MGASA-2026-0041

Source
https://advisories.mageia.org/MGASA-2026-0041.html
Import Source
https://advisories.mageia.org/MGASA-2026-0041.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2026-0041
Related
  • CVE-2026-2003
  • CVE-2026-2004
  • CVE-2026-2005
  • CVE-2026-2006
  • CVE-2026-2007
Published
2026-02-17T17:47:08Z
Modified
2026-02-17T18:09:44.952948Z
Summary
Updated postgresql15 packages fix security vulnerabilities
Details

PostgreSQL oidvector discloses a few bytes of memory. (CVE-2026-2003) PostgreSQL intarray missing validation of type of input to selectivity estimator executes arbitrary code. (CVE-2026-2004) PostgreSQL pgcrypto heap buffer overflow executes arbitrary code. (CVE-2026-2005) PostgreSQL missing validation of multibyte character length executes arbitrary code. (CVE-2026-2006) PostgreSQL pg_trgm heap buffer overflow writes pattern onto server memory. (CVE-2026-2007

References
Credits

Affected packages

Mageia:9 / postgresql15

Package

Name
postgresql15
Purl
pkg:rpm/mageia/postgresql15?arch=source&distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
15.16-1.mga9

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2026-0041.json"