Multiple vulnerabilities have been found in PostgreSQL, the worst of which could result in arbitrary code execution. Affected packages Package dev-db/postgresql on all architectures Affected versions < 14.23-r1 < 15.18-r1 < 16.14-r1 < 17.10 < 18.4 Unaffected versions >= 14.23-r1 >= 15.18-r1 >= 16.14-r1 >= 17.10 >= 18.4 Background PostgreSQL is an open source object-relational database management system. Description Multiple vulnerabilities have been discovered in PostgreSQL. Please review the CVE identifiers referenced below for details. Impact Please review the referenced CVE identifiers for details. Workaround There is no known workaround at this time. Resolution All PostgreSQL 14 users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=dev-db/postgresql-14.23-r1:14" All PostgreSQL 15 users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=dev-db/postgresql-15.18-r1:15" All PostgreSQL 16 users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=dev-db/postgresql-16.14-r1:16" All PostgreSQL 17 users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=dev-db/postgresql-17.10:17" All PostgreSQL 18 users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=dev-db/postgresql-18.4:18" References CVE-2025-1094 CVE-2025-4207 CVE-2025-8713 CVE-2025-8714 CVE-2025-8715 CVE-2025-12817 CVE-2026-2003 CVE-2026-2004 CVE-2026-2005 CVE-2026-2006 CVE-2026-2007 CVE-2026-6472 CVE-2026-6473 CVE-2026-6474 CVE-2026-6475 CVE-2026-6476 CVE-2026-6477 CVE-2026-6478 CVE-2026-6479 CVE-2026-6575 CVE-2026-6637 CVE-2026-6638 Release date August 17, 2026 Latest revision August 17, 2026: 1 Severity high Exploitable local and remote Bugzilla entries 949747 955658 961496 966064 969976 974982
Multiple vulnerabilities in PostgreSQL, including one allowing arbitrary code execution, affect versions prior to 14.23-r1, 15.18-r1, 16.14-r1, 17.10, and 18.4. The CVSS scores for referenced CVEs range from 8.1 (High) to 3.1 (Low). The resolution is to upgrade to PostgreSQL 14.23-r1, 15.18-r1, 16.14-r1, 17.10, or 18.4 respectively, as no workaround is available.