SUSE-SU-2026:0197-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20260197-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:0197-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:0197-1
Upstream
  • CVE-2025-12817
  • CVE-2025-12818
Related
  • CVE-2025-12817
  • CVE-2025-12818
Published
2026-01-21T09:31:57Z
Modified
2026-03-23T04:51:59Z
Summary
Security update for postgresql17, postgresql18
Details

This update for postgresql17, postgresql18 fixes the following issues:

Changes in postgresql18:

  • Fix build with uring for post SLE15 code streams.

Update to 18.1:

  • https://www.postgresql.org/about/news/p-3171/
  • https://www.postgresql.org/docs/release/18.1/
  • bsc#1253332, CVE-2025-12817: Missing check for CREATE privileges on the schema in CREATE STATISTICS allowed table owners to create statistics in any schema, potentially leading to unexpected naming conflicts.
  • bsc#1253333, CVE-2025-12818: Several places in libpq were not sufficiently careful about computing the required size of a memory allocation. Sufficiently large inputs could cause integer overflow, resulting in an undersized buffer, which would then lead to writing past the end of the buffer.
  • pg_config --libs returns -lnuma so we need to require it.

Update to 18.0:

Changes in postgresql17:

Update to 17.7:

  • https://www.postgresql.org/about/news/p-3171/
  • https://www.postgresql.org/docs/release/17.7/
  • bsc#1253332, CVE-2025-12817: Missing check for CREATE privileges on the schema in CREATE STATISTICS allowed table owners to create statistics in any schema, potentially leading to unexpected naming conflicts.
  • bsc#1253333, CVE-2025-12818: Several places in libpq were not sufficiently careful about computing the required size of a memory allocation. Sufficiently large inputs could cause integer overflow, resulting in an undersized buffer, which would then lead to writing past the end of the buffer.
  • switch library to pg 18
References

Affected packages

SUSE:Linux Enterprise Server 12 SP5-LTSS
postgresql

Package

Name
postgresql
Purl
pkg:rpm/suse/postgresql&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
18-4.32.1

Ecosystem specific

{
    "binaries": [
        {
            "libecpg6": "18.1-8.3.4",
            "libecpg6-32bit": "18.1-8.3.4",
            "libpq5": "18.1-8.3.4",
            "libpq5-32bit": "18.1-8.3.4",
            "postgresql": "18-4.32.1",
            "postgresql-contrib": "18-4.32.1",
            "postgresql-devel": "18-4.32.1",
            "postgresql-docs": "18-4.32.1",
            "postgresql-plperl": "18-4.32.1",
            "postgresql-plpython": "18-4.32.1",
            "postgresql-pltcl": "18-4.32.1",
            "postgresql-server": "18-4.32.1",
            "postgresql-server-devel": "18-4.32.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:0197-1.json"
postgresql18

Package

Name
postgresql18
Purl
pkg:rpm/suse/postgresql18&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
18.1-8.3.4

Ecosystem specific

{
    "binaries": [
        {
            "libecpg6": "18.1-8.3.4",
            "libecpg6-32bit": "18.1-8.3.4",
            "libpq5": "18.1-8.3.4",
            "libpq5-32bit": "18.1-8.3.4",
            "postgresql": "18-4.32.1",
            "postgresql-contrib": "18-4.32.1",
            "postgresql-devel": "18-4.32.1",
            "postgresql-docs": "18-4.32.1",
            "postgresql-plperl": "18-4.32.1",
            "postgresql-plpython": "18-4.32.1",
            "postgresql-pltcl": "18-4.32.1",
            "postgresql-server": "18-4.32.1",
            "postgresql-server-devel": "18-4.32.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:0197-1.json"
SUSE:Linux Enterprise Server LTSS Extended Security 12 SP5
postgresql

Package

Name
postgresql
Purl
pkg:rpm/suse/postgresql&distro=SUSE%20Linux%20Enterprise%20Server%20LTSS%20Extended%20Security%2012%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
18-4.32.1

Ecosystem specific

{
    "binaries": [
        {
            "libecpg6": "18.1-8.3.4",
            "libecpg6-32bit": "18.1-8.3.4",
            "libpq5": "18.1-8.3.4",
            "libpq5-32bit": "18.1-8.3.4",
            "postgresql": "18-4.32.1",
            "postgresql-contrib": "18-4.32.1",
            "postgresql-devel": "18-4.32.1",
            "postgresql-docs": "18-4.32.1",
            "postgresql-plperl": "18-4.32.1",
            "postgresql-plpython": "18-4.32.1",
            "postgresql-pltcl": "18-4.32.1",
            "postgresql-server": "18-4.32.1",
            "postgresql-server-devel": "18-4.32.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:0197-1.json"
postgresql18

Package

Name
postgresql18
Purl
pkg:rpm/suse/postgresql18&distro=SUSE%20Linux%20Enterprise%20Server%20LTSS%20Extended%20Security%2012%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
18.1-8.3.4

Ecosystem specific

{
    "binaries": [
        {
            "libecpg6": "18.1-8.3.4",
            "libecpg6-32bit": "18.1-8.3.4",
            "libpq5": "18.1-8.3.4",
            "libpq5-32bit": "18.1-8.3.4",
            "postgresql": "18-4.32.1",
            "postgresql-contrib": "18-4.32.1",
            "postgresql-devel": "18-4.32.1",
            "postgresql-docs": "18-4.32.1",
            "postgresql-plperl": "18-4.32.1",
            "postgresql-plpython": "18-4.32.1",
            "postgresql-pltcl": "18-4.32.1",
            "postgresql-server": "18-4.32.1",
            "postgresql-server-devel": "18-4.32.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:0197-1.json"