{"id":"USN-8653-1","summary":"postgresql-14, postgresql-16, postgresql-18 vulnerabilities","details":"It was discovered that PostgreSQL incorrectly handled COPY FROM STDIN when\nan early failure occurred. An authenticated user could possibly use this\nissue to execute arbitrary SQL commands. (CVE-2026-6464)\n\nIt was discovered that PostgreSQL incorrectly reset extended statistics\nownership during ALTER TABLE ALTER TYPE operations. An attacker could\npossibly use this issue to obtain sensitive information or gain unintended\nprivileges. (CVE-2026-6469)\n\nIt was discovered that PostgreSQL failed to check the USAGE privilege on\ntypes. An authenticated user could possibly use this issue to obtain\nsensitive information. (CVE-2026-6470)\n\nIt was discovered that PostgreSQL logical decoding could load arbitrary\nshared libraries. An authenticated user could possibly use this issue to\nexecute arbitrary code. (CVE-2026-6471)\n\nIt was discovered that PostgreSQL had integer wraparound issues in tsvector\nand tsquery allocations. An authenticated user could possibly use this\nissue to execute arbitrary code. (CVE-2026-14662)\n\nIt was discovered that PostgreSQL pgcrypto silently used cleartext when\nOpenSSL-disabled ciphers were requested. An authenticated user could\npossibly use this issue to obtain sensitive information. (CVE-2026-14663)\n\nIt was discovered that PostgreSQL had a heap buffer overflow in regular\nexpression processing. An authenticated user could possibly use this issue\nto execute arbitrary code. (CVE-2026-14664)\n\nIt was discovered that PostgreSQL row security policies were not properly\ninvalidated when roles were modified. An attacker could possibly use this\nissue to bypass intended row security restrictions. (CVE-2026-14666)\n\nIt was discovered that PostgreSQL had a type confusion issue in the\nselectivity estimator involving ctid. An authenticated user could possibly\nuse this issue to obtain sensitive information. (CVE-2026-14668)\n\nIt was discovered that PostgreSQL had a heap buffer overflow in the to_char\nfunction. An authenticated user could possibly use this issue to execute\narbitrary code. (CVE-2026-14669)\n\nIt was discovered that PostgreSQL had a heap buffer overflow in the PL/Perl\ntied object handling. An authenticated user could possibly use this issue\nto execute arbitrary code. (CVE-2026-14670)\n\nIt was discovered that PostgreSQL had a type confusion issue in the\nreferential integrity plan cache. An authenticated user could possibly use\nthis issue to execute arbitrary code. (CVE-2026-14671)\n\nIt was discovered that PostgreSQL had an observable response discrepancy\nwhen non-default scram_iterations were used. A remote attacker could\npossibly use this issue to enumerate valid usernames. This issue only\naffected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-14672)\n\nIt was discovered that PostgreSQL amcheck did not clear untrusted search\npaths. An authenticated user could possibly use this issue to execute\narbitrary code. (CVE-2026-14673)\n\nIt was discovered that PostgreSQL had a heap buffer overflow in\npg_stat_statements. An authenticated user could possibly use this issue to\nexecute arbitrary code. This issue only affected Ubuntu 26.04 LTS.\n(CVE-2026-14676)\n\nIt was discovered that PostgreSQL had integer wraparound issues in PL/Tcl\nand PL/Perl allocations on 32-bit systems. An authenticated user could\npossibly use this issue to execute arbitrary code. (CVE-2026-14677)\n\nIt was discovered that PostgreSQL pg_trgm read past the end of a buffer\nduring picksplit operations. An authenticated user could possibly use this\nissue to obtain sensitive information. (CVE-2026-14678)\n\nIt was discovered that PostgreSQL had a stack buffer overflow in argument\nmatching. An authenticated user could possibly use this issue to corrupt\nserver memory. (CVE-2026-14679)\n\nIt was discovered that PostgreSQL had a type confusion issue when functions\nused internal arguments. An authenticated user could possibly use this\nissue to execute arbitrary code. (CVE-2026-14680)\n\nIt was discovered that PostgreSQL did not properly enforce GSSAPI\nencryption when used together with SSL. An attacker could possibly use this\nissue to perform a machine-in-the-middle attack and obtain sensitive\ninformation. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-14681)\n\nIt was discovered that PostgreSQL allowed SQL injection through EXTRACT\narguments during expression deparsing. An authenticated user could possibly\nuse this issue to perform SQL injection attacks. (CVE-2026-15741)\n\nIt was discovered that PostgreSQL fuzzystrmatch had integer wraparound\nissues that could write to arbitrary addresses. An authenticated user could\npossibly use this issue to execute arbitrary code. (CVE-2026-15742)\n\nIt was discovered that PostgreSQL had a type confusion issue in\npg_restore_attribute_stats(). An authenticated user could possibly use this\nissue to execute arbitrary code. This issue only affected Ubuntu 26.04 LTS.\n(CVE-2026-16238)\n\nIt was discovered that PostgreSQL had a type confusion issue when handling\ncursor CLOSE and DECLARE operations. An authenticated user could possibly\nuse this issue to execute arbitrary code. (CVE-2026-16239)\n\nIt was discovered that PostgreSQL had an integer underflow in the ECPG\nclient library. An attacker could possibly use this issue to cause\nPostgreSQL to crash, resulting in a denial of service. (CVE-2026-16241)\n\nIt was discovered that PostgreSQL had an out-of-bounds read in the ascii()\nfunction. An authenticated user could possibly use this issue to obtain\nsensitive information. (CVE-2026-18024)\n\nIt was discovered that the psql \\unrestrict command allowed the superuser\nof a pg_dump origin server to execute arbitrary code in the psql client. An\nattacker could possibly use this issue to execute arbitrary code.\n(CVE-2026-18408)\n\nIt was discovered that PostgreSQL pg_dump had a heap buffer overflow. An\nattacker could possibly use this issue to execute arbitrary code.\n(CVE-2026-19385)","modified":"2026-08-20T23:44:58.684078119Z","published":"2026-08-20T11:42:58Z","related":["UBUNTU-CVE-2025-8714","UBUNTU-CVE-2026-14662","UBUNTU-CVE-2026-14663","UBUNTU-CVE-2026-14664","UBUNTU-CVE-2026-14666","UBUNTU-CVE-2026-14668","UBUNTU-CVE-2026-14669","UBUNTU-CVE-2026-14670","UBUNTU-CVE-2026-14671","UBUNTU-CVE-2026-14672","UBUNTU-CVE-2026-14673","UBUNTU-CVE-2026-14676","UBUNTU-CVE-2026-14677","UBUNTU-CVE-2026-14678","UBUNTU-CVE-2026-14679","UBUNTU-CVE-2026-14680","UBUNTU-CVE-2026-14681","UBUNTU-CVE-2026-15741","UBUNTU-CVE-2026-15742","UBUNTU-CVE-2026-16238","UBUNTU-CVE-2026-16239","UBUNTU-CVE-2026-16241","UBUNTU-CVE-2026-18024","UBUNTU-CVE-2026-18408","UBUNTU-CVE-2026-19385","UBUNTU-CVE-2026-6464","UBUNTU-CVE-2026-6469","UBUNTU-CVE-2026-6470","UBUNTU-CVE-2026-6471","UBUNTU-CVE-2026-6473"],"upstream":["CVE-2025-8714","CVE-2026-14662","CVE-2026-14663","CVE-2026-14664","CVE-2026-14666","CVE-2026-14668","CVE-2026-14669","CVE-2026-14670","CVE-2026-14671","CVE-2026-14672","CVE-2026-14673","CVE-2026-14676","CVE-2026-14677","CVE-2026-14678","CVE-2026-14679","CVE-2026-14680","CVE-2026-14681","CVE-2026-15741","CVE-2026-15742","CVE-2026-16238","CVE-2026-16239","CVE-2026-16241","CVE-2026-18024","CVE-2026-18408","CVE-2026-19385","CVE-2026-6464","CVE-2026-6469","CVE-2026-6470","CVE-2026-6471","CVE-2026-6473","UBUNTU-CVE-2025-8714","UBUNTU-CVE-2026-14662","UBUNTU-CVE-2026-14663","UBUNTU-CVE-2026-14664","UBUNTU-CVE-2026-14666","UBUNTU-CVE-2026-14668","UBUNTU-CVE-2026-14669","UBUNTU-CVE-2026-14670","UBUNTU-CVE-2026-14671","UBUNTU-CVE-2026-14672","UBUNTU-CVE-2026-14673","UBUNTU-CVE-2026-14676","UBUNTU-CVE-2026-14677","UBUNTU-CVE-2026-14678","UBUNTU-CVE-2026-14679","UBUNTU-CVE-2026-14680","UBUNTU-CVE-2026-14681","UBUNTU-CVE-2026-15741","UBUNTU-CVE-2026-15742","UBUNTU-CVE-2026-16238","UBUNTU-CVE-2026-16239","UBUNTU-CVE-2026-16241","UBUNTU-CVE-2026-18024","UBUNTU-CVE-2026-18408","UBUNTU-CVE-2026-19385","UBUNTU-CVE-2026-6464","UBUNTU-CVE-2026-6469","UBUNTU-CVE-2026-6470","UBUNTU-CVE-2026-6471","UBUNTU-CVE-2026-6473"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-8653-1"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2025-8714"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-6464"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-6469"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-6470"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-6471"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-6473"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-14662"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-14663"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-14664"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-14666"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-14668"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-14669"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-14670"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-14671"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-14672"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-14673"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-14676"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-14677"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-14678"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-14679"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-14680"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-14681"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-15741"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-15742"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-16238"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-16239"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-16241"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-18024"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-18408"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-19385"}],"affected":[{"package":{"name":"postgresql-14","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/postgresql-14?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"14.24-0ubuntu0.22.04.1"}]}],"versions":["14.1-1ubuntu1","14.2-1","14.2-1ubuntu1","14.3-0ubuntu0.22.04.1","14.4-0ubuntu0.22.04.1","14.5-0ubuntu0.22.04.1","14.6-0ubuntu0.22.04.1","14.7-0ubuntu0.22.04.1","14.8-0ubuntu0.22.04.1","14.9-0ubuntu0.22.04.1","14.10-0ubuntu0.22.04.1","14.11-0ubuntu0.22.04.1","14.12-0ubuntu0.22.04.1","14.13-0ubuntu0.22.04.1","14.15-0ubuntu0.22.04.1","14.17-0ubuntu0.22.04.1","14.18-0ubuntu0.22.04.1","14.19-0ubuntu0.22.04.1","14.20-0ubuntu0.22.04.1","14.22-0ubuntu0.22.04.1","14.23-0ubuntu0.22.04.1"],"ecosystem_specific":{"binaries":[{"binary_name":"libecpg-compat3","binary_version":"14.24-0ubuntu0.22.04.1"},{"binary_version":"14.24-0ubuntu0.22.04.1","binary_name":"libecpg6"},{"binary_name":"libpgtypes3","binary_version":"14.24-0ubuntu0.22.04.1"},{"binary_version":"14.24-0ubuntu0.22.04.1","binary_name":"libpq5"},{"binary_name":"postgresql-14","binary_version":"14.24-0ubuntu0.22.04.1"},{"binary_version":"14.24-0ubuntu0.22.04.1","binary_name":"postgresql-client-14"},{"binary_name":"postgresql-doc-14","binary_version":"14.24-0ubuntu0.22.04.1"},{"binary_name":"postgresql-plperl-14","binary_version":"14.24-0ubuntu0.22.04.1"},{"binary_version":"14.24-0ubuntu0.22.04.1","binary_name":"postgresql-plpython3-14"},{"binary_name":"postgresql-pltcl-14","binary_version":"14.24-0ubuntu0.22.04.1"},{"binary_name":"postgresql-server-dev-14","binary_version":"14.24-0ubuntu0.22.04.1"}],"availability":"No subscription required"},"database_specific":{"cves_map":{"ecosystem":"Ubuntu:22.04:LTS","cves":[{"id":"CVE-2026-6464","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2026-6469","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2026-6470","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-6471","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]},{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-14662"},{"id":"CVE-2026-14663","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2026-14664","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"score":"medium","type":"Ubuntu"}]},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2026-14666"},{"id":"CVE-2026-14668","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-14669"},{"id":"CVE-2026-14670","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2026-14671","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2026-14673","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N"},{"score":"medium","type":"Ubuntu"}]},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-14677"},{"id":"CVE-2026-14678","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}]},{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-14679"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-14680"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-15741"},{"id":"CVE-2026-15742","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2026-16239","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]},{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2026-16241"},{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-18024"},{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2026-18408"},{"id":"CVE-2026-19385","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}]}]},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8653-1.json"}},{"package":{"name":"postgresql-16","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/postgresql-16?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"16.15-0ubuntu0.24.04.1"}]}],"versions":["16.0-2","16.1-1","16.1-1build1","16.1-1build3","16.2-1","16.2-1ubuntu2","16.2-1ubuntu3","16.2-1ubuntu4","16.3-0ubuntu0.24.04.1","16.4-0ubuntu0.24.04.1","16.4-0ubuntu0.24.04.2","16.6-0ubuntu0.24.04.1","16.8-0ubuntu0.24.04.1","16.9-0ubuntu0.24.04.1","16.10-0ubuntu0.24.04.1","16.11-0ubuntu0.24.04.1","16.13-0ubuntu0.24.04.1","16.14-0ubuntu0.24.04.1"],"ecosystem_specific":{"binaries":[{"binary_version":"16.15-0ubuntu0.24.04.1","binary_name":"libecpg-compat3"},{"binary_name":"libecpg6","binary_version":"16.15-0ubuntu0.24.04.1"},{"binary_name":"libpgtypes3","binary_version":"16.15-0ubuntu0.24.04.1"},{"binary_name":"libpq5","binary_version":"16.15-0ubuntu0.24.04.1"},{"binary_version":"16.15-0ubuntu0.24.04.1","binary_name":"postgresql-16"},{"binary_name":"postgresql-client-16","binary_version":"16.15-0ubuntu0.24.04.1"},{"binary_name":"postgresql-doc-16","binary_version":"16.15-0ubuntu0.24.04.1"},{"binary_name":"postgresql-plperl-16","binary_version":"16.15-0ubuntu0.24.04.1"},{"binary_version":"16.15-0ubuntu0.24.04.1","binary_name":"postgresql-plpython3-16"},{"binary_version":"16.15-0ubuntu0.24.04.1","binary_name":"postgresql-pltcl-16"},{"binary_name":"postgresql-server-dev-16","binary_version":"16.15-0ubuntu0.24.04.1"}],"availability":"No subscription required"},"database_specific":{"cves_map":{"ecosystem":"Ubuntu:24.04:LTS","cves":[{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-6464"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-6469"},{"id":"CVE-2026-6470","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}]},{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-6471"},{"id":"CVE-2026-14662","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-14663","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-14664","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-14666","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2026-14668","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2026-14669","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2026-14670","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2026-14671","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2026-14672"},{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2026-14673"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2026-14677"},{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-14678"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-14679"},{"id":"CVE-2026-14680","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-15741","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},{"score":"medium","type":"Ubuntu"}]},{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2026-15742"},{"id":"CVE-2026-16239","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-16241","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}]},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-18024"},{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-18408"},{"id":"CVE-2026-19385","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"score":"medium","type":"Ubuntu"}]}]},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8653-1.json"}},{"package":{"name":"postgresql-18","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/postgresql-18?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"18.6-0ubuntu0.26.04.1"}]}],"versions":["18.0-1","18.1-1","18.1-1ubuntu1","18.1-1ubuntu2","18.1-2","18.3-1","18.4-0ubuntu0.26.04.1"],"ecosystem_specific":{"binaries":[{"binary_name":"libecpg-compat3","binary_version":"18.6-0ubuntu0.26.04.1"},{"binary_version":"18.6-0ubuntu0.26.04.1","binary_name":"libecpg6"},{"binary_name":"libpgtypes3","binary_version":"18.6-0ubuntu0.26.04.1"},{"binary_version":"18.6-0ubuntu0.26.04.1","binary_name":"libpq-oauth"},{"binary_version":"18.6-0ubuntu0.26.04.1","binary_name":"libpq5"},{"binary_version":"18.6-0ubuntu0.26.04.1","binary_name":"postgresql-18"},{"binary_name":"postgresql-18-jit","binary_version":"18.6-0ubuntu0.26.04.1"},{"binary_version":"18.6-0ubuntu0.26.04.1","binary_name":"postgresql-client-18"},{"binary_name":"postgresql-doc-18","binary_version":"18.6-0ubuntu0.26.04.1"},{"binary_name":"postgresql-plperl-18","binary_version":"18.6-0ubuntu0.26.04.1"},{"binary_name":"postgresql-plpython3-18","binary_version":"18.6-0ubuntu0.26.04.1"},{"binary_version":"18.6-0ubuntu0.26.04.1","binary_name":"postgresql-pltcl-18"},{"binary_name":"postgresql-server-dev-18","binary_version":"18.6-0ubuntu0.26.04.1"}],"availability":"No subscription required"},"database_specific":{"cves_map":{"ecosystem":"Ubuntu:26.04:LTS","cves":[{"id":"CVE-2026-6464","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2026-6469","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}]},{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-6470"},{"id":"CVE-2026-6471","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-14662","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2026-14663","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-14664","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-14666","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2026-14668","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-14669","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2026-14670","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-14671","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-14672","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}]},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-14673"},{"id":"CVE-2026-14676","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"score":"medium","type":"Ubuntu"}]},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2026-14677"},{"id":"CVE-2026-14678","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-14679","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2026-14680","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]},{"severity":[{"score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-14681"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2026-15741"},{"id":"CVE-2026-15742","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-16238","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}]},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2026-16239"},{"id":"CVE-2026-16241","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2026-18024"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2026-18408"},{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2026-19385"}]},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8653-1.json"}}],"schema_version":"1.9.0"}