Release date:
2026-08-14 12:34:22 UTC
Description:
* SECURITY UPDATE: out-of-bounds reads and backend crashes via oidvector and int2vector values with unexpected array dimensions, reachable because a general oid[] or int2[] array can be cast to the vector type
- debian/patches/CVE-2026-2003.patch: add check_valid_oidvector() and
check_valid_int2vector() validators that reject arrays whose ndim,
dataoffset or elemtype violate the vector type's restrictions, and call
them before reading dim1 in the hashing, btree comparison, input and
format_type paths in src/backend/access/hash/hashfunc.c,
src/backend/access/nbtree/nbtcompare.c,
src/backend/utils/adt/format_type.c, src/backend/utils/adt/int.c,
src/backend/utils/adt/oid.c and src/include/utils/builtins.h
- CVE-2026-2003
* SECURITY UPDATE: a non-superuser can install an arbitrary function as an operator's restriction or join selectivity estimator, and built-in estimators can be attached to an operator of the wrong type
- debian/patches/CVE-2026-2004.patch: require superuser to specify a
non-built-in restriction or join selectivity estimator in CREATE OPERATOR
while requiring only EXECUTE rights for built-in ones, add
get_function_sibling_type() and harden the intarray, tsearch and network
selectivity estimators against being attached to the wrong operator, and
backport the upstream pg_extension.oid syscache (EXTENSIONOID) that
PostgreSQL 11 lacks, in contrib/intarray/_int_selfuncs.c,
src/backend/commands/operatorcmds.c, src/backend/commands/extension.c,
src/backend/catalog/pg_depend.c, src/backend/tsearch/ts_selfuncs.c,
src/backend/utils/adt/network_selfuncs.c,
src/backend/utils/cache/syscache.c and their headers
- CVE-2026-2004
* SECURITY UPDATE: buffer overflow in pgp_pub_decrypt_bytea() in pgcrypto when the PGP session key is longer than the destination buffer
- debian/patches/CVE-2026-2005.patch: bound the session key length against
PGP_MAX_KEY before storing it in the decryption context and report the new
PXE_PGP_KEY_TOO_BIG error instead of overrunning the buffer, in
contrib/pgcrypto/pgp-pubdec.c, contrib/pgcrypto/px.c and
contrib/pgcrypto/px.h
- CVE-2026-2005
* SECURITY UPDATE: out-of-bounds reads when measuring truncated or invalid multibyte characters, an understated maximum character length for EUC_CN, and missing encoding validation of PGP-decrypted text
- debian/patches/CVE-2026-2006.patch: replace the unbounded pg_mblen() with
the bounds-checked pg_mblen_with_len(), pg_mblen_range() and
pg_mblen_unbounded() variants throughout the backend, tsearch, ltree,
pg_trgm, btree_gist, unaccent and dict_xsyn code, make the mb2wchar
conversion functions tolerate short input, raise the EUC_CN maximum
character length from 2 to 3 so SS2 and SS3 sequences are measured
correctly in src/backend/utils/mb/wchar.c, and require PGP-decrypted text
to pass pg_verifymbstr() encoding validation in
contrib/pgcrypto/pgp-pgsql.c
- CVE-2026-2006
Updated packages:
-
libecpg-compat3-11_11.22-1~trixie+tuxcare.els13_amd64.deb
sha:6382d929c72019d55c91e02abbbab804e392acbf
-
libecpg-dev-11_11.22-1~trixie+tuxcare.els13_amd64.deb
sha:f00a8615ee937022d7c7fc08946160c16de5063e
-
libecpg6-11_11.22-1~trixie+tuxcare.els13_amd64.deb
sha:5dca3f27fe4448a4b10b70cd3dce0a63d52dc3f5
-
libpgtypes3-11_11.22-1~trixie+tuxcare.els13_amd64.deb
sha:6e8deb7429171c7e1cb62e6c23acdfc175cd97bf
-
libpq-dev-11_11.22-1~trixie+tuxcare.els13_amd64.deb
sha:0b10c55ea21927ea1a4ef5377e533d17a6b0d0bf
-
libpq5-11_11.22-1~trixie+tuxcare.els13_amd64.deb
sha:b6482f54ec1c6f3dbacbce603fe30b6185f60c8f
-
postgresql11_11.22-1~trixie+tuxcare.els13_amd64.deb
sha:28163f7de233f7ba83c12bc2b5f2437d4fef7cb9
-
postgresql11-client_11.22-1~trixie+tuxcare.els13_amd64.deb
sha:8483876f1b55e1b7af431060b5f4381a9bd818dd
-
postgresql11-doc_11.22-1~trixie+tuxcare.els13_all.deb
sha:cdaf235aa1b9f288bf556d77cf19ce72a74eed0a
-
postgresql11-plperl_11.22-1~trixie+tuxcare.els13_amd64.deb
sha:d74c2442358676a4ced3f29f2e53064e2c5c847b
-
postgresql11-plpython3_11.22-1~trixie+tuxcare.els13_amd64.deb
sha:a8c0f7ff7b9f095277da7604ba8da2e07d6491ee
-
postgresql11-pltcl_11.22-1~trixie+tuxcare.els13_amd64.deb
sha:ddc819e2569d7ab7397e8a478989a0165416ce53
-
postgresql11-server-dev_11.22-1~trixie+tuxcare.els13_amd64.deb
sha:d0c9e063cabe018da5142f6b9802f13bab7e7132
-
libecpg-compat3-11_11.22-1~trixie+tuxcare.els13_arm64.deb
sha:0668306cd9b703775c423e63b68376169b0a5c4c
-
libecpg-dev-11_11.22-1~trixie+tuxcare.els13_arm64.deb
sha:e61fa23247175f4af79ea4a0a7ed30204f573e8b
-
libecpg6-11_11.22-1~trixie+tuxcare.els13_arm64.deb
sha:a4e86ba80de332922795db7b53169ec29b3fcea9
-
libpgtypes3-11_11.22-1~trixie+tuxcare.els13_arm64.deb
sha:4342e6199952755a2a08c49d09cfc9f425ec98b4
-
libpq-dev-11_11.22-1~trixie+tuxcare.els13_arm64.deb
sha:4ad7a821b7486a0e58370e03a6ee388d9eb72fbf
-
libpq5-11_11.22-1~trixie+tuxcare.els13_arm64.deb
sha:a0e49e038e965cf99ae3357d3bdafdef9278594f
-
postgresql11_11.22-1~trixie+tuxcare.els13_arm64.deb
sha:e8fc496f14015d3f161c7cb7a2722295b1fe0b1f
-
postgresql11-client_11.22-1~trixie+tuxcare.els13_arm64.deb
sha:92fc88608fa0aad358c1b88fb4ff246e808a721c
-
postgresql11-doc_11.22-1~trixie+tuxcare.els13_all.deb
sha:cdaf235aa1b9f288bf556d77cf19ce72a74eed0a
-
postgresql11-plperl_11.22-1~trixie+tuxcare.els13_arm64.deb
sha:c7f5d011af420f582d416680bab907c936061489
-
postgresql11-plpython3_11.22-1~trixie+tuxcare.els13_arm64.deb
sha:c8472e5646dc489cca74b09317408849ff2e4866
-
postgresql11-pltcl_11.22-1~trixie+tuxcare.els13_arm64.deb
sha:d70e50525a9149ad1fb3a55b1341f638cce8c7e2
-
postgresql11-server-dev_11.22-1~trixie+tuxcare.els13_arm64.deb
sha:7d95757d35991c32a06eea6133f1cced3f6cf8e1
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.