SUSE-SU-2026:4014-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20264014-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4014-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:4014-1
Upstream
  • CVE-2026-14662
  • CVE-2026-14663
  • CVE-2026-14664
  • CVE-2026-14666
  • CVE-2026-14668
  • CVE-2026-14669
  • CVE-2026-14670
  • CVE-2026-14671
  • CVE-2026-14672
  • CVE-2026-14673
  • CVE-2026-14676
  • CVE-2026-14677
  • CVE-2026-14678
  • CVE-2026-14679
  • CVE-2026-14680
  • CVE-2026-14681
  • CVE-2026-15741
  • CVE-2026-15742
  • CVE-2026-16238
  • CVE-2026-16239
  • CVE-2026-16241
  • CVE-2026-18024
  • CVE-2026-18408
  • CVE-2026-19385
  • CVE-2026-6464
  • CVE-2026-6469
  • CVE-2026-6470
  • CVE-2026-6471
Related
  • CVE-2026-14662
  • CVE-2026-14663
  • CVE-2026-14664
  • CVE-2026-14666
  • CVE-2026-14668
  • CVE-2026-14669
  • CVE-2026-14670
  • CVE-2026-14671
  • CVE-2026-14672
  • CVE-2026-14673
  • CVE-2026-14676
  • CVE-2026-14677
  • CVE-2026-14678
  • CVE-2026-14679
  • CVE-2026-14680
  • CVE-2026-14681
  • CVE-2026-15741
  • CVE-2026-15742
  • CVE-2026-16238
  • CVE-2026-16239
  • CVE-2026-16241
  • CVE-2026-18024
  • CVE-2026-18408
  • CVE-2026-19385
  • CVE-2026-6464
  • CVE-2026-6469
  • CVE-2026-6470
  • CVE-2026-6471
Published
2026-09-07T07:36:31Z
Modified
2026-09-13T18:23:15Z
Summary
Security update for postgresql18
Details

This update for postgresql18 fixes the following issues:

  • CVE-2026-6464: psql COPY FROM STDIN early failure processes data lines as psql commands (bsc#1275046).
  • CVE-2026-6469: ALTER TABLE ALTER TYPE resets extended statistics ownership (bsc#1275044).
  • CVE-2026-6470: failure to check type USAGE privilege (bsc#1275043).
  • CVE-2026-6471: logical decoding can dlopen arbitrary file (bsc#1275042).
  • CVE-2026-14662: tsvector and tsquery undersize allocations, via integer wraparound (bsc#1275001).
  • CVE-2026-14663: pgcrypto, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext (bsc#1275002).
  • CVE-2026-14664: regexp heap buffer overflow executes arbitrary code (bsc#1275068).
  • CVE-2026-14666: row security caching disregards role modifications (bsc#1275067).
  • CVE-2026-14668: ctid type confusion in selectivity estimator discloses derivative of arbitrary read (bsc#1275066).
  • CVE-2026-14669: to_char heap buffer overflow executes arbitrary code (bsc#1275065).
  • CVE-2026-14670: plperl tied object heap buffer overflow executes arbitrary code (bsc#1275064).
  • CVE-2026-14671: refint plan cache type confusion executes arbitrary code (bsc#1275063).
  • CVE-2026-14672: observable response discrepancy with non-default scram_iterations provides user existence oracle (bsc#1275062).
  • CVE-2026-14673: amcheck does not clear untrusted search path (bsc#1275061).
  • CVE-2026-14676: pg_stat_statements heap buffer overflow executes arbitrary code (bsc#1275060).
  • CVE-2026-14677: 32-bit pltcl and plperl undersize allocations, via integer wraparound (bsc#1275059).
  • CVE-2026-14678: pg_trgm picksplit reads past end of buffer (bsc#1275058).
  • CVE-2026-14679: stack buffer overflow in argument match writes 0x0 and 0x1 to server memory (bsc#1275057).
  • CVE-2026-14680: type confusion via 'internal' arguments (bsc#1275056).
  • CVE-2026-14681: improper enforcement of GSSAPI encryption when coupled with SSL (bsc#1275055).
  • CVE-2026-15741: expression deparse allows SQL injection via EXTRACT argument (bsc#1275054).
  • CVE-2026-15742: fuzzystrmatch writes effectively-arbitrary addresses, via integer wraparound (bsc#1275053).
  • CVE-2026-16238: type confusion in pg_restore_attribute_stats() executes arbitrary code (bsc#1275052).
  • CVE-2026-16239: type confusion in cursor CLOSE + DECLARE executes arbitrary code (bsc#1275051).
  • CVE-2026-16241: ECPG integer underflow can crash the client (bsc#1275050).
  • CVE-2026-18024: ascii() function reads past end of buffer (bsc#1275049).
  • CVE-2026-18408: psql \unrestrict lets superuser of pg_dump origin server execute arbitrary code in psql client (bsc#1275048).
  • CVE-2026-19385: pg_dump heap buffer overflow executes arbitrary code (bsc#1275047).

Changes for postgresql18:

References

Affected packages

SUSE:Linux Enterprise Module for Basesystem 15 SP7
postgresql18

Package

Name
postgresql18
Purl
pkg:rpm/suse/postgresql18&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
18.6-150600.13.16.1

Ecosystem specific

{
    "binaries": [
        {
            "libpq5": "18.6-150600.13.16.1",
            "libpq5-32bit": "18.6-150600.13.16.1",
            "postgresql18": "18.6-150600.13.16.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4014-1.json"
SUSE:Linux Enterprise Module for Package Hub 15 SP7
postgresql18

Package

Name
postgresql18
Purl
pkg:rpm/suse/postgresql18&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
18.6-150600.13.16.1

Ecosystem specific

{
    "binaries": [
        {
            "postgresql18-llvmjit": "18.6-150600.13.16.1",
            "postgresql18-llvmjit-devel": "18.6-150600.13.16.1",
            "postgresql18-test": "18.6-150600.13.16.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4014-1.json"
SUSE:Linux Enterprise Module for Server Applications 15 SP7
postgresql18

Package

Name
postgresql18
Purl
pkg:rpm/suse/postgresql18&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
18.6-150600.13.16.1

Ecosystem specific

{
    "binaries": [
        {
            "libecpg6": "18.6-150600.13.16.1",
            "postgresql18-contrib": "18.6-150600.13.16.1",
            "postgresql18-devel": "18.6-150600.13.16.1",
            "postgresql18-docs": "18.6-150600.13.16.1",
            "postgresql18-plperl": "18.6-150600.13.16.1",
            "postgresql18-plpython": "18.6-150600.13.16.1",
            "postgresql18-pltcl": "18.6-150600.13.16.1",
            "postgresql18-server": "18.6-150600.13.16.1",
            "postgresql18-server-devel": "18.6-150600.13.16.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4014-1.json"
SUSE:Linux Enterprise Server 15 SP6-LTSS
postgresql18

Package

Name
postgresql18
Purl
pkg:rpm/suse/postgresql18&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
18.6-150600.13.16.1

Ecosystem specific

{
    "binaries": [
        {
            "libecpg6": "18.6-150600.13.16.1",
            "libpq5": "18.6-150600.13.16.1",
            "libpq5-32bit": "18.6-150600.13.16.1",
            "postgresql18": "18.6-150600.13.16.1",
            "postgresql18-contrib": "18.6-150600.13.16.1",
            "postgresql18-devel": "18.6-150600.13.16.1",
            "postgresql18-docs": "18.6-150600.13.16.1",
            "postgresql18-plperl": "18.6-150600.13.16.1",
            "postgresql18-plpython": "18.6-150600.13.16.1",
            "postgresql18-pltcl": "18.6-150600.13.16.1",
            "postgresql18-server": "18.6-150600.13.16.1",
            "postgresql18-server-devel": "18.6-150600.13.16.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4014-1.json"
SUSE:Linux Enterprise Server for SAP Applications 15 SP6
postgresql18

Package

Name
postgresql18
Purl
pkg:rpm/suse/postgresql18&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
18.6-150600.13.16.1

Ecosystem specific

{
    "binaries": [
        {
            "libecpg6": "18.6-150600.13.16.1",
            "libpq5": "18.6-150600.13.16.1",
            "libpq5-32bit": "18.6-150600.13.16.1",
            "postgresql18": "18.6-150600.13.16.1",
            "postgresql18-contrib": "18.6-150600.13.16.1",
            "postgresql18-devel": "18.6-150600.13.16.1",
            "postgresql18-docs": "18.6-150600.13.16.1",
            "postgresql18-plperl": "18.6-150600.13.16.1",
            "postgresql18-plpython": "18.6-150600.13.16.1",
            "postgresql18-pltcl": "18.6-150600.13.16.1",
            "postgresql18-server": "18.6-150600.13.16.1",
            "postgresql18-server-devel": "18.6-150600.13.16.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4014-1.json"