{"id":"ALSA-2026:67280","summary":"Important: postgresql18 security update","details":"PostgreSQL is an advanced Object-Relational database management system (DBMS). The base postgresql package contains the client programs that you'll need to access a PostgreSQL DBMS server, as well as HTML documentation for the whole system. These client programs can be located on the same machine as the PostgreSQL server, or on a remote machine that accesses a PostgreSQL server over a network connection. The PostgreSQL server can be found in the postgresql-server sub-package.  \n\nSecurity Fix(es):  \n\n  * postgresql: PostgreSQL: SQL injection in pg_createsubscriber allows arbitrary SQL execution as superuser (CVE-2026-6476)\n  * postgresql: PostgreSQL: Arbitrary code execution via integer wraparound in tsvector and tsquery functions (CVE-2026-14662)\n  * postgresql: PostgreSQL: Arbitrary code execution via untrusted data inclusion in pg_dump (CVE-2026-18408)\n  * postgresql: PostgreSQL psql: Arbitrary command execution via untrusted data in COPY FROM STDIN (CVE-2026-6464)\n  * postgresql: PostgreSQL: Arbitrary code execution via logical decoding plugin (CVE-2026-6471)\n  * postgresql: PostgreSQL: Arbitrary code execution via type confusion with \"internal\" arguments (CVE-2026-14680)\n  * postgresql: PostgreSQL: Arbitrary code execution via heap buffer overflow in regexp (CVE-2026-14664)\n  * postgresql: pltcl: plperl: PostgreSQL: Arbitrary code execution in 32-bit pltcl and plperl (CVE-2026-14677)\n  * postgresql-fuzzystrmatch: PostgreSQL fuzzystrmatch: Arbitrary code execution via integer wraparound (CVE-2026-15742)\n  * postgresql: PostgreSQL: Arbitrary code execution via type confusion in cursor lifecycle (CVE-2026-16239)\n  * postgresql: PostgreSQL: Arbitrary code execution via long POSIX timezone abbreviation (CVE-2026-14669)\n  * postgresql: PostgreSQL: Arbitrary code execution via type confusion in pg_restore_attribute_stats() (CVE-2026-16238)\n  * postgresql: PostgreSQL: Stack buffer overflow via OUT parameter count manipulation (CVE-2026-14679)\n  * postgresql: PostgreSQL: Arbitrary code execution via type confusion in 'refint' module (CVE-2026-14671)\n  * postgresql: PostgreSQL pg_stat_statements: Arbitrary code execution via heap buffer overflow (CVE-2026-14676)\n  * postgresql: PostgreSQL: Arbitrary code execution via plperl tied hash heap buffer overflow (CVE-2026-14670)\n  * postgresql: PostgreSQL: Information disclosure via type confusion in ctid selectivity estimator (CVE-2026-14668)\n  * postgresql: PostgreSQL pg_dump: Arbitrary code execution via crafted transform lists (CVE-2026-19385)\n  * postgresql: PostgreSQL: Privilege escalation via SQL injection in EXTRACT() deparse (CVE-2026-15741)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n","modified":"2026-09-17T12:26:42.073438121Z","published":"2026-09-14T00:00:00Z","related":["CVE-2026-14662","CVE-2026-14664","CVE-2026-14668","CVE-2026-14669","CVE-2026-14670","CVE-2026-14671","CVE-2026-14676","CVE-2026-14677","CVE-2026-14679","CVE-2026-14680","CVE-2026-15741","CVE-2026-15742","CVE-2026-16238","CVE-2026-16239","CVE-2026-18408","CVE-2026-19385","CVE-2026-6464","CVE-2026-6471","CVE-2026-6476"],"references":[{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:67280"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-14662"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-14664"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-14668"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-14669"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-14670"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-14671"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-14676"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-14677"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-14679"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-14680"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-15741"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-15742"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-16238"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-16239"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-18408"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-19385"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-6464"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-6471"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-6476"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2477437"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2515302"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2515307"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2515308"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2515311"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2515313"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2515314"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2515316"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2515317"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2515319"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2515324"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2515328"},{"type":"ADVISORY","url":"https://errata.almalinux.org/10/ALSA-2026-67280.html"}],"affected":[{"package":{"name":"postgresql18","ecosystem":"AlmaLinux:10","purl":"pkg:rpm/almalinux/postgresql18"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"18.6-1.el10_2"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux10/ALSA-2026:67280.json"}},{"package":{"name":"postgresql18-contrib","ecosystem":"AlmaLinux:10","purl":"pkg:rpm/almalinux/postgresql18-contrib"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"18.6-1.el10_2"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux10/ALSA-2026:67280.json"}},{"package":{"name":"postgresql18-docs","ecosystem":"AlmaLinux:10","purl":"pkg:rpm/almalinux/postgresql18-docs"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"18.6-1.el10_2"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux10/ALSA-2026:67280.json"}},{"package":{"name":"postgresql18-plperl","ecosystem":"AlmaLinux:10","purl":"pkg:rpm/almalinux/postgresql18-plperl"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"18.6-1.el10_2"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux10/ALSA-2026:67280.json"}},{"package":{"name":"postgresql18-plpython3","ecosystem":"AlmaLinux:10","purl":"pkg:rpm/almalinux/postgresql18-plpython3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"18.6-1.el10_2"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux10/ALSA-2026:67280.json"}},{"package":{"name":"postgresql18-private-devel","ecosystem":"AlmaLinux:10","purl":"pkg:rpm/almalinux/postgresql18-private-devel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"18.6-1.el10_2"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux10/ALSA-2026:67280.json"}},{"package":{"name":"postgresql18-private-libs","ecosystem":"AlmaLinux:10","purl":"pkg:rpm/almalinux/postgresql18-private-libs"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"18.6-1.el10_2"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux10/ALSA-2026:67280.json"}},{"package":{"name":"postgresql18-server","ecosystem":"AlmaLinux:10","purl":"pkg:rpm/almalinux/postgresql18-server"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"18.6-1.el10_2"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux10/ALSA-2026:67280.json"}},{"package":{"name":"postgresql18-server-devel","ecosystem":"AlmaLinux:10","purl":"pkg:rpm/almalinux/postgresql18-server-devel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"18.6-1.el10_2"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux10/ALSA-2026:67280.json"}},{"package":{"name":"postgresql18-static","ecosystem":"AlmaLinux:10","purl":"pkg:rpm/almalinux/postgresql18-static"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"18.6-1.el10_2"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux10/ALSA-2026:67280.json"}},{"package":{"name":"postgresql18-test","ecosystem":"AlmaLinux:10","purl":"pkg:rpm/almalinux/postgresql18-test"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"18.6-1.el10_2"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux10/ALSA-2026:67280.json"}},{"package":{"name":"postgresql18-test-rpm-macros","ecosystem":"AlmaLinux:10","purl":"pkg:rpm/almalinux/postgresql18-test-rpm-macros"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"18.6-1.el10_2"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux10/ALSA-2026:67280.json"}},{"package":{"name":"postgresql18-upgrade","ecosystem":"AlmaLinux:10","purl":"pkg:rpm/almalinux/postgresql18-upgrade"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"18.6-1.el10_2"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux10/ALSA-2026:67280.json"}},{"package":{"name":"postgresql18-upgrade-devel","ecosystem":"AlmaLinux:10","purl":"pkg:rpm/almalinux/postgresql18-upgrade-devel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"18.6-1.el10_2"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux10/ALSA-2026:67280.json"}}],"schema_version":"1.9.0"}