[CLSA-2026:1790939319] Fix CVE(s): CVE-2026-6464, CVE-2026-6470
Type:
security
Severity:
Moderate
Release date:
2026-10-02 11:09:00 UTC
Description:
* SECURITY UPDATE: Missing USAGE privilege checks on types - debian/patches/CVE-2026-6470.patch: require USAGE on the subtype in CREATE TYPE AS RANGE, on every type referenced by newly stored expressions (column defaults, check constraints, domains, index and partition expressions, policies, rules, trigger WHEN conditions, views, function parameter defaults), and on the composite type in ALTER TABLE OF; rebuilds of existing expressions are not re-checked (expression statistics and SQL-standard function bodies do not exist in 13) - CVE-2026-6470 * SECURITY UPDATE: SQL injection via in-line COPY FROM STDIN data in psql - debian/patches/CVE-2026-6464.patch: teach psql to recognise and count COPY ... FROM STDIN commands and to read and discard their in-line data when the command fails before the server enters COPY IN mode, and save/restore more lexer state when skipping text in \if blocks; includes upstream follow-up f1204c1a79 so that every COPY in a multi-command string is counted - CVE-2026-6464
Updated packages:
  • libecpg-compat3-13_13.23-1~trixie+tuxcare.els19_amd64.deb
    sha:4da6dd90c16ac95811b1bb4fb300b04ed0fd379c
  • libecpg-dev-13_13.23-1~trixie+tuxcare.els19_amd64.deb
    sha:f600a28136318fd5258827384c9c263190d50e64
  • libecpg6-13_13.23-1~trixie+tuxcare.els19_amd64.deb
    sha:245f9759472a98eafa88f5a5fe0f760c82c12d96
  • libpgtypes3-13_13.23-1~trixie+tuxcare.els19_amd64.deb
    sha:e9db6adb822d66afdbe92ce7c8d560371069b881
  • libpq-dev-13_13.23-1~trixie+tuxcare.els19_amd64.deb
    sha:719de11510aabb1fb262c571950cb476b855bdf0
  • libpq5-13_13.23-1~trixie+tuxcare.els19_amd64.deb
    sha:286f75511ed50cfc43fc146f013d4f4b41b2ed55
  • postgresql13_13.23-1~trixie+tuxcare.els19_amd64.deb
    sha:59fa8dd6f57a7f86b3b40158b1c09b1b4fc95056
  • postgresql13-client_13.23-1~trixie+tuxcare.els19_amd64.deb
    sha:ffc7f319af799f248a2dc5f90dabfadefd003384
  • postgresql13-doc_13.23-1~trixie+tuxcare.els19_all.deb
    sha:2df692681edaac8e97eb30eca568179ac0053215
  • postgresql13-plperl_13.23-1~trixie+tuxcare.els19_amd64.deb
    sha:99ec4c2fb540f2b06a5b5137bf6d3740365b61c3
  • postgresql13-plpython3_13.23-1~trixie+tuxcare.els19_amd64.deb
    sha:e2bde86fc94ad559afe55d944b2766d6afddc962
  • postgresql13-pltcl_13.23-1~trixie+tuxcare.els19_amd64.deb
    sha:6cdf73a61c30685d44573aa786b5790d5d8ed53c
  • postgresql13-server-dev_13.23-1~trixie+tuxcare.els19_amd64.deb
    sha:3ed84b9431a45d22e2d8a184fa7c18e8dec5f967
  • libecpg-compat3-13_13.23-1~trixie+tuxcare.els19_arm64.deb
    sha:2d48422ff445145e4d442a0d1b3a2f9a13121133
  • libecpg-dev-13_13.23-1~trixie+tuxcare.els19_arm64.deb
    sha:7cc5c8d0e3c4489f22ba793440981587db337e33
  • libecpg6-13_13.23-1~trixie+tuxcare.els19_arm64.deb
    sha:fffc7359a58021fd15c9921f18b100b4ae2e80a7
  • libpgtypes3-13_13.23-1~trixie+tuxcare.els19_arm64.deb
    sha:47fc4835e755ea91f942cf7cb28f36b2f3aa21bb
  • libpq-dev-13_13.23-1~trixie+tuxcare.els19_arm64.deb
    sha:04e492f45a9df3d65135dff2b20bed8a138ddd10
  • libpq5-13_13.23-1~trixie+tuxcare.els19_arm64.deb
    sha:c5c8835e3eacb869b2055ee1586c4caf56420e9e
  • postgresql13_13.23-1~trixie+tuxcare.els19_arm64.deb
    sha:09af5751869cb0c6c02fda5ac28e5b8f503defcb
  • postgresql13-client_13.23-1~trixie+tuxcare.els19_arm64.deb
    sha:7983b2d5f6b08fbdd440270b01e6eef50f8ae03f
  • postgresql13-plperl_13.23-1~trixie+tuxcare.els19_arm64.deb
    sha:c7b90114738921b83db9b76d53bc979de23bd537
  • postgresql13-plpython3_13.23-1~trixie+tuxcare.els19_arm64.deb
    sha:8b1451afd4eb2ce765f93d00d07f9c27316eb3eb
  • postgresql13-pltcl_13.23-1~trixie+tuxcare.els19_arm64.deb
    sha:e817bd803f57b9a594d4efa938d5eddd2cc5876f
  • postgresql13-server-dev_13.23-1~trixie+tuxcare.els19_arm64.deb
    sha:bbe5531b25367dd32863d2143a601266aa11295c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.