Release date:
2026-08-17 11:15:10 UTC
Description:
* SECURITY UPDATE: server crash or disclosure of server memory via
improperly validated oidvector and int2vector input values
- debian/patches/CVE-2026-2003.patch: add check_valid_oidvector() and
check_valid_int2vector() validators and call them from the hash,
btree comparison and output functions of the two types, in
src/backend/access/hash/hashfunc.c,
src/backend/access/nbtree/nbtcompare.c,
src/backend/utils/adt/format_type.c, int.c, oid.c and
src/include/utils/builtins.h
- CVE-2026-2003
* SECURITY UPDATE: memory disclosure or arbitrary code execution via
selectivity estimator functions attached to operators with mismatched
operand types
- debian/patches/CVE-2026-2004.patch: require superuser to attach a
non-built-in restriction or join estimator to an operator and verify
the operand types of tsmatchsel(), networksel() and the intarray
_int_matchsel() at run time, adding a get_function_sibling_type()
helper backed by a new pg_extension.oid syscache, in
src/backend/commands/operatorcmds.c, extension.c,
src/backend/tsearch/ts_selfuncs.c,
src/backend/utils/adt/network_selfuncs.c,
src/backend/utils/cache/syscache.c, src/backend/catalog/pg_depend.c
and contrib/intarray/_int_selfuncs.c
- CVE-2026-2004
* SECURITY UPDATE: heap buffer overflow in pgcrypto public key decryption
via an oversized session key in a crafted OpenPGP message
- debian/patches/CVE-2026-2005.patch: validate the session key length
against PGP_MAX_KEY in pgp_parse_pubenc_sesskey() and fail with the
new PXE_PGP_KEY_TOO_BIG error instead of overflowing the context
buffer, in contrib/pgcrypto/pgp-pubdec.c, px.c and px.h, with a new
pgp-pubkey-session regression test
- CVE-2026-2005
* SECURITY UPDATE: buffer overread in multibyte character processing via
invalidly encoded or truncated strings reaching pg_mblen() callers
- debian/patches/CVE-2026-2006.patch: introduce bounds-aware
pg_mblen_cstr(), pg_mblen_range() and pg_mblen_with_len() and switch
pg_mblen() call sites over to them, fix mb2wchar conversion of short
input and the EUC_CN maximum character length, require PGP-decrypted
text to pass encoding validation, and stop text_substring() from
reading past a truncated multibyte character, in
src/backend/utils/mb/mbutils.c, wchar.c, src/include/mb/pg_wchar.h,
src/backend/utils/adt/varlena.c, json.c, regexp.c,
src/backend/parser/scan.l, contrib/pgcrypto/pgp-pgsql.c, the tsearch
parsers and the btree_gist, dict_xsyn, ltree, pg_trgm and unaccent
contrib modules
- CVE-2026-2006
Updated packages:
-
libecpg-compat3-12_12.22-2~trixie+tuxcare.els10_amd64.deb
sha:6d2cd3d81bf93fae6d8b917196dafe1ba5fa29ba
-
libecpg-dev-12_12.22-2~trixie+tuxcare.els10_amd64.deb
sha:ff2d68dca421cd9514652aa5028a92766e823529
-
libecpg6-12_12.22-2~trixie+tuxcare.els10_amd64.deb
sha:1fbf2cb936373606502d788ac22e38b053cc34b6
-
libpgtypes3-12_12.22-2~trixie+tuxcare.els10_amd64.deb
sha:bc228a17ad3c3d35f53f9001c774ae21f28329ce
-
libpq-dev-12_12.22-2~trixie+tuxcare.els10_amd64.deb
sha:7eefdd455496dadf9ad1c4731ef484b6a93a823d
-
libpq5-12_12.22-2~trixie+tuxcare.els10_amd64.deb
sha:4d4568fc31bbdd3996d05d37cdfd31b441efef95
-
postgresql12_12.22-2~trixie+tuxcare.els10_amd64.deb
sha:1aedc2737b871603c5270f93ca60152d8dd9b0b0
-
postgresql12-client_12.22-2~trixie+tuxcare.els10_amd64.deb
sha:1d22801cdb5e95ab4e22280ad7f6e7d04a12a1b5
-
postgresql12-doc_12.22-2~trixie+tuxcare.els10_all.deb
sha:92d838ec5bdd71b1c3a090fba56cfa1b47d5c7f6
-
postgresql12-plperl_12.22-2~trixie+tuxcare.els10_amd64.deb
sha:3f140ad016ced79f65840e6bce5f9dc80c26c5e4
-
postgresql12-plpython3_12.22-2~trixie+tuxcare.els10_amd64.deb
sha:fc041471784a52bce8fd71e0d31c019ea5119d1b
-
postgresql12-pltcl_12.22-2~trixie+tuxcare.els10_amd64.deb
sha:7dfc4b3359b27bc2777f9d709f81d50586b53dc8
-
postgresql12-server-dev_12.22-2~trixie+tuxcare.els10_amd64.deb
sha:1ede501ab1a01a80af090bf285075385535784d9
-
libecpg-compat3-12_12.22-2~trixie+tuxcare.els10_arm64.deb
sha:e24d2d6960817e71f93de342c1036291d1e4d986
-
libecpg-dev-12_12.22-2~trixie+tuxcare.els10_arm64.deb
sha:9430aeacf7f1403d88d82978d76515244067065b
-
libecpg6-12_12.22-2~trixie+tuxcare.els10_arm64.deb
sha:b046c8eb6b0a0a892b551636ab846f7e6a0b35ef
-
libpgtypes3-12_12.22-2~trixie+tuxcare.els10_arm64.deb
sha:51af7effed23bbc102a3db642bdf0aa981770de2
-
libpq-dev-12_12.22-2~trixie+tuxcare.els10_arm64.deb
sha:f86eec297e2b239a6f8f32321d722af97fa0c118
-
libpq5-12_12.22-2~trixie+tuxcare.els10_arm64.deb
sha:33271f012111d9d650c5def1843dfb2cccb0b8f6
-
postgresql12_12.22-2~trixie+tuxcare.els10_arm64.deb
sha:c7e842619b2fb7648b9d4560755bda46d5a0882b
-
postgresql12-client_12.22-2~trixie+tuxcare.els10_arm64.deb
sha:d556edf5417edd56897f9a478b0b346cc75bf8ef
-
postgresql12-doc_12.22-2~trixie+tuxcare.els10_all.deb
sha:92d838ec5bdd71b1c3a090fba56cfa1b47d5c7f6
-
postgresql12-plperl_12.22-2~trixie+tuxcare.els10_arm64.deb
sha:bdd930853cfb09f2cb4dc61b0455b4853d4dd632
-
postgresql12-plpython3_12.22-2~trixie+tuxcare.els10_arm64.deb
sha:b53d8a3ca89cfcafe99f9d1485e02c1c3656a698
-
postgresql12-pltcl_12.22-2~trixie+tuxcare.els10_arm64.deb
sha:fecf146e5c9fd4b2958fe2967f81447c260250a4
-
postgresql12-server-dev_12.22-2~trixie+tuxcare.els10_arm64.deb
sha:640056d4588be4299ab7489bcc5613d7b6e06624
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.