336d8
  • postgresql11-plperl_11.22-1~trixie+tuxcare.els17_amd64.deb
    sha:908e5ea985b1de03ea3514b31cde7e6f3b61dccf
  • postgresql11-plpython3_11.22-1~trixie+tuxcare.els17_amd64.deb
    sha:bd5d9957be6f0742a73954a271946924eae64f8f
  • postgresql11-pltcl_11.22-1~trixie+tuxcare.els17_amd64.deb
    sha:09c168a3f044c2e3229885a27eba7ca415b3fa20
  • postgresql11-server-dev_11.22-1~trixie+tuxcare.els17_amd64.deb
    sha:20d9456d42c5c5bd1a1ccfe0e90c93994e199b2b
  • libecpg-compat3-11_11.22-1~trixie+tuxcare.els17_arm64.deb
    sha:88e3e592d285e2123f4386032f5ee643effc0eb0
  • libecpg-dev-11_11.22-1~trixie+tuxcare.els17_arm64.deb
    sha:ce4ac6517e718790bf49d6f71246c61388094a30
  • libecpg6-11_11.22-1~trixie+tuxcare.els17_arm64.deb
    sha:cac20e21596ecf7bf333e6bafd068603163ee38a
  • libpgtypes3-11_11.22-1~trixie+tuxcare.els17_arm64.deb
    sha:d72b25a4053eb907114b138d4af20fffe28d5e9d
  • libpq-dev-11_11.22-1~trixie+tuxcare.els17_arm64.deb
    sha:113fbf1fc201a726f9e10cb17a38ef8ed7bd735d
  • libpq5-11_11.22-1~trixie+tuxcare.els17_arm64.deb
    sha:50a8afcdb07191b1c44e16d00833e74f7bae9d65
  • postgresql11_11.22-1~trixie+tuxcare.els17_arm64.deb
    sha:d6e2057bbb684c08cbbca6529ffbc7d03b9beb47
  • postgresql11-client_11.22-1~trixie+tuxcare.els17_arm64.deb
    sha:03331c6cf072feb5c41217bc3d2bcf576fb75a7f
  • postgresql11-plperl_11.22-1~trixie+tuxcare.els17_arm64.deb
    sha:b30246dbe18d8056a6c6b96c320842696d980d97
  • postgresql11-plpython3_11.22-1~trixie+tuxcare.els17_arm64.deb
    sha:e72b9662f54aa3974cad508a1a79f2f32e6a2bc8
  • postgresql11-pltcl_11.22-1~trixie+tuxcare.els17_arm64.deb
    sha:f1ae6d6f5df2be7aebb93822019177d5ba67c086
  • postgresql11-server-dev_11.22-1~trixie+tuxcare.els17_arm64.deb
    sha:de3daadcdc015ab59ac2def29c9b43cb54d68881
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.