{"id":"MGASA-2026-0151","summary":"Updated postgresql15 packages fix security vulnerabilities","details":"PostgreSQL CREATE TYPE does not check multirange schema CREATE\nprivilege. (CVE-2026-6472)\nPostgreSQL server undersizes allocations, via integer wraparound.\n(CVE-2026-6473)\nPostgreSQL timeofday() can disclose portions of server memory.\n(CVE-2026-6474)\nPostgreSQL pg_basebackup and pg_rewind can overwrite unrelated files of\norigin superuser choice. (CVE-2026-6475)\nPostgreSQL libpq lo_* functions let server superuser overwrite client\nstack memory. (CVE-2026-6477)\nPostgreSQL discloses MD5-hashed passwords via covert timing channel.\n(CVE-2026-6478)\nPostgreSQL SSL/GSS init causes denial of service, via uncontrolled\nrecursion. (CVE-2026-6479)\nPostgreSQL refint allows stack buffer overflow and SQL injection.\n(CVE-2026-6637)\n","modified":"2026-05-19T03:00:06.842990Z","published":"2026-05-19T02:46:11Z","upstream":["CVE-2026-6472","CVE-2026-6473","CVE-2026-6474","CVE-2026-6475","CVE-2026-6476","CVE-2026-6477","CVE-2026-6478","CVE-2026-6479","CVE-2026-6575","CVE-2026-6637","CVE-2026-6638"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2026-0151.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=35534"},{"type":"WEB","url":"https://www.postgresql.org/about/news/postgresql-184-1710-1614-1518-and-1423-released-3297/"}],"affected":[{"package":{"name":"postgresql15","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/postgresql15?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"15.18-1.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0151.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}