[CLSA-2026:1790937511] Fix of 6 CVEs
Type:
security
Severity:
Important
Release date:
2026-10-02 10:39:02 UTC
Description:
* SECURITY UPDATE: heap buffer overflow in the regexp match and split functions, where the conversion buffer was undersized for input that does not pass encoding validation and grows when round tripped through pg_wchar - debian/patches/CVE-2026-14664.patch: always size the conversion buffer as maxlen * eml + 1 instead of bounding it by the original string length, in setup_regexp_matches() in src/backend/utils/adt/regexp.c - CVE-2026-14664 * SECURITY UPDATE: integer wraparound in the tsvector and tsquery data type functions, letting an unprivileged database user undersize an allocation and write out of bounds through crafted large inputs - debian/patches/CVE-2026-14662.patch: widen the length accumulators to size_t, reject empty and over long lexemes, enforce the MAXSTRPOS total data limit in make_tsvector(), parsetext(), tsvectorrecv(), tsvectorout(), array_to_tsvector(), cntsize() and fillQT(), and harden the TSQUERY_TOO_BIG macro, in src/backend/tsearch/to_tsany.c, ts_parse.c, src/backend/utils/adt/tsvector.c, tsvector_op.c, tsquery_util.c and src/include/tsearch/ts_type.h - CVE-2026-14662 * SECURITY UPDATE: improper neutralization of newlines in object names written into pg_dump and pg_dumpall comments, which injected psql meta commands that run when the dump is restored - debian/patches/CVE-2025-8715.patch: move sanitize_line() out of pg_backup_archiver.c into the shared dumputils.c and dumputils.h and apply it to the partition root comment in dumpTableData() and to the User Config and Database comments in dumpUserConfig() and dumpDatabases(), in src/bin/pg_dump/dumputils.c, dumputils.h, pg_backup_archiver.c, pg_dump.c and pg_dumpall.c - CVE-2025-8715 * SECURITY UPDATE: untrusted data inclusion in plain text dumps, where a malicious superuser of the origin server could inject psql meta commands that run as the client operating system account restoring the dump - debian/patches/CVE-2025-8714.patch: add a psql restricted mode with the new \restrict and \unrestrict meta commands, emit those markers around plain text dump output keyed by the new generate_restrict_key() and valid_restrict_key() helpers, and add the --restrict-key option, in src/bin/pg_dump/dumputils.c, dumputils.h, pg_backup.h, pg_backup_archiver.c, pg_dump.c, pg_dumpall.c, pg_restore.c and src/bin/psql/command.c - CVE-2025-8714 * SECURITY UPDATE: shell command injection via backquote expansion in the psql \unrestrict argument, which re-opened the CVE-2025-8714 attack by letting a malicious server run commands on the machine restoring a plain text dump - debian/patches/CVE-2026-18408.patch: scan the \unrestrict argument in OT_WHOLE_LINE mode so no backquote or variable expansion is performed, strip trailing spaces and semicolons, and use ignore_slash_whole_line() on the inactive branch, in src/bin/psql/command.c - CVE-2026-18408 * SECURITY UPDATE: missing authorization in DDL commands, letting an object creator create a dependency on a type and deny service against ALTER and DROP of that type - debian/patches/CVE-2026-6470.patch: add CheckUsageOnTypesInExpr() and CheckUsageOnTypesInSingleRelExpr() and call them from every stored expression path, and check ACL_USAGE on the range subtype in DefineRange() and on the composite type in ATExecAddOf(), in src/backend/catalog/dependency.c, heap.c, pg_proc.c, src/backend/commands/indexcmds.c, policy.c, tablecmds.c, trigger.c, typecmds.c, src/backend/parser/parse_utilcmd.c and src/backend/rewrite/rewriteDefine.c - CVE-2026-6470
Updated packages:
  • libecpg-compat3-12_12.22-2~trixie+tuxcare.els14_amd64.deb
    sha:8642eabf47314215b41be78167d0bc26007e88be
  • libecpg-dev-12_12.22-2~trixie+tuxcare.els14_amd64.deb
    sha:257ca42539d49d3eb932514c53ec3dd1b450c8a3
  • libecpg6-12_12.22-2~trixie+tuxcare.els14_amd64.deb
    sha:906f2c534d60600d823841c30307f035ec6e0ddf
  • libpgtypes3-12_12.22-2~trixie+tuxcare.els14_amd64.deb
    sha:0f020a5c27f07e7d4344edcb7485ddd44b85d4bd
  • libpq-dev-12_12.22-2~trixie+tuxcare.els14_amd64.deb
    sha:328ce2de90adc65ca13472baa208a3e5262427ee
  • libpq5-12_12.22-2~trixie+tuxcare.els14_amd64.deb
    sha:4d70b504b7360eb59d6c2eee3d0d597da2380568
  • postgresql12_12.22-2~trixie+tuxcare.els14_amd64.deb
    sha:d34f0756ff2847a86e5c0ab21a6b3b93d980efce
  • postgresql12-client_12.22-2~trixie+tuxcare.els14_amd64.deb
    sha:1574e30b3f4a338d9665a5463e2d261fb30b2075
  • postgresql12-doc_12.22-2~trixie+tuxcare.els14_all.deb
    sha:cb4ec64b374a40bc4d0029632953de60d0177ca3
  • postgresql12-plperl_12.22-2~trixie+tuxcare.els14_amd64.deb
    sha:8151c07d289edfc59533c69cb307e5d23a9c770b
  • postgresql12-plpython3_12.22-2~trixie+tuxcare.els14_amd64.deb
    sha:86b576cd770d4f0fd26c0e2df3d7e7fa76095d58
  • postgresql12-pltcl_12.22-2~trixie+tuxcare.els14_amd64.deb
    sha:d2773176f4ae251e0d2962473b07b1b579e2fcb8
  • postgresql12-server-dev_12.22-2~trixie+tuxcare.els14_amd64.deb
    sha:bfdd07f55e319aa4338270239b8df731154f67de
  • libecpg-compat3-12_12.22-2~trixie+tuxcare.els14_arm64.deb
    sha:4696895ff299040ac9266c60fd3b8cf950fde24b
  • libecpg-dev-12_12.22-2~trixie+tuxcare.els14_arm64.deb
    sha:fecb09c1079d66178f5b672f42bfff4947e08325
  • libecpg6-12_12.22-2~trixie+tuxcare.els14_arm64.deb
    sha:69e46a55143ca172d122466beacc088090db4257
  • libpgtypes3-12_12.22-2~trixie+tuxcare.els14_arm64.deb
    sha:3fb18a55dc28fc7e50344eb554eeb2e8f845b0b7
  • libpq-dev-12_12.22-2~trixie+tuxcare.els14_arm64.deb
    sha:ac001aa64933d30a8e143b05965209a8fbbdb974
  • libpq5-12_12.22-2~trixie+tuxcare.els14_arm64.deb
    sha:c02754042772dc6e990ac4aaeae71f070c791c54
  • postgresql12_12.22-2~trixie+tuxcare.els14_arm64.deb
    sha:b35faf6720418bac732c900f00960124676ec545
  • postgresql12-client_12.22-2~trixie+tuxcare.els14_arm64.deb
    sha:01774e0e2a8ca5d642a3e7c47f275b8eaf658049
  • postgresql12-plperl_12.22-2~trixie+tuxcare.els14_arm64.deb
    sha:9aaff19bd743243bb45a0e1d8f46fcdaad4f3a30
  • postgresql12-plpython3_12.22-2~trixie+tuxcare.els14_arm64.deb
    sha:ffa0d056f9774cac8a8870f6d5940a9ae46e2668
  • postgresql12-pltcl_12.22-2~trixie+tuxcare.els14_arm64.deb
    sha:b1b91d2d84ac74a3457cffcfe2d86b0ed8c01d5d
  • postgresql12-server-dev_12.22-2~trixie+tuxcare.els14_arm64.deb
    sha:51157e34bdc99d52704507262694c7828d1df5c5
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.