[security - high] postgresql:15 security update, postgresql-15.19-1.module+el8+2049+a44fae6d
エラータID: AXSA:2026-1941:01
PostgreSQL is an advanced object-relational database management system (DBMS).
Security Fix(es):
* postgresql: PostgreSQL: Arbitrary code execution via integer wraparound in tsvector and tsquery functions (CVE-2026-14662)
* postgresql: PostgreSQL: Arbitrary code execution via untrusted data inclusion in pg_dump (CVE-2026-18408)
* postgresql: PostgreSQL psql: Arbitrary command execution via untrusted data in COPY FROM STDIN (CVE-2026-6464)
* postgresql: PostgreSQL: Arbitrary code execution via logical decoding plugin (CVE-2026-6471)
* postgresql: PostgreSQL: Arbitrary code execution via type confusion with "internal" arguments (CVE-2026-14680)
* postgresql: PostgreSQL: Arbitrary code execution via heap buffer overflow in regexp (CVE-2026-14664)
* postgresql: pltcl: plperl: PostgreSQL: Arbitrary code execution in 32-bit pltcl and plperl (CVE-2026-14677)
* postgresql-fuzzystrmatch: PostgreSQL fuzzystrmatch: Arbitrary code execution via integer wraparound (CVE-2026-15742)
* postgresql: PostgreSQL: Arbitrary code execution via type confusion in cursor lifecycle (CVE-2026-16239)
* postgresql: PostgreSQL: Arbitrary code execution via long POSIX timezone abbreviation (CVE-2026-14669)
* postgresql: PostgreSQL: Stack buffer overflow via OUT parameter count manipulation (CVE-2026-14679)
* postgresql: PostgreSQL: Arbitrary code execution via type confusion in 'refint' module (CVE-2026-14671)
* postgresql: PostgreSQL: Arbitrary code execution via plperl tied hash heap buffer overflow (CVE-2026-14670)
* postgresql: PostgreSQL: Information disclosure via type confusion in ctid selectivity estimator (CVE-2026-14668)
* postgresql: PostgreSQL pg_dump: Arbitrary code execution via crafted transform lists (CVE-2026-19385)
* postgresql: PostgreSQL: Privilege escalation via SQL injection in EXTRACT() deparse (CVE-2026-15741)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-14662
Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds, via crafted large inputs. This may execute arbitrary code as the operating system user running the database. These types are typically sourced from application logic, not taken from the application's user. Hence, application users attacking the database, through the application as a conduit, are unlikely. CVE-2026-6473 had fixed similar problems. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
CVE-2026-14664
Heap buffer overflow in PostgreSQL regexp allows the query author to execute arbitrary code as the operating system user running the database, via text that would not pass encoding validation. This shares heritage with CVE-2026-2006, but this case involved unanticipated data growth when round-tripped through pg_wchar. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
CVE-2026-14668
Type confusion regarding input of PostgreSQL ctid data type selectivity estimator allows an object creator to view a calculation derived from the value of an arbitrary 4-byte span of memory, via a chosen non-ctid input. While the calculation loses precision, substantial memory value recovery appears possible. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
CVE-2026-14669
Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosing the timezone to execute arbitrary code as the operating system user running the database, via a long POSIX timezone abbreviation. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
CVE-2026-14670
Heap buffer overflow in PostgreSQL plperl return of a tied hash allows the function owner to execute arbitrary code as the operating system user running the database, via a crafted function body. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
CVE-2026-14671
Type confusion in PostgreSQL module "refint" allows an object creator to execute arbitrary code as the operating system user running the database. The fix for this emerged as a non-security bug report, and the fix appear in the git repository with subject "refint: Remove plan cache.", without a CVE number. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
CVE-2026-14677
Integer wraparound in PostgreSQL 32-bit builds of pltcl and plperl allows an object creator to cause the server to undersize an allocation and write out-of-bounds via crafted function bodies. This may execute arbitrary code as the operating system user running the database. CVE-2026-6473 had fixed similar problems. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
CVE-2026-14679
Stack buffer overflow in PostgreSQL argument name matching allows an object creator to achieve unknown impacts via OUT parameter count. The attack can write only 0x0 and 0x1 bytes. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
CVE-2026-14680
Type confusion with PostgreSQL "internal" data type arguments allows any user to execute arbitrary code as the operating system user running the database, via calls to functions with that argument type. Type "internal" represents a class of mutually-incompatible data structures not intended for access from SQL. The system intended to prevent such function calls, but this prevention had gaps. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
CVE-2026-15741
SQL injection in PostgreSQL EXTRACT() deparse allows an object owner to execute arbitrary SQL as a superuser via a hostile object definition. Attacks affect expression deparse consumers broadly, including pg_dump, psql commands like \sf, and any similar usage in non-core tools. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
CVE-2026-15742
Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct writes to a huge range of addresses, executing arbitrary code as the operating system user running the database, via extreme inputs to SQL function levenshtein() or levenshtein_less_equal(). Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
CVE-2026-16239
Type confusion in PostgreSQL "portal"/cursor lifecycle allows a user to execute arbitrary code as the operating system user running the database, via re-creation of a cursor or other portal with different types. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
CVE-2026-18408
Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql \restrict meta-command input expansion. The fix for CVE-2025-8714 introduced \restrict and \unrestrict to block this attack, but \unrestrict itself was sufficient for an attack. pg_dumpall is also affected. pg_restore is affected when used to generate a plain-format dump. Non-core use of \restrict would be affected, but we've not identified non-core use. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
CVE-2026-19385
Heap buffer overflow in PostgreSQL pg_dump of long function transform lists allows an object creator to execute arbitrary code as the operating system user running pg_dump, via a crafted transform list. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
CVE-2026-6464
Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection. If the "COPY FROM STDIN" or "\copy FROM STDIN" command fails before the server indicates that it awaits input rows, psql processes the in-line data rows as psql commands. "COPY FROM" with a filename is unaffected. The server administrator has no inherent control over the data rows, so a complete attack requires the attacker to separately acquire control of both the server and the data rows. Alternatively, an attacker controlling data rows alone might complete an attack through a coincidental error that they don't control. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
CVE-2026-6471
Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice of logical decoding plugin. This in turn runs arbitrary code as that account. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Modularity name: "postgresql"
Stream name: "15"
Update packages.
Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds, via crafted large inputs. This may execute arbitrary code as the operating system user running the database. These types are typically sourced from application logic, not taken from the application's user. Hence, application users attacking the database, through the application as a conduit, are unlikely. CVE-2026-6473 had fixed similar problems. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Heap buffer overflow in PostgreSQL regexp allows the query author to execute arbitrary code as the operating system user running the database, via text that would not pass encoding validation. This shares heritage with CVE-2026-2006, but this case involved unanticipated data growth when round-tripped through pg_wchar. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Type confusion regarding input of PostgreSQL ctid data type selectivity estimator allows an object creator to view a calculation derived from the value of an arbitrary 4-byte span of memory, via a chosen non-ctid input. While the calculation loses precision, substantial memory value recovery appears possible. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosing the timezone to execute arbitrary code as the operating system user running the database, via a long POSIX timezone abbreviation. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Heap buffer overflow in PostgreSQL plperl return of a tied hash allows the function owner to execute arbitrary code as the operating system user running the database, via a crafted function body. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Type confusion in PostgreSQL module "refint" allows an object creator to execute arbitrary code as the operating system user running the database. The fix for this emerged as a non-security bug report, and the fix appear in the git repository with subject "refint: Remove plan cache.", without a CVE number. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Integer wraparound in PostgreSQL 32-bit builds of pltcl and plperl allows an object creator to cause the server to undersize an allocation and write out-of-bounds via crafted function bodies. This may execute arbitrary code as the operating system user running the database. CVE-2026-6473 had fixed similar problems. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Stack buffer overflow in PostgreSQL argument name matching allows an object creator to achieve unknown impacts via OUT parameter count. The attack can write only 0x0 and 0x1 bytes. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Type confusion with PostgreSQL "internal" data type arguments allows any user to execute arbitrary code as the operating system user running the database, via calls to functions with that argument type. Type "internal" represents a class of mutually-incompatible data structures not intended for access from SQL. The system intended to prevent such function calls, but this prevention had gaps. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
SQL injection in PostgreSQL EXTRACT() deparse allows an object owner to execute arbitrary SQL as a superuser via a hostile object definition. Attacks affect expression deparse consumers broadly, including pg_dump, psql commands like \sf, and any similar usage in non-core tools. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct writes to a huge range of addresses, executing arbitrary code as the operating system user running the database, via extreme inputs to SQL function levenshtein() or levenshtein_less_equal(). Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Type confusion in PostgreSQL "portal"/cursor lifecycle allows a user to execute arbitrary code as the operating system user running the database, via re-creation of a cursor or other portal with different types. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql \restrict meta-command input expansion. The fix for CVE-2025-8714 introduced \restrict and \unrestrict to block this attack, but \unrestrict itself was sufficient for an attack. pg_dumpall is also affected. pg_restore is affected when used to generate a plain-format dump. Non-core use of \restrict would be affected, but we've not identified non-core use. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Heap buffer overflow in PostgreSQL pg_dump of long function transform lists allows an object creator to execute arbitrary code as the operating system user running pg_dump, via a crafted transform list. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection. If the "COPY FROM STDIN" or "\copy FROM STDIN" command fails before the server indicates that it awaits input rows, psql processes the in-line data rows as psql commands. "COPY FROM" with a filename is unaffected. The server administrator has no inherent control over the data rows, so a complete attack requires the attacker to separately acquire control of both the server and the data rows. Alternatively, an attacker controlling data rows alone might complete an attack through a coincidental error that they don't control. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice of logical decoding plugin. This in turn runs arbitrary code as that account. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
N/A
SRPMS
- pgaudit-1.7.0-1.module+el8+2049+a44fae6d.src.rpm
MD5: 6a57d1855e2b1dabd616c4d953084e6a
SHA-256: 42f0ce49ca3969247d4dc2f333cd6b2991c20b973c0158ed806cf14f0debfbe2
Size: 52.57 kB - pg_repack-1.4.8-1.module+el8+2049+a44fae6d.ML.1.src.rpm
MD5: 782f6b9becb7d2e3d7e42899ffa32c7d
SHA-256: c1e4403c62def39d00e3f4a54454ea599cf1ef5beec84f2466a4f59b948084b8
Size: 102.82 kB - postgres-decoderbufs-1.9.7-1.Final.module+el8+2049+a44fae6d.src.rpm
MD5: d6d0a7f0f6fdf463e31e5560e1bb3ac2
SHA-256: 1555135994757fd31e68c2b8701713b960ecfb1d21d676f857d56db91a89755d
Size: 23.30 kB - postgresql-15.19-1.module+el8+2049+a44fae6d.src.rpm
MD5: 3b3dc32e624fd6f4d81623c9e0c653b5
SHA-256: 58a1ea0a2c324b5914a0928cb3ed38782a1052c18ba1ffc247eb215d0c009bdc
Size: 51.38 MB
Asianux Server 8 for x86_64
- pgaudit-1.7.0-1.module+el8+2049+a44fae6d.x86_64.rpm
MD5: 085a56092ae9623b0881f0d4611a6027
SHA-256: 801b087ca0526128535714262b4fa185862509b9cf7c2d8cf71f524b87ead9d4
Size: 28.14 kB - pgaudit-debugsource-1.7.0-1.module+el8+2049+a44fae6d.x86_64.rpm
MD5: 22a83217475009fa003ef0300f91e855
SHA-256: 41c76c8c3e7ddb38fdec0bfa7e89ef9ebb89a5bdab1db6fcfbfab3716e7fb2e0
Size: 24.12 kB - pg_repack-1.4.8-1.module+el8+2049+a44fae6d.ML.1.x86_64.rpm
MD5: f3517c300239b835702028af0d8f102c
SHA-256: 372cb5c9b859f74cf64374c0bce8b2a47f356558e174f84a2d98ae9bdb1f220e
Size: 95.01 kB - pg_repack-debugsource-1.4.8-1.module+el8+2049+a44fae6d.ML.1.x86_64.rpm
MD5: 1512a2958f7f11e629753824a0b728f3
SHA-256: c0c1be5c257d1fa25761d10d9daa0e493dcc38f17635b0934fea3154a5ff6780
Size: 50.73 kB - postgres-decoderbufs-1.9.7-1.Final.module+el8+2049+a44fae6d.x86_64.rpm
MD5: d607cd745f79f5013c641f8311d686d3
SHA-256: 24f3d9add5274b40b53f339342b0b5b3c2f41adb2fa7cf77c25a453b59a08307
Size: 23.62 kB - postgres-decoderbufs-debugsource-1.9.7-1.Final.module+el8+2049+a44fae6d.x86_64.rpm
MD5: 1e288bddf2eeaae96b6547a5a32645e5
SHA-256: d2d7c5a91ec836d86af3945b17a29083e29bb80cd839d73345862acc78a804cb
Size: 18.27 kB - postgresql-15.19-1.module+el8+2049+a44fae6d.x86_64.rpm
MD5: 4f656f3187bd6a6ebef67a31ae8adfad
SHA-256: 343dc217fc5b814a3a273fdaa4531ba9a7c0f75e7a537a4b12c04880d467606e
Size: 1.75 MB - postgresql-contrib-15.19-1.module+el8+2049+a44fae6d.x86_64.rpm
MD5: 31d8e601934f183450bc34d50fdd50ed
SHA-256: d477b453f7e88541cd1301b0ef1ca76eb67dec41328e8c858c1ef672bc5093b8
Size: 971.88 kB - postgresql-debugsource-15.19-1.module+el8+2049+a44fae6d.x86_64.rpm
MD5: d6dccbc7a1b26792c2f3b4cbf788771e
SHA-256: d493fe6090af5f3211f39f0a4608ad80501fdf5a4f93d55c2644ed4a154bb7eb
Size: 19.01 MB - postgresql-docs-15.19-1.module+el8+2049+a44fae6d.x86_64.rpm
MD5: 3834a1e4cfb0958bfca41fbfc68ee156
SHA-256: e0aa5c8f800e40f309be8eea01abc92016b52e6aa443524c506a2408e1eb9853
Size: 10.45 MB - postgresql-plperl-15.19-1.module+el8+2049+a44fae6d.x86_64.rpm
MD5: a39910b34b2a552084c44ddb0fecc1f0
SHA-256: b5cf56ebb4b6739e4185949fe8c0de85464095c0aa9d8da075de7e30cfb38292
Size: 73.18 kB - postgresql-plpython3-15.19-1.module+el8+2049+a44fae6d.x86_64.rpm
MD5: a00f057a2538bdb7de6a50c78f107e86
SHA-256: 2cee98288835f1daa45688cafaab02f87d10a152160a72ec7af920199bc57d9c
Size: 93.19 kB - postgresql-pltcl-15.19-1.module+el8+2049+a44fae6d.x86_64.rpm
MD5: 70d4a167d0b42155f763bf885a64c46b
SHA-256: eda6537b52bdb3af64d251a117bb8d2d09a20cc227fb51b370c721e1de0d96a5
Size: 45.64 kB - postgresql-private-devel-15.19-1.module+el8+2049+a44fae6d.x86_64.rpm
MD5: da3978d6f0cf0251aaa67c9b6b66fc44
SHA-256: 7b62b82704737118c4f1c22c1a50cc553c70ad284081451defed06e0fd8962dd
Size: 65.60 kB - postgresql-private-libs-15.19-1.module+el8+2049+a44fae6d.x86_64.rpm
MD5: bac1542dddb72953077e54a95f53b381
SHA-256: d7a0d1ceebfa8f049c535934e82aad242177f99d06ab30696ab1453b6a7d1f1e
Size: 133.80 kB - postgresql-server-15.19-1.module+el8+2049+a44fae6d.x86_64.rpm
MD5: e65790e0f8343dc5eb7c16c0e386dd1b
SHA-256: a9578d29ae019ba63a6f23a1dce8f29bdfe7436b95a98017dabe7557efee27f1
Size: 6.21 MB - postgresql-server-devel-15.19-1.module+el8+2049+a44fae6d.x86_64.rpm
MD5: b911441fbdeee4736649e504b23c533b
SHA-256: 531300afef432622144a52babd0512e3e9b5ad71750a39986783f44f6f4b3864
Size: 1.38 MB - postgresql-static-15.19-1.module+el8+2049+a44fae6d.x86_64.rpm
MD5: d321bd8fad788b13c7ccc31e63649b8d
SHA-256: 05e5dc09378e9653e5b10a402b8516fe91ad0057bc36ff9c674047b44f4f0bf9
Size: 131.69 kB - postgresql-test-15.19-1.module+el8+2049+a44fae6d.x86_64.rpm
MD5: d7d4cf4855100ef3ee11415939dd698a
SHA-256: e09545b10e9b2eec95f88ab1632affc220d0be782bdce7f04579edefd0a25ac1
Size: 2.19 MB - postgresql-test-rpm-macros-15.19-1.module+el8+2049+a44fae6d.noarch.rpm
MD5: dae4f8bdb5bc4ae99680e96925c0e5f8
SHA-256: 03e65a861145a313fe44bf9c2cb237cdba657cdb7a5465af1c89256da7fda8b6
Size: 10.64 kB - postgresql-upgrade-15.19-1.module+el8+2049+a44fae6d.x86_64.rpm
MD5: aaa0ac2da25516e480dc9eba365cbc8d
SHA-256: 885af87109d9d2130a869d6a75691d194bd69157dc097cd23cce37de2653bece
Size: 4.51 MB - postgresql-upgrade-devel-15.19-1.module+el8+2049+a44fae6d.x86_64.rpm
MD5: 4a6867e126676cd14760b7b06088c0ae
SHA-256: 31d31fe67ca62e3def6246985be91f81c0752572d6c79ea37e5becdf4f74de6a
Size: 1.18 MB