{"id":"MGASA-2026-0347","summary":"Updated postgresql18 & postgresql15 packages fix security vulnerabilities","details":"psql COPY FROM STDIN early failure processes data lines as psql\ncommands. (CVE-2026-6464)\nALTER TABLE ALTER TYPE resets extended statistics ownership.\n(CVE-2026-6469)\nFails to check type USAGE privilege. (CVE-2026-6470)\nLogical decoding can dlopen arbitrary file. (CVE-2026-6471)\ntsvector and tsquery undersize allocations, via integer wraparound.\n(CVE-2026-14662)\npgcrypto, for OpenSSL-disabled ciphers, silently encrypts to and\ndecrypts from cleartext. (CVE-2026-14663)\nRegexp heap buffer overflow executes arbitrary code. (CVE-2026-14664)\nRow security caching disregards role modifications. (CVE-2026-14666)\nctid type confusion in selectivity estimator discloses derivative of\narbitrary read. (CVE-2026-14668)\nto_char heap buffer overflow executes arbitrary code. (CVE-2026-14669)\nplperl tied object heap buffer overflow executes arbitrary code.\n(CVE-2026-14670)\nrefint plan cache type confusion executes arbitrary code.\n(CVE-2026-14671)\nObservable response discrepancy with non-default scram_iterations\nprovides user existence oracle. (CVE-2026-14672)\namcheck does not clear untrusted search path. (CVE-2026-14673)\npg_stat_statements heap buffer overflow executes arbitrary code.\n(CVE-2026-14676)\n32-bit pltcl and plperl undersize allocations, via integer wraparound.\n(CVE-2026-14677)\npg_trgm picksplit reads past end of buffer. (CVE-2026-14678)\nStack buffer overflow in argument match writes 0x0 and 0x1 to server\nmemory. (CVE-2026-14679)\nType confusion via \"internal\" arguments. (CVE-2026-14680)\nImproper enforcement of GSSAPI encryption when coupled with SSL.\n(CVE-2026-14681)\nExpression deparse allows SQL injection via EXTRACT argument.\n(CVE-2026-15741)\nfuzzystrmatch writes effectively-arbitrary addresses, via integer\nwraparound. (CVE-2026-15742)\nType confusion in pg_restore_attribute_stats() executes arbitrary code.\n(CVE-2026-16238)\nType confusion in cursor CLOSE + DECLARE executes arbitrary code.\n(CVE-2026-16239)\nECPG integer underflow can crash the client. (CVE-2026-16241)\nascii() function reads past end of buffer. (CVE-2026-18024)\npsql \\unrestrict lets superuser of pg_dump origin server execute\narbitrary code in psql client. (CVE-2026-18408)\npg_dump heap buffer overflow executes arbitrary code. (CVE-2026-19385)\n","modified":"2026-08-31T16:41:22.878712390Z","published":"2026-08-31T16:22:02Z","upstream":["CVE-2026-14662","CVE-2026-14663","CVE-2026-14664","CVE-2026-14666","CVE-2026-14668","CVE-2026-14669","CVE-2026-14670","CVE-2026-14671","CVE-2026-14672","CVE-2026-14673","CVE-2026-14676","CVE-2026-14677","CVE-2026-14678","CVE-2026-14679","CVE-2026-14680","CVE-2026-14681","CVE-2026-15741","CVE-2026-15742","CVE-2026-16238","CVE-2026-16239","CVE-2026-16241","CVE-2026-18024","CVE-2026-18408","CVE-2026-19385","CVE-2026-6464","CVE-2026-6469","CVE-2026-6470","CVE-2026-6471"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2026-0347.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=36165"},{"type":"WEB","url":"https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/"}],"affected":[{"package":{"name":"postgresql18","ecosystem":"Mageia:10","purl":"pkg:rpm/mageia/postgresql18?arch=source&distro=mageia-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"18.6-1.mga10"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0347.json"}},{"package":{"name":"postgresql15","ecosystem":"Mageia:10","purl":"pkg:rpm/mageia/postgresql15?arch=source&distro=mageia-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"15.19-1.mga10"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0347.json"}},{"package":{"name":"postgresql15","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/postgresql15?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"15.19-1.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0347.json"}}],"schema_version":"1.9.0","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}