{"id":"SUSE-SU-2026:4014-1","summary":"Security update for postgresql18","details":"This update for postgresql18 fixes the following issues:\n\n- CVE-2026-6464: `psql` `COPY FROM STDIN` early failure processes data lines as `psql` commands (bsc#1275046).\n- CVE-2026-6469: `ALTER TABLE ALTER TYPE` resets extended statistics ownership (bsc#1275044).\n- CVE-2026-6470: failure to check type `USAGE` privilege (bsc#1275043).\n- CVE-2026-6471: logical decoding can `dlopen` arbitrary file (bsc#1275042).\n- CVE-2026-14662: `tsvector` and `tsquery` undersize allocations, via integer wraparound (bsc#1275001).\n- CVE-2026-14663: `pgcrypto`, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext\n  (bsc#1275002).\n- CVE-2026-14664: `regexp` heap buffer overflow executes arbitrary code (bsc#1275068).\n- CVE-2026-14666: row security caching disregards role modifications (bsc#1275067).\n- CVE-2026-14668: `ctid` type confusion in selectivity estimator discloses derivative of arbitrary read\n  (bsc#1275066).\n- CVE-2026-14669: `to_char` heap buffer overflow executes arbitrary code (bsc#1275065).\n- CVE-2026-14670: `plperl` tied object heap buffer overflow executes arbitrary code (bsc#1275064).\n- CVE-2026-14671: `refint` plan cache type confusion executes arbitrary code (bsc#1275063).\n- CVE-2026-14672:  observable response discrepancy with non-default `scram_iterations` provides user existence\n  oracle (bsc#1275062).\n- CVE-2026-14673: `amcheck` does not clear untrusted search path (bsc#1275061).\n- CVE-2026-14676: `pg_stat_statements` heap buffer overflow executes arbitrary code (bsc#1275060).\n- CVE-2026-14677: 32-bit `pltcl` and `plperl` undersize allocations, via integer wraparound (bsc#1275059).\n- CVE-2026-14678: `pg_trgm` `picksplit` reads past end of buffer (bsc#1275058).\n- CVE-2026-14679: stack buffer overflow in argument match writes `0x0` and `0x1` to server memory (bsc#1275057).\n- CVE-2026-14680: type confusion via 'internal' arguments (bsc#1275056).\n- CVE-2026-14681: improper enforcement of GSSAPI encryption when coupled with SSL (bsc#1275055).\n- CVE-2026-15741: expression deparse allows SQL injection via `EXTRACT` argument (bsc#1275054).\n- CVE-2026-15742: `fuzzystrmatch` writes effectively-arbitrary addresses, via integer wraparound (bsc#1275053).\n- CVE-2026-16238: type confusion in `pg_restore_attribute_stats()` executes arbitrary code (bsc#1275052).\n- CVE-2026-16239: type confusion in cursor `CLOSE + DECLARE` executes arbitrary code (bsc#1275051).\n- CVE-2026-16241: ECPG integer underflow can crash the client (bsc#1275050).\n- CVE-2026-18024: `ascii()` function reads past end of buffer (bsc#1275049).\n- CVE-2026-18408: `psql` `\\unrestrict` lets superuser of `pg_dump` origin server execute arbitrary code in `psql`\n  client (bsc#1275048).\n- CVE-2026-19385: `pg_dump` heap buffer overflow executes arbitrary code (bsc#1275047).\n\nChanges for postgresql18:\n\n- Update to version 18.6:\n  * https://www.postgresql.org/docs/18/release-18-6.html\n  * https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/\n","modified":"2026-09-13T18:23:15.247483213Z","published":"2026-09-07T07:36:31Z","related":["CVE-2026-14662","CVE-2026-14663","CVE-2026-14664","CVE-2026-14666","CVE-2026-14668","CVE-2026-14669","CVE-2026-14670","CVE-2026-14671","CVE-2026-14672","CVE-2026-14673","CVE-2026-14676","CVE-2026-14677","CVE-2026-14678","CVE-2026-14679","CVE-2026-14680","CVE-2026-14681","CVE-2026-15741","CVE-2026-15742","CVE-2026-16238","CVE-2026-16239","CVE-2026-16241","CVE-2026-18024","CVE-2026-18408","CVE-2026-19385","CVE-2026-6464","CVE-2026-6469","CVE-2026-6470","CVE-2026-6471"],"upstream":["CVE-2026-14662","CVE-2026-14663","CVE-2026-14664","CVE-2026-14666","CVE-2026-14668","CVE-2026-14669","CVE-2026-14670","CVE-2026-14671","CVE-2026-14672","CVE-2026-14673","CVE-2026-14676","CVE-2026-14677","CVE-2026-14678","CVE-2026-14679","CVE-2026-14680","CVE-2026-14681","CVE-2026-15741","CVE-2026-15742","CVE-2026-16238","CVE-2026-16239","CVE-2026-16241","CVE-2026-18024","CVE-2026-18408","CVE-2026-19385","CVE-2026-6464","CVE-2026-6469","CVE-2026-6470","CVE-2026-6471"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20264014-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275001"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275002"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275042"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275043"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275044"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275046"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275047"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275048"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275049"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275050"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275051"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275052"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275053"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275054"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275055"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275056"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275057"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275058"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275059"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275060"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275061"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275062"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275063"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275064"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275065"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275066"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275067"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275068"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-14662"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-14663"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-14664"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-14666"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-14668"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-14669"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-14670"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-14671"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-14672"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-14673"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-14676"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-14677"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-14678"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-14679"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-14680"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-14681"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-15741"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-15742"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16238"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16239"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16241"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-18024"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-18408"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-19385"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-6464"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-6469"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-6470"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-6471"}],"affected":[{"package":{"name":"postgresql18","ecosystem":"SUSE:Linux Enterprise Module for Basesystem 15 SP7","purl":"pkg:rpm/suse/postgresql18&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"18.6-150600.13.16.1"}]}],"ecosystem_specific":{"binaries":[{"postgresql18":"18.6-150600.13.16.1","libpq5":"18.6-150600.13.16.1","libpq5-32bit":"18.6-150600.13.16.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4014-1.json"}},{"package":{"name":"postgresql18","ecosystem":"SUSE:Linux Enterprise Module for Package Hub 15 SP7","purl":"pkg:rpm/suse/postgresql18&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"18.6-150600.13.16.1"}]}],"ecosystem_specific":{"binaries":[{"postgresql18-test":"18.6-150600.13.16.1","postgresql18-llvmjit":"18.6-150600.13.16.1","postgresql18-llvmjit-devel":"18.6-150600.13.16.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4014-1.json"}},{"package":{"name":"postgresql18","ecosystem":"SUSE:Linux Enterprise Module for Server Applications 15 SP7","purl":"pkg:rpm/suse/postgresql18&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"18.6-150600.13.16.1"}]}],"ecosystem_specific":{"binaries":[{"postgresql18-pltcl":"18.6-150600.13.16.1","postgresql18-devel":"18.6-150600.13.16.1","postgresql18-server-devel":"18.6-150600.13.16.1","postgresql18-docs":"18.6-150600.13.16.1","postgresql18-plpython":"18.6-150600.13.16.1","libecpg6":"18.6-150600.13.16.1","postgresql18-contrib":"18.6-150600.13.16.1","postgresql18-plperl":"18.6-150600.13.16.1","postgresql18-server":"18.6-150600.13.16.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4014-1.json"}},{"package":{"name":"postgresql18","ecosystem":"SUSE:Linux Enterprise Server 15 SP6-LTSS","purl":"pkg:rpm/suse/postgresql18&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"18.6-150600.13.16.1"}]}],"ecosystem_specific":{"binaries":[{"libecpg6":"18.6-150600.13.16.1","postgresql18-devel":"18.6-150600.13.16.1","postgresql18-docs":"18.6-150600.13.16.1","postgresql18-plpython":"18.6-150600.13.16.1","libpq5-32bit":"18.6-150600.13.16.1","postgresql18-pltcl":"18.6-150600.13.16.1","postgresql18-server":"18.6-150600.13.16.1","postgresql18-server-devel":"18.6-150600.13.16.1","libpq5":"18.6-150600.13.16.1","postgresql18":"18.6-150600.13.16.1","postgresql18-contrib":"18.6-150600.13.16.1","postgresql18-plperl":"18.6-150600.13.16.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4014-1.json"}},{"package":{"name":"postgresql18","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP6","purl":"pkg:rpm/suse/postgresql18&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"18.6-150600.13.16.1"}]}],"ecosystem_specific":{"binaries":[{"postgresql18-plpython":"18.6-150600.13.16.1","libecpg6":"18.6-150600.13.16.1","postgresql18-server-devel":"18.6-150600.13.16.1","postgresql18-plperl":"18.6-150600.13.16.1","postgresql18":"18.6-150600.13.16.1","libpq5":"18.6-150600.13.16.1","postgresql18-docs":"18.6-150600.13.16.1","postgresql18-pltcl":"18.6-150600.13.16.1","libpq5-32bit":"18.6-150600.13.16.1","postgresql18-contrib":"18.6-150600.13.16.1","postgresql18-server":"18.6-150600.13.16.1","postgresql18-devel":"18.6-150600.13.16.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4014-1.json"}}],"schema_version":"1.9.0"}