[CLSA-2026:1786713443] Fix CVE(s): CVE-2026-2003, CVE-2026-2004, CVE-2026-2005, CVE-2026-2006
Type:
security
Severity:
Important
Release date:
2026-08-14 13:17:37 UTC
Description:
* SECURITY UPDATE: Server memory disclosure via crafted oidvector/int2vector - debian/patches/CVE-2026-2003.patch: add check_valid_oidvector() and check_valid_int2vector() and call them from hashoidvector(), hashoidvectorextended(), btoidvectorcmp(), oidvectortypes(), int2vectorout() and oidvectorout(), so an oid[] or int2[] array cast to these types cannot violate the 1-dimensional, no-nulls layout those functions assume - CVE-2026-2003 * SECURITY UPDATE: Arbitrary code execution via intarray selectivity estimator - debian/patches/CVE-2026-2004.patch: require superuser to attach a non-built-in restriction or join selectivity estimator, reject a wrong-typed Const in _int_matchsel() via get_function_sibling_type(), turn the tsmatchsel() Assert into a runtime vartype check and validate the operator up front in networksel()/networkjoinsel() - CVE-2026-2004 * SECURITY UPDATE: Heap buffer overflow in pgcrypto public-key decryption - debian/patches/CVE-2026-2005.patch: bounds-check the session key length against PGP_MAX_KEY in pgp_parse_pubenc_sesskey() before the memcpy() into ctx->sess_key, and add the PXE_PGP_KEY_TOO_BIG error - CVE-2026-2005 * SECURITY UPDATE: Buffer overrun via crafted multibyte characters - debian/patches/CVE-2026-2006.patch: replace pg_mblen() with the bounds-checked pg_mblen_cstr()/_with_len()/_range()/_unbounded() variants across all callers, fix the EUC_CN encoding length for SS2/SS3 lead bytes, guard the mb2wchar conversions on short input and require PGP-decrypted text to pass encoding validation; also take the upstream follow-up that keeps SUBSTRING() working on toasted multibyte values, by counting characters with the new pg_mbcharcliplen_chars() helper that stops at the substring end instead of running pg_mbstrlen_with_len() over the whole conservative detoast slice, whose tail is routinely a partial character - CVE-2026-2006
Updated packages:
  • libecpg-compat3-13_13.23-1~trixie+tuxcare.els12_amd64.deb
    sha:5232a2a44e742ba334cfcd3d4f158cbd0d347b0d
  • libecpg-dev-13_13.23-1~trixie+tuxcare.els12_amd64.deb
    sha:7e499971ec6f855c7ab095cb93ad49a579446f21
  • libecpg6-13_13.23-1~trixie+tuxcare.els12_amd64.deb
    sha:8345dd9fc5f0eab8b8eb6635db5da66e303e0c3d
  • libpgtypes3-13_13.23-1~trixie+tuxcare.els12_amd64.deb
    sha:eec19086633f6c74dae2f14cbac099881916999f
  • libpq-dev-13_13.23-1~trixie+tuxcare.els12_amd64.deb
    sha:1a22c7b04bcfa3c6b52215ea89597db9a40b759b
  • libpq5-13_13.23-1~trixie+tuxcare.els12_amd64.deb
    sha:67d43565bdadf4bd4cf8912bce29edc02d8c11f3
  • postgresql13_13.23-1~trixie+tuxcare.els12_amd64.deb
    sha:f5a1b055500131a490f4d82f71b29e48fe346fca
  • postgresql13-client_13.23-1~trixie+tuxcare.els12_amd64.deb
    sha:de218089d3f681ce4dc0725c1b8334528521e8cd
  • postgresql13-doc_13.23-1~trixie+tuxcare.els12_all.deb
    sha:d5127d734dd69405f1f3bee75e15b104e53926bf
  • postgresql13-plperl_13.23-1~trixie+tuxcare.els12_amd64.deb
    sha:2898d842c488b24f512b90d10d92a45fffc17b82
  • postgresql13-plpython3_13.23-1~trixie+tuxcare.els12_amd64.deb
    sha:1a8477dfd8e4af3c8d41b2858c56623bef86136b
  • postgresql13-pltcl_13.23-1~trixie+tuxcare.els12_amd64.deb
    sha:5212605b8f39007d451c3b7dbfcb920a1e0e0c3d
  • postgresql13-server-dev_13.23-1~trixie+tuxcare.els12_amd64.deb
    sha:c4b4f35cc00cf38b9f5ca75c820f95210aa1b26c
  • libecpg-compat3-13_13.23-1~trixie+tuxcare.els12_arm64.deb
    sha:2125239f2ac72663d29978904bff8b288953719a
  • libecpg-dev-13_13.23-1~trixie+tuxcare.els12_arm64.deb
    sha:343fef12fa515d896ca548e5b732344d38a62b2a
  • libecpg6-13_13.23-1~trixie+tuxcare.els12_arm64.deb
    sha:c43a8f54146f0dce65ae70a8b7b14c7c789a8816
  • libpgtypes3-13_13.23-1~trixie+tuxcare.els12_arm64.deb
    sha:8d835fcb1e9fa3cd7bf54d349760bd672971d7a7
  • libpq-dev-13_13.23-1~trixie+tuxcare.els12_arm64.deb
    sha:8c9219f0aee1549235fc8911f9bcbaff694319c7
  • libpq5-13_13.23-1~trixie+tuxcare.els12_arm64.deb
    sha:9e3b23d60b533007ca8103026dbcff326243d936
  • postgresql13_13.23-1~trixie+tuxcare.els12_arm64.deb
    sha:71a98f81650bdc089cec3f973fb2d405c3f21bdd
  • postgresql13-client_13.23-1~trixie+tuxcare.els12_arm64.deb
    sha:c2e57e3503e098795a423a4caba67b4bfe24bedd
  • postgresql13-doc_13.23-1~trixie+tuxcare.els12_all.deb
    sha:d5127d734dd69405f1f3bee75e15b104e53926bf
  • postgresql13-plperl_13.23-1~trixie+tuxcare.els12_arm64.deb
    sha:2835db64930f131d9b59e9a7e8524025b1e7449b
  • postgresql13-plpython3_13.23-1~trixie+tuxcare.els12_arm64.deb
    sha:8f4cb55ee76c9cb526af27f7b3df45221a3b7f22
  • postgresql13-pltcl_13.23-1~trixie+tuxcare.els12_arm64.deb
    sha:c81312a5c95f34a1d78bac121cefc8e86c9fcb6d
  • postgresql13-server-dev_13.23-1~trixie+tuxcare.els12_arm64.deb
    sha:ae52f76a242e3ca19713058fd8355a31c9d9ebcd
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.