{"id":"SUSE-SU-2026:22077-1","summary":"Security update for postgresql18","details":"This update for postgresql18 fixes the following issues\n\nSecurity issues:\n\n- CVE-2026-6472: ensure the user has CREATE privilege on the schema specified (bsc#1265172).\n- CVE-2026-6473: integer overflows in memory-allocation calculations (bsc#1265173).\n- CVE-2026-6474: Guard against malicious time zone names (bsc#1265174).\n- CVE-2026-6475: Prevent path traversal in pg_basebackup and pg_rewind (bsc#1265175).\n- CVE-2026-6476: Properly quote subscription names in pg_createsubscriber (bsc#1265176).\n- CVE-2026-6477: Mark PQfn() as unsafe, and avoid using it within libpq (bsc#1265177).\n- CVE-2026-6478: Use timing-safe string comparisons in authentication code (bsc#1265178).\n- CVE-2026-6479: Prevent unbounded recursion while processing startup packets (bsc#1265179).\n- CVE-2026-6575: Detect faulty input when restoring attribute MCV statistics (bsc#1265180).\n- CVE-2026-6637: Prevent SQL injection and buffer overruns in contrib/spi (bsc#1265181).\n- CVE-2026-6638: Properly quote object names in logical replication origin checks (bsc#1265182).\n\nNon security issue:\n\n- Update to version 18.4.\n- Get rid of update-alternatives for openSUSE/SLE 16.0 and newer\n to support immutable systems and transactional updates (jsc#PED-14820).\n","modified":"2026-06-16T18:24:35.099596040Z","published":"2026-06-04T07:40:40Z","related":["CVE-2026-6472","CVE-2026-6473","CVE-2026-6474","CVE-2026-6475","CVE-2026-6476","CVE-2026-6477","CVE-2026-6478","CVE-2026-6479","CVE-2026-6575","CVE-2026-6637","CVE-2026-6638"],"upstream":["CVE-2026-6472","CVE-2026-6473","CVE-2026-6474","CVE-2026-6475","CVE-2026-6476","CVE-2026-6477","CVE-2026-6478","CVE-2026-6479","CVE-2026-6575","CVE-2026-6637","CVE-2026-6638"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202622077-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263804"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265172"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265173"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265174"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265175"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265176"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265177"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265178"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265179"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265180"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265181"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265182"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-6472"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-6473"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-6474"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-6475"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-6476"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-6477"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-6478"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-6479"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-6575"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-6637"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-6638"}],"affected":[{"package":{"name":"postgresql18","ecosystem":"SUSE:Linux Enterprise Server 16.0","purl":"pkg:rpm/suse/postgresql18&distro=SUSE%20Linux%20Enterprise%20Server%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"18.4-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"postgresql18-pltcl":"18.4-160000.1.1","postgresql18":"18.4-160000.1.1","postgresql18-docs":"18.4-160000.1.1","libpq5":"18.4-160000.1.1","postgresql18-contrib":"18.4-160000.1.1","libecpg6":"18.4-160000.1.1","postgresql18-plperl":"18.4-160000.1.1","postgresql18-server-devel":"18.4-160000.1.1","postgresql18-server":"18.4-160000.1.1","postgresql18-plpython":"18.4-160000.1.1","postgresql18-devel":"18.4-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22077-1.json"}},{"package":{"name":"postgresql18","ecosystem":"SUSE:Linux Enterprise Server for SAP applications 16.0","purl":"pkg:rpm/suse/postgresql18&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"18.4-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"postgresql18-pltcl":"18.4-160000.1.1","postgresql18":"18.4-160000.1.1","postgresql18-server-devel":"18.4-160000.1.1","postgresql18-plpython":"18.4-160000.1.1","libpq5":"18.4-160000.1.1","postgresql18-plperl":"18.4-160000.1.1","postgresql18-docs":"18.4-160000.1.1","libecpg6":"18.4-160000.1.1","postgresql18-contrib":"18.4-160000.1.1","postgresql18-devel":"18.4-160000.1.1","postgresql18-server":"18.4-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22077-1.json"}}],"schema_version":"1.7.5"}