[CLSA-2026:1786714067] Fix CVE(s): CVE-2026-2003, CVE-2026-2004, CVE-2026-2005, CVE-2026-2006
Type:
security
Severity:
Important
Release date:
2026-08-14 13:28:02 UTC
Description:
* SECURITY UPDATE: Server memory disclosure via crafted oidvector/int2vector - debian/patches/CVE-2026-2003.patch: add check_valid_oidvector() and check_valid_int2vector() and call them from hashoidvector(), hashoidvectorextended(), btoidvectorcmp(), oidvectortypes(), int2vectorout() and oidvectorout(), so an oid[] or int2[] array cast to these types cannot violate the 1-dimensional, no-nulls layout those functions assume - CVE-2026-2003 * SECURITY UPDATE: Arbitrary code execution via intarray selectivity estimator - debian/patches/CVE-2026-2004.patch: require superuser to attach a non-built-in restriction or join selectivity estimator, reject a wrong-typed Const in _int_matchsel() via get_function_sibling_type(), turn the tsmatchsel() Assert into a runtime vartype check and validate the operator up front in networksel()/networkjoinsel() - CVE-2026-2004 * SECURITY UPDATE: Heap buffer overflow in pgcrypto public-key decryption - debian/patches/CVE-2026-2005.patch: bounds-check the session key length against PGP_MAX_KEY in pgp_parse_pubenc_sesskey() before the memcpy() into ctx->sess_key, and add the PXE_PGP_KEY_TOO_BIG error - CVE-2026-2005 * SECURITY UPDATE: Buffer overrun via crafted multibyte characters - debian/patches/CVE-2026-2006.patch: replace pg_mblen() with the bounds-checked pg_mblen_cstr()/_with_len()/_range()/_unbounded() variants across all callers, fix the EUC_CN encoding length for SS2/SS3 lead bytes, guard the mb2wchar conversions on short input and require PGP-decrypted text to pass encoding validation; also take the upstream follow-up that keeps SUBSTRING() working on toasted multibyte values, by counting characters with the new pg_mbcharcliplen_chars() helper that stops at the substring end instead of running pg_mbstrlen_with_len() over the whole conservative detoast slice, whose tail is routinely a partial character - CVE-2026-2006
Updated packages:
  • libecpg-compat3-13_13.23-1~bookworm+tuxcare.els12_amd64.deb
    sha:0213bccd1433dd381b6daa2d2076f21d9f925b62
  • libecpg-dev-13_13.23-1~bookworm+tuxcare.els12_amd64.deb
    sha:fe395abc813cbd624135fb3ac5d65e4a440c9fab
  • libecpg6-13_13.23-1~bookworm+tuxcare.els12_amd64.deb
    sha:d7ffdebd6e619071bf1be6144002fd775ddce9bb
  • libpgtypes3-13_13.23-1~bookworm+tuxcare.els12_amd64.deb
    sha:71b96fd15f9d46208990e8ad5655b7db550d978c
  • libpq-dev-13_13.23-1~bookworm+tuxcare.els12_amd64.deb
    sha:71301811e69214fc6a6f1d8b4088ffdcc5ba85e0
  • libpq5-13_13.23-1~bookworm+tuxcare.els12_amd64.deb
    sha:4e1a037ea64dfd2f81b3ca15283b65d1a00efd72
  • postgresql13_13.23-1~bookworm+tuxcare.els12_amd64.deb
    sha:231dfeae7607b161ac81d760552f1dbf17b47304
  • postgresql13-client_13.23-1~bookworm+tuxcare.els12_amd64.deb
    sha:59618bdd5b65cf2b6c09dd57632902bd364c76d6
  • postgresql13-doc_13.23-1~bookworm+tuxcare.els12_all.deb
    sha:3e4269e8b9ad9c112f5801c621f0a8a5ed144f31
  • postgresql13-plperl_13.23-1~bookworm+tuxcare.els12_amd64.deb
    sha:01b5532ddce1fa316d6b71888a216706de54e9e4
  • postgresql13-plpython3_13.23-1~bookworm+tuxcare.els12_amd64.deb
    sha:57d206f791b3ae128c39c4cbc698e8fb537dae65
  • postgresql13-pltcl_13.23-1~bookworm+tuxcare.els12_amd64.deb
    sha:d56a1f332621a8cabe5ca904715edac99b41e9ea
  • postgresql13-server-dev_13.23-1~bookworm+tuxcare.els12_amd64.deb
    sha:abfe85041dbc697f2c176aa1bc1f7903d8b510a0
  • libecpg-compat3-13_13.23-1~bookworm+tuxcare.els12_arm64.deb
    sha:5075c66425b696cbc8a3dd1bdf159b49e2508087
  • libecpg-dev-13_13.23-1~bookworm+tuxcare.els12_arm64.deb
    sha:068319143e5218b140aba4d8a06f14fdb832d717
  • libecpg6-13_13.23-1~bookworm+tuxcare.els12_arm64.deb
    sha:17d0c147656e942529bb49f81da7a768389d5756
  • libpgtypes3-13_13.23-1~bookworm+tuxcare.els12_arm64.deb
    sha:2f6790e920869bace4e3ff58d3b3302b911a14cd
  • libpq-dev-13_13.23-1~bookworm+tuxcare.els12_arm64.deb
    sha:be6eded8f67c6e4500f8ed0b333d21e14efab4cd
  • libpq5-13_13.23-1~bookworm+tuxcare.els12_arm64.deb
    sha:54a9a8e78c0cbdff010dfc8c9a97a13b916f638b
  • postgresql13_13.23-1~bookworm+tuxcare.els12_arm64.deb
    sha:494e59c8d5a1ccf2f8197097d19a381a296fca31
  • postgresql13-client_13.23-1~bookworm+tuxcare.els12_arm64.deb
    sha:fb99e603ccc3b755a9573976d95625cf733a6f69
  • postgresql13-doc_13.23-1~bookworm+tuxcare.els12_all.deb
    sha:3e4269e8b9ad9c112f5801c621f0a8a5ed144f31
  • postgresql13-plperl_13.23-1~bookworm+tuxcare.els12_arm64.deb
    sha:90ac91262f8f4bccb9e0c65ba4e074f0656bf814
  • postgresql13-plpython3_13.23-1~bookworm+tuxcare.els12_arm64.deb
    sha:172ef705fb61235f98b95ede9165dbff9b69b7c3
  • postgresql13-pltcl_13.23-1~bookworm+tuxcare.els12_arm64.deb
    sha:eca2c417f950ccbac8ba44ba9f12899a70743774
  • postgresql13-server-dev_13.23-1~bookworm+tuxcare.els12_arm64.deb
    sha:621cfd9683bb8d29625ab0edbb01c50abae4e2a5
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.