[CLSA-2026:1790938557] Fix of 5 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-10-02 10:56:24 UTC
Description:
* SECURITY UPDATE: SQL injection in psql where in-line COPY ... FROM STDIN data was executed as SQL commands when the COPY command failed or was skipped inside an \if branch - debian/patches/CVE-2026-6464.patch: teach the lexer to recognize and count COPY ... FROM STDIN commands via copy_stdin_count and psqlscan_is_copy_from_stdin(), save and restore the full lexer state when skipping \if branches, and make SendQuery() read and discard the pending COPY data through handleCopyIn() with a NULL connection, in src/bin/psql/command.c, common.c, copy.c, mainloop.c, startup.c, psqlscanslash.l, src/fe_utils/conditional.c and psqlscan.l - CVE-2026-6464 * SECURITY UPDATE: out of bounds reads in the ascii() function on invalid multibyte input, able to disclose bytes of server memory or trigger assertion failures - debian/patches/CVE-2026-18024.patch: validate the multibyte sequence length against the input length and replace the byte range assertions with ERRCODE_CHARACTER_NOT_IN_REPERTOIRE errors, in ascii() in src/backend/utils/adt/oracle_compat.c - CVE-2026-18024 * SECURITY UPDATE: stale cached plans kept enforcing outdated row level security policies after role membership or role attribute changes - debian/patches/CVE-2026-14666.patch: register syscache invalidation callbacks on pg_auth_members and pg_authid that invalidate the role dependent cached plans, in PlanCacheRoleCallback() and InitPlanCache() in src/backend/utils/cache/plancache.c - CVE-2026-14666 * SECURITY UPDATE: pgcrypto PGP encryption silently produced effectively unencrypted output when OpenSSL rejected the cipher, for example in FIPS mode, because the px_cipher_encrypt() result was never checked and the plaintext was XORed with a non encrypted block - debian/patches/CVE-2026-14663.patch: raise an error when the cipher fails during PGP processing and add the decrypt only ignore-cipher-failure option to recover data from badly encrypted messages, in contrib/pgcrypto/pgp-cfb.c, pgp-decrypt.c, pgp-encrypt.c, pgp-pgsql.c, pgp-pubkey.c, pgp.c and pgp.h - CVE-2026-14663 * SECURITY UPDATE: out of bounds writes in ecpg client programs processing bytea data from a rogue server that lacks the expected hex prefix - debian/patches/CVE-2026-16241.patch: reject bytea values shorter than two bytes or missing the \x prefix with a new ECPG_BYTEA_FORMAT error before computing decode sizes, in ecpg_get_data() in src/interfaces/ecpg/ecpglib/data.c, error.c and src/interfaces/ecpg/include/ecpgerrno.h - CVE-2026-16241
Updated packages:
  • libecpg-compat3-12_12.22-2~trixie+tuxcare.els15_amd64.deb
    sha:884e7b0dea05c0b24eb036978fd218aad805652c
  • libecpg-dev-12_12.22-2~trixie+tuxcare.els15_amd64.deb
    sha:4b9ccd1cb6e45c63502fdc67a244dcd82710d813
  • libecpg6-12_12.22-2~trixie+tuxcare.els15_amd64.deb
    sha:1b36ba74035684485555bf9d12a1aa062d30f075
  • libpgtypes3-12_12.22-2~trixie+tuxcare.els15_amd64.deb
    sha:f4f50fdbb94ff809819f6882f9e21f08e681664d
  • libpq-dev-12_12.22-2~trixie+tuxcare.els15_amd64.deb
    sha:c29ac53b9e8a9c69bc40bec83cad3c2370eb1dea
  • libpq5-12_12.22-2~trixie+tuxcare.els15_amd64.deb
    sha:d0d8a69ee2a51efac83c145de14e336ad44d33ac
  • postgresql12_12.22-2~trixie+tuxcare.els15_amd64.deb
    sha:1f3a888676518c7d8a9959d35e89b7c6cbecc0d4
  • postgresql12-client_12.22-2~trixie+tuxcare.els15_amd64.deb
    sha:46fe7813d93eb673244f29db06e6da58d56bd9fe
  • postgresql12-doc_12.22-2~trixie+tuxcare.els15_all.deb
    sha:85ca9d9f2099ecd4e1033d87a62493f99df3caf5
  • postgresql12-plperl_12.22-2~trixie+tuxcare.els15_amd64.deb
    sha:de666210774ca3e9a615aca1d84261b7b1b8d226
  • postgresql12-plpython3_12.22-2~trixie+tuxcare.els15_amd64.deb
    sha:fb0e0971467df67809285a06abab0b0d32b5f691
  • postgresql12-pltcl_12.22-2~trixie+tuxcare.els15_amd64.deb
    sha:06ae1f91cbad939de0a3aac0e75ecd209e4cc696
  • postgresql12-server-dev_12.22-2~trixie+tuxcare.els15_amd64.deb
    sha:11104640e0c3ae18294c127e79d9d2c4c0b542bb
  • libecpg-compat3-12_12.22-2~trixie+tuxcare.els15_arm64.deb
    sha:66a5a16299da7553863d82f37e6a1744be621cde
  • libecpg-dev-12_12.22-2~trixie+tuxcare.els15_arm64.deb
    sha:a56cb2e55d9c3d95965963eae35d634cc5227835
  • libecpg6-12_12.22-2~trixie+tuxcare.els15_arm64.deb
    sha:f7849aa74cb37a6a36f168d753bb61187441563a
  • libpgtypes3-12_12.22-2~trixie+tuxcare.els15_arm64.deb
    sha:e0bfbce819503e491b47be6e483fc55e21f59361
  • libpq-dev-12_12.22-2~trixie+tuxcare.els15_arm64.deb
    sha:6370cd0384c772ea4dedb5476b880068c9fecfb6
  • libpq5-12_12.22-2~trixie+tuxcare.els15_arm64.deb
    sha:b01580ba323f2ce4c0cb6237558a502c49c85baf
  • postgresql12_12.22-2~trixie+tuxcare.els15_arm64.deb
    sha:af29d8d91cd6311d9830e83a4241b7921a88f2e1
  • postgresql12-client_12.22-2~trixie+tuxcare.els15_arm64.deb
    sha:4ea7f239cf820362abfd3d2d40eefe91c66c010d
  • postgresql12-plperl_12.22-2~trixie+tuxcare.els15_arm64.deb
    sha:aad01e23c944fff5986163b7fbe100174d76e5f1
  • postgresql12-plpython3_12.22-2~trixie+tuxcare.els15_arm64.deb
    sha:88afb6a041426c4cafafa67aaf49c57bb0d986e6
  • postgresql12-pltcl_12.22-2~trixie+tuxcare.els15_arm64.deb
    sha:008ea919c3d772344b793060ea3c68eb0ca59b20
  • postgresql12-server-dev_12.22-2~trixie+tuxcare.els15_arm64.deb
    sha:cc8aaf438c7d5258ab9629e69c4048795c1c025f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.