CLSA-2026-1779870008

See a problem?
Import Source
https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2026-1779870008.json
JSON Data
https://api.osv.dev/v1/vulns/CLSA-2026-1779870008
Upstream
  • CVE-2026-6473
  • CVE-2026-6474
  • CVE-2026-6475
  • CVE-2026-6477
  • CVE-2026-6478
  • CVE-2026-6479
  • CVE-2026-6637
Published
2026-05-27T08:20:12Z
Modified
2026-06-04T09:46:50Z
Summary
Fix of 7 CVEs
Details
  • SECURITY UPDATE: postgresql May-2026 CVE batch
    • debian/patches/CVE-2026-6473.patch: integer overflow fixes across multiple vulnerable sites: formatting.c size calculations (mul_size), intarray/ltxtquery findoprnd() left-offset overflow with int16 check, ltree lquery numvar/totallen overflow with PG_UINT16_MAX check, ts_headline option length overflow with per-option ERRCODE_INVALID_PARAMETER_VALUE checks, array_agg accumArrayResultArr() nitems overflow with MaxArraySize check, and hstore_plperl/hstore_plpython palloc overflow via mul_size().
    • debian/patches/CVE-2026-6474.patch: guard pg_strftime() callers and ensure null-terminated output on overflow; split timeofday() pg_strftime so the %Z timezone string is never embedded as a format string in subsequent snprintf().
    • debian/patches/CVE-2026-6475.patch: prevent path traversal in pg_rewind via path_is_safe_for_extraction() helper.
    • debian/patches/CVE-2026-6477.patch: harden PQfn()/pqFunctionCall3 against server-controlled buffer overruns in libpq large-object interface (lo_read, lo_lseek64 and lo_tell64 callers).
    • debian/patches/CVE-2026-6478.patch: add timingsafe_bcmp() helper and apply it in MD5/RADIUS/plain auth paths to prevent timing-channel leaks (SCRAM not in 9.5).
    • debian/patches/CVE-2026-6479.patch: fix unbounded recursive handling of SSL negotiation in ProcessStartupPacket() (convert recursive call to goto-retry loop).
    • debian/patches/CVE-2026-6637.patch: switch refint contrib check_foreign_key to StringInfo and quote_literal_cstr() to prevent SQL injection and stack buffer overruns.
    • CVE-2026-6473
    • CVE-2026-6474
    • CVE-2026-6475
    • CVE-2026-6477
    • CVE-2026-6478
    • CVE-2026-6479
    • CVE-2026-6637
  • debian/patches/fix-regress-tzdata-LMT.patch: refresh src/test/regress expected output for date, timestamptz and horology tests so they match the LMT abbreviation emitted by current tzdata for pre-1883 dates.
References

Affected packages

TuxCare:Ubuntu:16.04
libecpg-compat3

Package

Name
libecpg-compat3
Purl
pkg:deb/tuxcare/libecpg-compat3?distro=ubuntu-16.04

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
9.5.25-0ubuntu0.16.04.1+tuxcare.els13

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2026-1779870008.json"
libecpg-dev

Package

Name
libecpg-dev
Purl
pkg:deb/tuxcare/libecpg-dev?distro=ubuntu-16.04

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
9.5.25-0ubuntu0.16.04.1+tuxcare.els13

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2026-1779870008.json"
libecpg6

Package

Name
libecpg6
Purl
pkg:deb/tuxcare/libecpg6?distro=ubuntu-16.04

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
9.5.25-0ubuntu0.16.04.1+tuxcare.els13

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2026-1779870008.json"
libpgtypes3

Package

Name
libpgtypes3
Purl
pkg:deb/tuxcare/libpgtypes3?distro=ubuntu-16.04

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
9.5.25-0ubuntu0.16.04.1+tuxcare.els13

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2026-1779870008.json"
libpq-dev

Package

Name
libpq-dev
Purl
pkg:deb/tuxcare/libpq-dev?distro=ubuntu-16.04

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
9.5.25-0ubuntu0.16.04.1+tuxcare.els13

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2026-1779870008.json"
libpq5

Package

Name
libpq5
Purl
pkg:deb/tuxcare/libpq5?distro=ubuntu-16.04

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
9.5.25-0ubuntu0.16.04.1+tuxcare.els13

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2026-1779870008.json"
postgresql-9.5

Package

Name
postgresql-9.5
Purl
pkg:deb/tuxcare/postgresql-9.5?distro=ubuntu-16.04

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
9.5.25-0ubuntu0.16.04.1+tuxcare.els13

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2026-1779870008.json"
postgresql-client-9.5

Package

Name
postgresql-client-9.5
Purl
pkg:deb/tuxcare/postgresql-client-9.5?distro=ubuntu-16.04

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
9.5.25-0ubuntu0.16.04.1+tuxcare.els13

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2026-1779870008.json"
postgresql-contrib-9.5

Package

Name
postgresql-contrib-9.5
Purl
pkg:deb/tuxcare/postgresql-contrib-9.5?distro=ubuntu-16.04

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
9.5.25-0ubuntu0.16.04.1+tuxcare.els13

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2026-1779870008.json"
postgresql-doc-9.5

Package

Name
postgresql-doc-9.5
Purl
pkg:deb/tuxcare/postgresql-doc-9.5?distro=ubuntu-16.04

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
9.5.25-0ubuntu0.16.04.1+tuxcare.els13

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2026-1779870008.json"
postgresql-plperl-9.5

Package

Name
postgresql-plperl-9.5
Purl
pkg:deb/tuxcare/postgresql-plperl-9.5?distro=ubuntu-16.04

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
9.5.25-0ubuntu0.16.04.1+tuxcare.els13

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2026-1779870008.json"
postgresql-plpython-9.5

Package

Name
postgresql-plpython-9.5
Purl
pkg:deb/tuxcare/postgresql-plpython-9.5?distro=ubuntu-16.04

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
9.5.25-0ubuntu0.16.04.1+tuxcare.els13

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2026-1779870008.json"
postgresql-plpython3-9.5

Package

Name
postgresql-plpython3-9.5
Purl
pkg:deb/tuxcare/postgresql-plpython3-9.5?distro=ubuntu-16.04

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
9.5.25-0ubuntu0.16.04.1+tuxcare.els13

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2026-1779870008.json"
postgresql-pltcl-9.5

Package

Name
postgresql-pltcl-9.5
Purl
pkg:deb/tuxcare/postgresql-pltcl-9.5?distro=ubuntu-16.04

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
9.5.25-0ubuntu0.16.04.1+tuxcare.els13

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2026-1779870008.json"
postgresql-server-dev-9.5

Package

Name
postgresql-server-dev-9.5
Purl
pkg:deb/tuxcare/postgresql-server-dev-9.5?distro=ubuntu-16.04

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
9.5.25-0ubuntu0.16.04.1+tuxcare.els13

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2026-1779870008.json"