[CLSA-2026:1790593828] Fix of 14 CVEs
Type:
security
Severity:
None
Release date:
2026-09-28 11:10:36 UTC
Description:
* Ubuntu 22.04 build of debian13els 13.23-1~trixie+tuxcare.els14, under the PGDG package names so it upgrades PGDG installs in place. * SECURITY UPDATE: integer overflows in several server features - debian/patches/CVE-2026-6473.patch - CVE-2026-6473 * SECURITY UPDATE: path traversal in pg_basebackup and pg_rewind - debian/patches/CVE-2026-6475.patch - CVE-2026-6475 * SECURITY UPDATE: stack overflow via recursive SSL/GSS negotiation - debian/patches/CVE-2026-6479.patch - CVE-2026-6479 * SECURITY UPDATE: crash or memory disclosure via crafted time zone name - debian/patches/CVE-2026-6474.patch - CVE-2026-6474 * SECURITY UPDATE: stack buffer overflow and SQL injection in contrib/spi - debian/patches/CVE-2026-6637.patch - CVE-2026-6637 * SECURITY UPDATE: timing side channel in authentication comparisons - debian/patches/CVE-2026-6478.patch - CVE-2026-6478 * SECURITY UPDATE: buffer overrun in libpq large object interface - debian/patches/CVE-2026-6477.patch - CVE-2026-6477 * SECURITY UPDATE: memory disclosure via crafted oidvector/int2vector - debian/patches/CVE-2026-2003.patch - CVE-2026-2003 * SECURITY UPDATE: code execution via intarray selectivity estimator - debian/patches/CVE-2026-2004.patch - CVE-2026-2004 * SECURITY UPDATE: heap buffer overflow in pgcrypto pubkey decryption - debian/patches/CVE-2026-2005.patch - CVE-2026-2005 * SECURITY UPDATE: buffer overrun via crafted multibyte characters - debian/patches/CVE-2026-2006.patch - CVE-2026-2006 * SECURITY UPDATE: heap buffer overflow in to_char(timestamptz) - debian/patches/CVE-2026-14669.patch - CVE-2026-14669 * SECURITY UPDATE: heap buffer overflow in pg_dump transform lists - debian/patches/CVE-2026-19385.patch - CVE-2026-19385 * SECURITY UPDATE: untrusted search path in amcheck - debian/patches/CVE-2026-14673.patch - CVE-2026-14673 * Build with clang/llvm 15 from the jammy archive. * Compute the catalog version inline: jammy's postgresql-common ships no server/catversion helper. * Don't build libpq5, libpq-dev, libecpg*, libpgtypes3: jammy's 14.x libraries outrank them. * Drop the Alpine packaging and dbpp templating: this branch builds only jammy.
Updated packages:
  • postgresql-13_13.23-1.pgdg22.04+1+tuxcare.els1_amd64.deb
    sha:7cf5c6e9c4f0f60d91b17901cc4cf19fd258e904
  • postgresql-client-13_13.23-1.pgdg22.04+1+tuxcare.els1_amd64.deb
    sha:b4a6610796ec04168c2b10a8c98dc0d9368c51da
  • postgresql-doc-13_13.23-1.pgdg22.04+1+tuxcare.els1_all.deb
    sha:cd1a1fb950e224fe35b780555ff88f7ffe7669ef
  • postgresql-plperl-13_13.23-1.pgdg22.04+1+tuxcare.els1_amd64.deb
    sha:a855eb7f5d4f5108f126d0d42d7c934a1835b347
  • postgresql-plpython3-13_13.23-1.pgdg22.04+1+tuxcare.els1_amd64.deb
    sha:4c54ec35eac89a4a93280b0cfcbefe9148e088fd
  • postgresql-pltcl-13_13.23-1.pgdg22.04+1+tuxcare.els1_amd64.deb
    sha:859e99c0102a7eacbe7ad2688e53473ce4c22264
  • postgresql-server-dev-13_13.23-1.pgdg22.04+1+tuxcare.els1_amd64.deb
    sha:40686770e2e95f20b618985aaa26d107541030f3
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.