[CLSA-2026:1786965297] Fix CVE(s): CVE-2026-2003, CVE-2026-2004, CVE-2026-2005, CVE-2026-2006
Type:
security
Severity:
Important
Release date:
2026-08-17 11:15:10 UTC
Description:
* SECURITY UPDATE: server crash or disclosure of server memory via improperly validated oidvector and int2vector input values - debian/patches/CVE-2026-2003.patch: add check_valid_oidvector() and check_valid_int2vector() validators and call them from the hash, btree comparison and output functions of the two types, in src/backend/access/hash/hashfunc.c, src/backend/access/nbtree/nbtcompare.c, src/backend/utils/adt/format_type.c, int.c, oid.c and src/include/utils/builtins.h - CVE-2026-2003 * SECURITY UPDATE: memory disclosure or arbitrary code execution via selectivity estimator functions attached to operators with mismatched operand types - debian/patches/CVE-2026-2004.patch: require superuser to attach a non-built-in restriction or join estimator to an operator and verify the operand types of tsmatchsel(), networksel() and the intarray _int_matchsel() at run time, adding a get_function_sibling_type() helper backed by a new pg_extension.oid syscache, in src/backend/commands/operatorcmds.c, extension.c, src/backend/tsearch/ts_selfuncs.c, src/backend/utils/adt/network_selfuncs.c, src/backend/utils/cache/syscache.c, src/backend/catalog/pg_depend.c and contrib/intarray/_int_selfuncs.c - CVE-2026-2004 * SECURITY UPDATE: heap buffer overflow in pgcrypto public key decryption via an oversized session key in a crafted OpenPGP message - debian/patches/CVE-2026-2005.patch: validate the session key length against PGP_MAX_KEY in pgp_parse_pubenc_sesskey() and fail with the new PXE_PGP_KEY_TOO_BIG error instead of overflowing the context buffer, in contrib/pgcrypto/pgp-pubdec.c, px.c and px.h, with a new pgp-pubkey-session regression test - CVE-2026-2005 * SECURITY UPDATE: buffer overread in multibyte character processing via invalidly encoded or truncated strings reaching pg_mblen() callers - debian/patches/CVE-2026-2006.patch: introduce bounds-aware pg_mblen_cstr(), pg_mblen_range() and pg_mblen_with_len() and switch pg_mblen() call sites over to them, fix mb2wchar conversion of short input and the EUC_CN maximum character length, require PGP-decrypted text to pass encoding validation, and stop text_substring() from reading past a truncated multibyte character, in src/backend/utils/mb/mbutils.c, wchar.c, src/include/mb/pg_wchar.h, src/backend/utils/adt/varlena.c, json.c, regexp.c, src/backend/parser/scan.l, contrib/pgcrypto/pgp-pgsql.c, the tsearch parsers and the btree_gist, dict_xsyn, ltree, pg_trgm and unaccent contrib modules - CVE-2026-2006
Updated packages:
  • libecpg-compat3-12_12.22-2~trixie+tuxcare.els10_amd64.deb
    sha:6d2cd3d81bf93fae6d8b917196dafe1ba5fa29ba
  • libecpg-dev-12_12.22-2~trixie+tuxcare.els10_amd64.deb
    sha:ff2d68dca421cd9514652aa5028a92766e823529
  • libecpg6-12_12.22-2~trixie+tuxcare.els10_amd64.deb
    sha:1fbf2cb936373606502d788ac22e38b053cc34b6
  • libpgtypes3-12_12.22-2~trixie+tuxcare.els10_amd64.deb
    sha:bc228a17ad3c3d35f53f9001c774ae21f28329ce
  • libpq-dev-12_12.22-2~trixie+tuxcare.els10_amd64.deb
    sha:7eefdd455496dadf9ad1c4731ef484b6a93a823d
  • libpq5-12_12.22-2~trixie+tuxcare.els10_amd64.deb
    sha:4d4568fc31bbdd3996d05d37cdfd31b441efef95
  • postgresql12_12.22-2~trixie+tuxcare.els10_amd64.deb
    sha:1aedc2737b871603c5270f93ca60152d8dd9b0b0
  • postgresql12-client_12.22-2~trixie+tuxcare.els10_amd64.deb
    sha:1d22801cdb5e95ab4e22280ad7f6e7d04a12a1b5
  • postgresql12-doc_12.22-2~trixie+tuxcare.els10_all.deb
    sha:92d838ec5bdd71b1c3a090fba56cfa1b47d5c7f6
  • postgresql12-plperl_12.22-2~trixie+tuxcare.els10_amd64.deb
    sha:3f140ad016ced79f65840e6bce5f9dc80c26c5e4
  • postgresql12-plpython3_12.22-2~trixie+tuxcare.els10_amd64.deb
    sha:fc041471784a52bce8fd71e0d31c019ea5119d1b
  • postgresql12-pltcl_12.22-2~trixie+tuxcare.els10_amd64.deb
    sha:7dfc4b3359b27bc2777f9d709f81d50586b53dc8
  • postgresql12-server-dev_12.22-2~trixie+tuxcare.els10_amd64.deb
    sha:1ede501ab1a01a80af090bf285075385535784d9
  • libecpg-compat3-12_12.22-2~trixie+tuxcare.els10_arm64.deb
    sha:e24d2d6960817e71f93de342c1036291d1e4d986
  • libecpg-dev-12_12.22-2~trixie+tuxcare.els10_arm64.deb
    sha:9430aeacf7f1403d88d82978d76515244067065b
  • libecpg6-12_12.22-2~trixie+tuxcare.els10_arm64.deb
    sha:b046c8eb6b0a0a892b551636ab846f7e6a0b35ef
  • libpgtypes3-12_12.22-2~trixie+tuxcare.els10_arm64.deb
    sha:51af7effed23bbc102a3db642bdf0aa981770de2
  • libpq-dev-12_12.22-2~trixie+tuxcare.els10_arm64.deb
    sha:f86eec297e2b239a6f8f32321d722af97fa0c118
  • libpq5-12_12.22-2~trixie+tuxcare.els10_arm64.deb
    sha:33271f012111d9d650c5def1843dfb2cccb0b8f6
  • postgresql12_12.22-2~trixie+tuxcare.els10_arm64.deb
    sha:c7e842619b2fb7648b9d4560755bda46d5a0882b
  • postgresql12-client_12.22-2~trixie+tuxcare.els10_arm64.deb
    sha:d556edf5417edd56897f9a478b0b346cc75bf8ef
  • postgresql12-doc_12.22-2~trixie+tuxcare.els10_all.deb
    sha:92d838ec5bdd71b1c3a090fba56cfa1b47d5c7f6
  • postgresql12-plperl_12.22-2~trixie+tuxcare.els10_arm64.deb
    sha:bdd930853cfb09f2cb4dc61b0455b4853d4dd632
  • postgresql12-plpython3_12.22-2~trixie+tuxcare.els10_arm64.deb
    sha:b53d8a3ca89cfcafe99f9d1485e02c1c3656a698
  • postgresql12-pltcl_12.22-2~trixie+tuxcare.els10_arm64.deb
    sha:fecf146e5c9fd4b2958fe2967f81447c260250a4
  • postgresql12-server-dev_12.22-2~trixie+tuxcare.els10_arm64.deb
    sha:640056d4588be4299ab7489bcc5613d7b6e06624
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.