Description:
* SECURITY UPDATE: heap buffer overflow in the regexp match and split
functions, where the conversion buffer was undersized for input that
does not pass encoding validation and grows when round tripped through
pg_wchar
- debian/patches/CVE-2026-14664.patch: always size the conversion buffer
as maxlen * eml + 1 instead of bounding it by the original string
length, in setup_regexp_matches() in
src/backend/utils/adt/regexp.c
- CVE-2026-14664
* SECURITY UPDATE: integer wraparound in the tsvector and tsquery data type
functions, letting an unprivileged database user undersize an allocation
and write out of bounds through crafted large inputs
- debian/patches/CVE-2026-14662.patch: widen the length accumulators to
size_t, reject empty and over long lexemes, enforce the MAXSTRPOS total
data limit in make_tsvector(), parsetext(), tsvectorrecv(),
tsvectorout(), array_to_tsvector(), cntsize() and fillQT(), and harden
the TSQUERY_TOO_BIG macro, in src/backend/tsearch/to_tsany.c,
ts_parse.c, src/backend/utils/adt/tsvector.c, tsvector_op.c,
tsquery_util.c and src/include/tsearch/ts_type.h
- CVE-2026-14662
* SECURITY UPDATE: improper neutralization of newlines in object names
written into pg_dump and pg_dumpall comments, which injected psql meta
commands that run when the dump is restored
- debian/patches/CVE-2025-8715.patch: move sanitize_line() out of
pg_backup_archiver.c into the shared dumputils.c and dumputils.h and
apply it to the partition root comment in dumpTableData() and to the
User Config and Database comments in dumpUserConfig() and
dumpDatabases(), in src/bin/pg_dump/dumputils.c, dumputils.h,
pg_backup_archiver.c, pg_dump.c and pg_dumpall.c
- CVE-2025-8715
* SECURITY UPDATE: untrusted data inclusion in plain text dumps, where a
malicious superuser of the origin server could inject psql meta commands
that run as the client operating system account restoring the dump
- debian/patches/CVE-2025-8714.patch: add a psql restricted mode with the
new \restrict and \unrestrict meta commands, emit those markers around
plain text dump output keyed by the new generate_restrict_key() and
valid_restrict_key() helpers, and add the --restrict-key option, in
src/bin/pg_dump/dumputils.c, dumputils.h, pg_backup.h,
pg_backup_archiver.c, pg_dump.c, pg_dumpall.c, pg_restore.c and
src/bin/psql/command.c
- CVE-2025-8714
* SECURITY UPDATE: shell command injection via backquote expansion in the
psql \unrestrict argument, which re-opened the CVE-2025-8714 attack by
letting a malicious server run commands on the machine restoring a
plain text dump
- debian/patches/CVE-2026-18408.patch: scan the \unrestrict argument in
OT_WHOLE_LINE mode so no backquote or variable expansion is performed,
strip trailing spaces and semicolons, and use ignore_slash_whole_line()
on the inactive branch, in src/bin/psql/command.c
- CVE-2026-18408
* SECURITY UPDATE: missing authorization in DDL commands, letting an object
creator create a dependency on a type and deny service against ALTER and
DROP of that type
- debian/patches/CVE-2026-6470.patch: add CheckUsageOnTypesInExpr() and
CheckUsageOnTypesInSingleRelExpr() and call them from every stored
expression path, and check ACL_USAGE on the range subtype in
DefineRange() and on the composite type in ATExecAddOf(), in
src/backend/catalog/dependency.c, heap.c, pg_proc.c,
src/backend/commands/indexcmds.c, policy.c, tablecmds.c, trigger.c,
typecmds.c, src/backend/parser/parse_utilcmd.c and
src/backend/rewrite/rewriteDefine.c
- CVE-2026-6470