[CLSA-2026:1790945295] Fix of 6 CVEs
Type:
security
Severity:
Important
Release date:
2026-10-02 12:48:31 UTC
Description:
* Port of debian13els 13.23-1~trixie+tuxcare.els15 and els16. * SECURITY UPDATE: arbitrary library load via logical decoding output plugin - debian/patches/CVE-2026-6471.patch - CVE-2026-6471 * SECURITY UPDATE: integer overflow in fuzzystrmatch levenshtein() - debian/patches/CVE-2026-15742.patch - CVE-2026-15742 * SECURITY UPDATE: portal type confusion in EXECUTE and FETCH - debian/patches/CVE-2026-16239.patch (keeps the 13.x SetTuplestoreDestReceiverParams() ABI for extension binaries) - CVE-2026-16239 * SECURITY UPDATE: type confusion via functions on type internal - debian/patches/CVE-2026-14680.patch - CVE-2026-14680 * SECURITY UPDATE: integer wraparound in pltcl and plperl allocations - debian/patches/CVE-2026-14677.patch - CVE-2026-14677 * SECURITY UPDATE: backquote expansion in psql \unrestrict at restore time - debian/patches/CVE-2026-18408.patch - CVE-2026-18408
Updated packages:
  • postgresql-13_13.23-1.pgdg22.04+1+tuxcare.els2_amd64.deb
    sha:c2a891b6ce6a8f73b0c4ea8e8efe32ef1dbe0976
  • postgresql-client-13_13.23-1.pgdg22.04+1+tuxcare.els2_amd64.deb
    sha:cc481d6eb13cd1a6f8ce8f7f75f942a6ec776aa0
  • postgresql-doc-13_13.23-1.pgdg22.04+1+tuxcare.els2_all.deb
    sha:6b7b73143378378294acc8ee6da0eeda9f56d47e
  • postgresql-plperl-13_13.23-1.pgdg22.04+1+tuxcare.els2_amd64.deb
    sha:5082a03519b8df325a50fc6dc909818921fc8ea0
  • postgresql-plpython3-13_13.23-1.pgdg22.04+1+tuxcare.els2_amd64.deb
    sha:9dd02ded0c748f3a3a49839efa37bd05cd9c0bb9
  • postgresql-pltcl-13_13.23-1.pgdg22.04+1+tuxcare.els2_amd64.deb
    sha:f409bc51229df2f27f44753ba73120fe97f4dbc5
  • postgresql-server-dev-13_13.23-1.pgdg22.04+1+tuxcare.els2_amd64.deb
    sha:6b545e9dd5501327cdcf56527f80a84bb53dd230
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.