Security News

Cybersecurity news aggregator

🔄
INFO Updates Red Hat Errata

RHSA-2026:67280: Important: postgresql18 security update

  • What: Security update for PostgreSQL 18
  • Impact: Red Hat Enterprise Linux 10 users need to apply the patch
Read Full Article →

Red Hat Product Errata RHSA-2026:67280 - Security Advisory Issued: 2026-09-14 Updated: 2026-09-14 RHSA-2026:67280 - Security Advisory Overview Updated Packages Synopsis Important: postgresql18 security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for postgresql18 is now available for Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description PostgreSQL is an advanced Object-Relational database management system (DBMS). The base postgresql package contains the client programs that you'll need to access a PostgreSQL DBMS server, as well as HTML documentation for the whole system. These client programs can be located on the same machine as the PostgreSQL server, or on a remote machine that accesses a PostgreSQL server over a network connection. The PostgreSQL server can be found in the postgresql-server sub-package. Security Fix(es): postgresql: PostgreSQL: SQL injection in pg_createsubscriber allows arbitrary SQL execution as superuser (CVE-2026-6476) postgresql: PostgreSQL: Arbitrary code execution via integer wraparound in tsvector and tsquery functions (CVE-2026-14662) postgresql: PostgreSQL: Arbitrary code execution via untrusted data inclusion in pg_dump (CVE-2026-18408) postgresql: PostgreSQL psql: Arbitrary command execution via untrusted data in COPY FROM STDIN (CVE-2026-6464) postgresql: PostgreSQL: Arbitrary code execution via logical decoding plugin (CVE-2026-6471) postgresql: PostgreSQL: Arbitrary code execution via type confusion with "internal" arguments (CVE-2026-14680) postgresql: PostgreSQL: Arbitrary code execution via heap buffer overflow in regexp (CVE-2026-14664) postgresql: pltcl: plperl: PostgreSQL: Arbitrary code execution in 32-bit pltcl and plperl (CVE-2026-14677) postgresql-fuzzystrmatch: PostgreSQL fuzzystrmatch: Arbitrary code execution via integer wraparound (CVE-2026-15742) postgresql: PostgreSQL: Arbitrary code execution via type confusion in cursor lifecycle (CVE-2026-16239) postgresql: PostgreSQL: Arbitrary code execution via long POSIX timezone abbreviation (CVE-2026-14669) postgresql: PostgreSQL: Arbitrary code execution via type confusion in pg_restore_attribute_stats() (CVE-2026-16238) postgresql: PostgreSQL: Stack buffer overflow via OUT parameter count manipulation (CVE-2026-14679) postgresql: PostgreSQL: Arbitrary code execution via type confusion in 'refint' module (CVE-2026-14671) postgresql: PostgreSQL pg_stat_statements: Arbitrary code execution via heap buffer overflow (CVE-2026-14676) postgresql: PostgreSQL: Arbitrary code execution via plperl tied hash heap buffer overflow (CVE-2026-14670) postgresql: PostgreSQL: Information disclosure via type confusion in ctid selectivity estimator (CVE-2026-14668) postgresql: PostgreSQL pg_dump: Arbitrary code execution via crafted transform lists (CVE-2026-19385) postgresql: PostgreSQL: Privilege escalation via SQL injection in EXTRACT() deparse (CVE-2026-15741) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 10 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 x86_64 Red Hat Enterprise Linux for IBM z Systems 10 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 s390x Red Hat Enterprise Linux for Power, little endian 10 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat Enterprise Linux for ARM 64 10 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat CodeReady Linux Builder for x86_64 10 x86_64 Red Hat CodeReady Linux Builder for Power, little endian 10 ppc64le Red Hat CodeReady Linux Builder for ARM 64 10 aarch64 Red Hat CodeReady Linux Builder for IBM z Systems 10 s390x Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 10.2 x86_64 Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 10.2 s390x Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.2 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.2 s390x Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.2 ppc64le Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.2 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 10.2 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 10.2 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 10.2 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 10.2 s390x Fixes BZ - 2477437 - CVE-2026-6476 postgresql: PostgreSQL: SQL injection in pg_createsubscriber allows arbitrary SQL execution as superuser BZ - 2515302 - CVE-2026-14662 postgresql: PostgreSQL: Arbitrary code execution via integer wraparound in tsvector and tsquery functions BZ - 2515307 - CVE-2026-6471 postgresql: PostgreSQL: Arbitrary code execution via logical decoding plugin BZ - 2515308 - CVE-2026-14680 postgresql: PostgreSQL: Arbitrary code execution via type confusion with "internal" arguments BZ - 2515311 - CVE-2026-14664 postgresql: PostgreSQL: Arbitrary code execution via heap buffer overflow in regexp BZ - 2515313 - CVE-2026-14677 postgresql: pltcl: plperl: PostgreSQL: Arbitrary code execution in 32-bit pltcl and plperl BZ - 2515314 - CVE-2026-15742 postgresql-fuzzystrmatch: PostgreSQL fuzzystrmatch: Arbitrary code execution via integer wraparound BZ - 2515316 - CVE-2026-16239 postgresql: PostgreSQL: Arbitrary code execution via type confusion in cursor lifecycle BZ - 2515317 - CVE-2026-14669 postgresql: PostgreSQL: Arbitrary code execution via long POSIX timezone abbreviation BZ - 2515319 - CVE-2026-16238 postgresql: PostgreSQL: Arbitrary code execution via type confusion in pg_restore_attribute_stats() BZ - 2515324 - CVE-2026-14676 postgresql: PostgreSQL pg_stat_statements: Arbitrary code execution via heap buffer overflow BZ - 2515328 - CVE-2026-19385 postgresql: PostgreSQL pg_dump: Arbitrary code execution via crafted transform lists CVEs CVE-2026-6464 CVE-2026-6471 CVE-2026-6476 CVE-2026-14662 CVE-2026-14664 CVE-2026-14668 CVE-2026-14669 CVE-2026-14670 CVE-2026-14671 CVE-2026-14676 CVE-2026-14677 CVE-2026-14679 CVE-2026-14680 CVE-2026-15741 CVE-2026-15742 CVE-2026-16238 CVE-2026-16239 CVE-2026-18408 CVE-2026-19385 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 10 SRPM postgresql18-18.6-1.el10_2.src.rpm SHA-256: ad8e77c51214d44a9dc2647db59633886329d4ab075ff3278918f3af6555a7c1 x86_64 postgresql18-18.6-1.el10_2.x86_64.rpm SHA-256: 208e59839b193201b7e3d64223dffa8101ddfb0ecf832c213b7ea5e85a705897 postgresql18-contrib-18.6-1.el10_2.x86_64.rpm SHA-256: 1b4bc5f1e7015265f895e8cb2e3e12517d243a5ca211c56bfe5b4efc4e43097c postgresql18-contrib-debuginfo-18.6-1.el10_2.x86_64.rpm SHA-256: d4ef04ae172b575f609c2196d17bee9807938439f72cecd7ae22a3509411e97a postgresql18-debuginfo-18.6-1.el10_2.x86_64.rpm SHA-256: 06d92bd11ca715ceecbb89ceaef2d75bb7193f0744e4b77bcaeb5e0214ba95d6 postgresql18-debugsource-18.6-1.el10_2.x86_64.rpm SHA-256: 60bf67f988a0e6fed1352dc4a790adfb9c8b466eedc38badd7aa8636cf09e2f5 postgresql18-docs-18.6-1.el10_2.x86_64.rpm SHA-256: 7da25bf9ba123caddc935b749b97922f9297f4fb04d13b34702037dc680d39ca postgresql18-docs-debuginfo-18.6-1.el10_2.x86_64.rpm SHA-256: 25130a9138061dbff4d5b799ac83409be4bc2314f77e5722c7b390c56566cb5f postgresql18-plperl-18.6-1.el10_2.x86_64.rpm SHA-256: 1718acaa0d1d024c9596d92b1fcddfb98b37f4d01f177763689eb85ae4115f37 postgresql18-plperl-debuginfo-18.6-1.el10_2.x86_64.rpm SHA-256: d6f28fd9a67f297cc7685b3ebdd9007f883158202926b057b5f5ba5cb334f06b postgresql18-plpython3-18.6-1.el10_2.x86_64.rpm SHA-256: 75caedce2e1e4420bcb122a2b3861148fa316f9e1755c807a5004423ebf0f96e postgresql18-plpython3-debuginfo-18.6-1.el10_2.x86_64.rpm SHA-256: aedbc671b17db4cc5d55f98ad64ac735bd173659a3b36ff55afa7b0127115add postgresql18-pltcl-debuginfo-18.6-1.el10_2.x86_64.rpm SHA-256: 11d6d2f6df87b2ae796f97cacb05c3641e2e24b8d3d215e7f548fd37dd5cb2dd postgresql18-private-devel-18.6-1.el10_2.x86_64.rpm SHA-256: 778679689eeec8cee1ce22020c900b307ecead4bb14b041d2661859e9194ae96 postgresql18-private-libs-18.6-1.el10_2.x86_64.rpm SHA-256: 4c6aaf1b14772133d76f57cb586bc4b2b5b875492f1ede35414cac89e5983e90 postgresql18-private-libs-debuginfo-18.6-1.el10_2.x86_64.rpm SHA-256: e932aa5f4fafd932b5d774b8bdb199cc05ac6522e6873b721e0f74f47adf1555 postgresql18-server-18.6-1.el10_2.x86_64.rpm SHA-256: 2a3a9c3f2d9ba06f34766f7eb80e2ac965fe787307b5858570c3dc1c89afec65 postgresql18-server-debuginfo-18.6-1.el10_2.x86_64.rpm SHA-256: 9c52e6fd04c2e4fe919480a572814fc14aa21bbefdfbf0fa4713080b152cae8a postgresql18-server-devel-18.6-1.el10_2.x86_64.rpm SHA-256: df5d312961fcb5eeb6a8f1d99226741b6fe940921f884327458079f427f121e5 postgresql18-server-devel-debuginfo-18.6-1.el10_2.x86_64.rpm SHA-256: 5ef411cbc0fbf37d980f9f8826dfe74df243da94d0bbaa04e64904e791ad172a postgresql18-static-18.6-1.el10_2.x86_64.rpm SHA-256: a86ba456fcb25d19e7c4eb9e18b89ab4af6e83d80ce6c8ff89094556b98fbce7 postgresql18-test-18.6-1.el10_2.x86_64.rpm SHA-256:

Share this article