Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:67848: Important: postgresql:18 security update

Red Hat has issued an Important security advisory (RHSA-2026:67848) for the PostgreSQL 18 module on RHEL 9, addressing multiple critical vulnerabilities including SQL injection, heap buffer overflows, and type confusion flaws that enable arbitrary code execution and privilege escalation. For example, CVE-2026-14662 (CVSS 8.8) allows arbitrary code execution via integer wraparound in tsvector functions, affecting PostgreSQL 18.0 through 18.4. The fixed version for PostgreSQL 18 is 18.5, as specified in the NVD data for several of the listed CVEs.
Read Full Article →

Red Hat Product Errata RHSA-2026:67848 - Security Advisory Issued: 2026-09-16 Updated: 2026-09-16 RHSA-2026:67848 - Security Advisory Overview Updated Packages Synopsis Important: postgresql:18 security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for the postgresql:18 module is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description PostgreSQL is an advanced object-relational database management system (DBMS). Security Fix(es): postgresql: PostgreSQL: SQL injection in pg_createsubscriber allows arbitrary SQL execution as superuser (CVE-2026-6476) postgresql: PostgreSQL: Arbitrary code execution via integer wraparound in tsvector and tsquery functions (CVE-2026-14662) postgresql: PostgreSQL: Arbitrary code execution via untrusted data inclusion in pg_dump (CVE-2026-18408) postgresql: PostgreSQL psql: Arbitrary command execution via untrusted data in COPY FROM STDIN (CVE-2026-6464) postgresql: PostgreSQL: Arbitrary code execution via logical decoding plugin (CVE-2026-6471) postgresql: PostgreSQL: Arbitrary code execution via type confusion with "internal" arguments (CVE-2026-14680) postgresql: PostgreSQL: Arbitrary code execution via heap buffer overflow in regexp (CVE-2026-14664) postgresql: pltcl: plperl: PostgreSQL: Arbitrary code execution in 32-bit pltcl and plperl (CVE-2026-14677) postgresql-fuzzystrmatch: PostgreSQL fuzzystrmatch: Arbitrary code execution via integer wraparound (CVE-2026-15742) postgresql: PostgreSQL: Arbitrary code execution via type confusion in cursor lifecycle (CVE-2026-16239) postgresql: PostgreSQL: Arbitrary code execution via long POSIX timezone abbreviation (CVE-2026-14669) postgresql: PostgreSQL: Arbitrary code execution via type confusion in pg_restore_attribute_stats() (CVE-2026-16238) postgresql: PostgreSQL: Stack buffer overflow via OUT parameter count manipulation (CVE-2026-14679) postgresql: PostgreSQL: Arbitrary code execution via type confusion in 'refint' module (CVE-2026-14671) postgresql: PostgreSQL pg_stat_statements: Arbitrary code execution via heap buffer overflow (CVE-2026-14676) postgresql: PostgreSQL: Arbitrary code execution via plperl tied hash heap buffer overflow (CVE-2026-14670) postgresql: PostgreSQL: Information disclosure via type confusion in ctid selectivity estimator (CVE-2026-14668) postgresql: PostgreSQL pg_dump: Arbitrary code execution via crafted transform lists (CVE-2026-19385) postgresql: PostgreSQL: Privilege escalation via SQL injection in EXTRACT() deparse (CVE-2026-15741) postgis: PostGIS: Memory Disclosure and Denial of Service via Malformed FlatGeobuf Buffer (CVE-2026-73515) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 9 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 x86_64 Red Hat Enterprise Linux for IBM z Systems 9 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.8 s390x Red Hat Enterprise Linux for Power, little endian 9 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.8 ppc64le Red Hat Enterprise Linux for ARM 64 9 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.8 aarch64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.8 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.8 x86_64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.8 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.8 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.8 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.8 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.8 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.8 s390x Fixes BZ - 2477437 - CVE-2026-6476 postgresql: PostgreSQL: SQL injection in pg_createsubscriber allows arbitrary SQL execution as superuser BZ - 2515302 - CVE-2026-14662 postgresql: PostgreSQL: Arbitrary code execution via integer wraparound in tsvector and tsquery functions BZ - 2515303 - CVE-2026-18408 postgresql: PostgreSQL: Arbitrary code execution via untrusted data inclusion in pg_dump BZ - 2515306 - CVE-2026-6464 postgresql: PostgreSQL psql: Arbitrary command execution via untrusted data in COPY FROM STDIN BZ - 2515307 - CVE-2026-6471 postgresql: PostgreSQL: Arbitrary code execution via logical decoding plugin BZ - 2515308 - CVE-2026-14680 postgresql: PostgreSQL: Arbitrary code execution via type confusion with "internal" arguments BZ - 2515311 - CVE-2026-14664 postgresql: PostgreSQL: Arbitrary code execution via heap buffer overflow in regexp BZ - 2515313 - CVE-2026-14677 postgresql: pltcl: plperl: PostgreSQL: Arbitrary code execution in 32-bit pltcl and plperl BZ - 2515314 - CVE-2026-15742 postgresql-fuzzystrmatch: PostgreSQL fuzzystrmatch: Arbitrary code execution via integer wraparound BZ - 2515316 - CVE-2026-16239 postgresql: PostgreSQL: Arbitrary code execution via type confusion in cursor lifecycle BZ - 2515317 - CVE-2026-14669 postgresql: PostgreSQL: Arbitrary code execution via long POSIX timezone abbreviation BZ - 2515319 - CVE-2026-16238 postgresql: PostgreSQL: Arbitrary code execution via type confusion in pg_restore_attribute_stats() BZ - 2515321 - CVE-2026-14679 postgresql: PostgreSQL: Stack buffer overflow via OUT parameter count manipulation BZ - 2515322 - CVE-2026-14671 postgresql: PostgreSQL: Arbitrary code execution via type confusion in 'refint' module BZ - 2515324 - CVE-2026-14676 postgresql: PostgreSQL pg_stat_statements: Arbitrary code execution via heap buffer overflow BZ - 2515325 - CVE-2026-14670 postgresql: PostgreSQL: Arbitrary code execution via plperl tied hash heap buffer overflow BZ - 2515326 - CVE-2026-14668 postgresql: PostgreSQL: Information disclosure via type confusion in ctid selectivity estimator BZ - 2515328 - CVE-2026-19385 postgresql: PostgreSQL pg_dump: Arbitrary code execution via crafted transform lists BZ - 2515332 - CVE-2026-15741 postgresql: PostgreSQL: Privilege escalation via SQL injection in EXTRACT() deparse BZ - 2515434 - CVE-2026-73515 postgis: PostGIS: Memory Disclosure and Denial of Service via Malformed FlatGeobuf Buffer CVEs CVE-2026-6464 CVE-2026-6471 CVE-2026-6476 CVE-2026-14662 CVE-2026-14664 CVE-2026-14668 CVE-2026-14669 CVE-2026-14670 CVE-2026-14671 CVE-2026-14676 CVE-2026-14677 CVE-2026-14679 CVE-2026-14680 CVE-2026-15741 CVE-2026-15742 CVE-2026-16238 CVE-2026-16239 CVE-2026-18408 CVE-2026-19385 CVE-2026-73515 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 9 SRPM pg_repack-1.5.3-1.module+el9.8.0+23739+1c42644c.src.rpm SHA-256: a814ef5c2d5780750dabc6615ba69bb771e4ee7c534147b9480c0aca2c0a4201 pgaudit-18.0-1.module+el9.8.0+23739+1c42644c.src.rpm SHA-256: 415b616c3b5ad53369b96d9816cc698e2dce6ebc8682b4cea3b1a49d23fb2e68 pgvector-0.8.1-1.module+el9.8.0+23739+1c42644c.src.rpm SHA-256: 3b09a8b48b267bb9a6fe5c040f1261874e181741e9064e01e05ff167be6ceebb postgis-3.6.1-4.module+el9.8.0+24879+1364ef12.src.rpm SHA-256: f1482c6540b04bcaa263369b56114d245111089062d2886a77ae11844a31552c postgres-decoderbufs-3.3.1-1.Final.module+el9.8.0+23739+1c42644c.src.rpm SHA-256: 7c8008ec94cbe1fb2648189001dff5f111d221a3f4b731169e50e9d79f34f2d3 postgresql-18.6-1.module+el9.8.0+24816+5c11f535.src.rpm SHA-256: 1feda293ece860fdae411325d46d5a27e0186a4e1480549d0237efd78448d18e x86_64 postgresql-test-rpm-macros-18.6-1.module+el9.8.0+24816+5c11f535.noarch.rpm SHA-256: e39eac390af2a27203abe36c2e2d36a527ef84c32e1f52c13aa0791917d6eede postgresql-test-rpm-macros-18.6-1.module+el9.8.0+24816+5c11f535.noarch.rpm SHA-256: e39eac390af2a27203abe36c2e2d36a527ef84c32e1f52c13aa0791917d6eede pg_repack-1.5.3-1.module+el9.8.0+23739+1c42644c.x86_64.rpm SHA-256: a4f1a1a1b12086af7218bba9504a280cf264ea5a0ca8079cfd11c1fc5a91d0d4 pg_repack-debuginfo-1.5.3-1.module+el9.8.0+23739+1c42644c.x86_64.rpm SHA-256: 0757d90177cf4425fea541e21f5701226a492adcfefbefb790c911b26bf85b75 pg_repack-debugsource-1.5.3-1.module+el9.8.0+23739+1c42644c.x86_64.rpm SHA-256: 5c6da0269a5861844b461d89874ee98e7917e23a5263f944211dc9a15a36bbfa pgaudit-18.0-1.module+el9.8.0+23739+1c42644c.x86_64.rpm SHA-256: 07df3de00db439cdb61adf8178792075a3633a3c45129b0e7561d26bdc68ce48 pgaudit-debuginfo-18.0-1.module+el9.8.0+23739+1c42644c.x86_64.rpm SHA-256: b55fb852eda19dad065a615e4e72b67bac71015204fefb0e73c2602aea46547b pgaudit-debugsource-18.0-1.module+el9.8.0+23739+1c42644c.x86_64.rpm SHA-256: 66975560eb3c2ee9718b00a080294c1c5830d9caf47be2aa9e42d0f147333aba pgvector-0.8.1-1.module+el9.8.0+23739+1c42644c.x86_64.rpm SHA-256: 7f0a4bce189c9d62023ddb6a0be4650f1bde7d59379b84c0d8e3bf351bd07b95 pgvector-debuginfo-0.8.1-1.module+el9.8.0+23739+1c42644c.x86_64.rpm SHA-256: ad65878b5423ea6369672bd0832ece971c0cac7ae00265de173a2bd5a810c272 pgvector-debugsource-0.8.1-1.module+el9.8.0+23739+1c42644c.x86_64.rpm SHA-256: 1405c7e5ef2c647cbeeaf1bac0be111bc58576bfa7f1acedcbcc76418da1e315 postgis-3.6.1-4.module+el9.8.0+24879+1364ef12.x86_64.rpm SHA-256: 315fc888de70c8dd9c53d768faeb4f57b32ecb3de36ac6694838ac87f199cd49 postgis-client-3.6.1-4.module+el9.8.0+24879+1364ef12.x86_64.rpm SHA-256

Share this article