openSUSE-SU-2026:21702-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21702-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2026:21702-1
Upstream
CVE (25)
  • CVE-2026-14662
  • CVE-2026-14663
  • CVE-2026-14664
  • CVE-2026-14666
  • CVE-2026-14668
  • CVE-2026-14669
  • CVE-2026-14670
  • CVE-2026-14671
  • CVE-2026-14672
  • CVE-2026-14677
  • CVE-2026-14678
  • CVE-2026-14679
  • CVE-2026-14680
  • CVE-2026-14681
  • CVE-2026-15741
  • CVE-2026-15742
  • CVE-2026-16239
  • CVE-2026-16241
  • CVE-2026-18024
  • CVE-2026-18408
  • CVE-2026-19385
  • CVE-2026-6464
  • CVE-2026-6469
  • CVE-2026-6470
  • CVE-2026-6471
Related
Published
2026-08-30T15:41:31Z
Modified
2026-08-31T18:15:05Z
Summary
Security update for postgresql17
Details

This update for postgresql17 fixes the following issues:

  • CVE-2026-6464: psql COPY FROM STDIN early failure processes data lines as psql commands (bsc#1275046).
  • CVE-2026-6469: ALTER TABLE ALTER TYPE resets extended statistics ownership (bsc#1275044).
  • CVE-2026-6470: failure to check type USAGE privilege (bsc#1275043).
  • CVE-2026-6471: logical decoding can dlopen arbitrary file (bsc#1275042).
  • CVE-2026-14662: tsvector and tsquery undersize allocations, via integer wraparound (bsc#1275001).
  • CVE-2026-14663: pgcrypto, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext (bsc#1275002).
  • CVE-2026-14664: regexp heap buffer overflow executes arbitrary code (bsc#1275068).
  • CVE-2026-14666: row security caching disregards role modifications (bsc#1275067).
  • CVE-2026-14668: ctid type confusion in selectivity estimator discloses derivative of arbitrary read (bsc#1275066).
  • CVE-2026-14669: to_char heap buffer overflow executes arbitrary code (bsc#1275065).
  • CVE-2026-14670: plperl tied object heap buffer overflow executes arbitrary code (bsc#1275064).
  • CVE-2026-14671: refint plan cache type confusion executes arbitrary code (bsc#1275063).
  • CVE-2026-14672: observable response discrepancy with non-default scram_iterations provides user existence oracle (bsc#1275062).
  • CVE-2026-14677: 32-bit pltcl and plperl undersize allocations, via integer wraparound (bsc#1275059).
  • CVE-2026-14678: pg_trgm picksplit reads past end of buffer (bsc#1275058).
  • CVE-2026-14679: stack buffer overflow in argument match writes 0x0 and 0x1 to server memory (bsc#1275057).
  • CVE-2026-14680: type confusion via "internal" arguments (bsc#1275056).
  • CVE-2026-14681: improper enforcement of GSSAPI encryption when coupled with SSL (bsc#1275055).
  • CVE-2026-15741: expression deparse allows SQL injection via EXTRACT argument (bsc#1275054).
  • CVE-2026-15742: fuzzystrmatch writes effectively-arbitrary addresses, via integer wraparound (bsc#1275053).
  • CVE-2026-16239: type confusion in cursor CLOSE + DECLARE executes arbitrary code (bsc#1275051).
  • CVE-2026-16241: ECPG integer underflow can crash the client (bsc#1275050).
  • CVE-2026-18024: ascii() function reads past end of buffer (bsc#1275049).
  • CVE-2026-18408: psql \unrestrict lets superuser of pg_dump origin server execute arbitrary code in psql client (bsc#1275048).
  • CVE-2026-19385: pg_dump heap buffer overflow executes arbitrary code (bsc#1275047).

Changes for postgresql17:

References

Affected packages

openSUSE:Leap 16.0 / postgresql17

Package

Name
postgresql17
Purl
pkg:rpm/opensuse/postgresql17&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
17.11-160000.1.1

Ecosystem specific

{
    "binaries":  [
        {
            "postgresql17":  "17.11-160000.1.1",
            "postgresql17-contrib":  "17.11-160000.1.1",
            "postgresql17-devel":  "17.11-160000.1.1",
            "postgresql17-docs":  "17.11-160000.1.1",
            "postgresql17-llvmjit":  "17.11-160000.1.1",
            "postgresql17-llvmjit-devel":  "17.11-160000.1.1",
            "postgresql17-plperl":  "17.11-160000.1.1",
            "postgresql17-plpython":  "17.11-160000.1.1",
            "postgresql17-pltcl":  "17.11-160000.1.1",
            "postgresql17-server":  "17.11-160000.1.1",
            "postgresql17-server-devel":  "17.11-160000.1.1",
            "postgresql17-test":  "17.11-160000.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21702-1.json"