[security - high] postgresql:12 security update, postgresql-12.22-10.module+el8+2053+7296a9bb
エラータID: AXSA:2026-2007:01
PostgreSQL is an advanced object-relational database management system (DBMS).
Security Fix(es):
* postgresql: PostgreSQL: Arbitrary code execution via integer wraparound in tsvector and tsquery functions (CVE-2026-14662)
* postgresql: PostgreSQL psql: Arbitrary command execution via untrusted data in COPY FROM STDIN (CVE-2026-6464)
* postgresql: PostgreSQL: Arbitrary code execution via logical decoding plugin (CVE-2026-6471)
* postgresql: PostgreSQL: Arbitrary code execution via type confusion with "internal" arguments (CVE-2026-14680)
* postgresql: PostgreSQL: Arbitrary code execution via heap buffer overflow in regexp (CVE-2026-14664)
* postgresql: pltcl: plperl: PostgreSQL: Arbitrary code execution in 32-bit pltcl and plperl (CVE-2026-14677)
* postgresql-fuzzystrmatch: PostgreSQL fuzzystrmatch: Arbitrary code execution via integer wraparound (CVE-2026-15742)
* postgresql: PostgreSQL: Arbitrary code execution via type confusion in cursor lifecycle (CVE-2026-16239)
* postgresql: PostgreSQL: Arbitrary code execution via long POSIX timezone abbreviation (CVE-2026-14669)
* postgresql: PostgreSQL: Stack buffer overflow via OUT parameter count manipulation (CVE-2026-14679)
* postgresql: PostgreSQL: Arbitrary code execution via type confusion in 'refint' module (CVE-2026-14671)
* postgresql: PostgreSQL: Arbitrary code execution via plperl tied hash heap buffer overflow (CVE-2026-14670)
* postgresql: PostgreSQL: Information disclosure via type confusion in ctid selectivity estimator (CVE-2026-14668)
* postgresql: PostgreSQL pg_dump: Arbitrary code execution via crafted transform lists (CVE-2026-19385)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-14662
Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds, via crafted large inputs. This may execute arbitrary code as the operating system user running the database. These types are typically sourced from application logic, not taken from the application's user. Hence, application users attacking the database, through the application as a conduit, are unlikely. CVE-2026-6473 had fixed similar problems. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
CVE-2026-14664
Heap buffer overflow in PostgreSQL regexp allows the query author to execute arbitrary code as the operating system user running the database, via text that would not pass encoding validation. This shares heritage with CVE-2026-2006, but this case involved unanticipated data growth when round-tripped through pg_wchar. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
CVE-2026-14668
Type confusion regarding input of PostgreSQL ctid data type selectivity estimator allows an object creator to view a calculation derived from the value of an arbitrary 4-byte span of memory, via a chosen non-ctid input. While the calculation loses precision, substantial memory value recovery appears possible. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
CVE-2026-14669
Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosing the timezone to execute arbitrary code as the operating system user running the database, via a long POSIX timezone abbreviation. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
CVE-2026-14670
Heap buffer overflow in PostgreSQL plperl return of a tied hash allows the function owner to execute arbitrary code as the operating system user running the database, via a crafted function body. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
CVE-2026-14671
Type confusion in PostgreSQL module "refint" allows an object creator to execute arbitrary code as the operating system user running the database. The fix for this emerged as a non-security bug report, and the fix appear in the git repository with subject "refint: Remove plan cache.", without a CVE number. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
CVE-2026-14677
Integer wraparound in PostgreSQL 32-bit builds of pltcl and plperl allows an object creator to cause the server to undersize an allocation and write out-of-bounds via crafted function bodies. This may execute arbitrary code as the operating system user running the database. CVE-2026-6473 had fixed similar problems. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
CVE-2026-14679
Stack buffer overflow in PostgreSQL argument name matching allows an object creator to achieve unknown impacts via OUT parameter count. The attack can write only 0x0 and 0x1 bytes. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
CVE-2026-14680
Type confusion with PostgreSQL "internal" data type arguments allows any user to execute arbitrary code as the operating system user running the database, via calls to functions with that argument type. Type "internal" represents a class of mutually-incompatible data structures not intended for access from SQL. The system intended to prevent such function calls, but this prevention had gaps. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
CVE-2026-15742
Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct writes to a huge range of addresses, executing arbitrary code as the operating system user running the database, via extreme inputs to SQL function levenshtein() or levenshtein_less_equal(). Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
CVE-2026-16239
Type confusion in PostgreSQL "portal"/cursor lifecycle allows a user to execute arbitrary code as the operating system user running the database, via re-creation of a cursor or other portal with different types. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
CVE-2026-19385
Heap buffer overflow in PostgreSQL pg_dump of long function transform lists allows an object creator to execute arbitrary code as the operating system user running pg_dump, via a crafted transform list. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
CVE-2026-6464
Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection. If the "COPY FROM STDIN" or "\copy FROM STDIN" command fails before the server indicates that it awaits input rows, psql processes the in-line data rows as psql commands. "COPY FROM" with a filename is unaffected. The server administrator has no inherent control over the data rows, so a complete attack requires the attacker to separately acquire control of both the server and the data rows. Alternatively, an attacker controlling data rows alone might complete an attack through a coincidental error that they don't control. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
CVE-2026-6471
Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice of logical decoding plugin. This in turn runs arbitrary code as that account. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Modularity name: "postgresql"
Stream name: "12"
Update packages.
Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds, via crafted large inputs. This may execute arbitrary code as the operating system user running the database. These types are typically sourced from application logic, not taken from the application's user. Hence, application users attacking the database, through the application as a conduit, are unlikely. CVE-2026-6473 had fixed similar problems. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Heap buffer overflow in PostgreSQL regexp allows the query author to execute arbitrary code as the operating system user running the database, via text that would not pass encoding validation. This shares heritage with CVE-2026-2006, but this case involved unanticipated data growth when round-tripped through pg_wchar. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Type confusion regarding input of PostgreSQL ctid data type selectivity estimator allows an object creator to view a calculation derived from the value of an arbitrary 4-byte span of memory, via a chosen non-ctid input. While the calculation loses precision, substantial memory value recovery appears possible. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosing the timezone to execute arbitrary code as the operating system user running the database, via a long POSIX timezone abbreviation. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Heap buffer overflow in PostgreSQL plperl return of a tied hash allows the function owner to execute arbitrary code as the operating system user running the database, via a crafted function body. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Type confusion in PostgreSQL module "refint" allows an object creator to execute arbitrary code as the operating system user running the database. The fix for this emerged as a non-security bug report, and the fix appear in the git repository with subject "refint: Remove plan cache.", without a CVE number. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Integer wraparound in PostgreSQL 32-bit builds of pltcl and plperl allows an object creator to cause the server to undersize an allocation and write out-of-bounds via crafted function bodies. This may execute arbitrary code as the operating system user running the database. CVE-2026-6473 had fixed similar problems. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Stack buffer overflow in PostgreSQL argument name matching allows an object creator to achieve unknown impacts via OUT parameter count. The attack can write only 0x0 and 0x1 bytes. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Type confusion with PostgreSQL "internal" data type arguments allows any user to execute arbitrary code as the operating system user running the database, via calls to functions with that argument type. Type "internal" represents a class of mutually-incompatible data structures not intended for access from SQL. The system intended to prevent such function calls, but this prevention had gaps. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct writes to a huge range of addresses, executing arbitrary code as the operating system user running the database, via extreme inputs to SQL function levenshtein() or levenshtein_less_equal(). Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Type confusion in PostgreSQL "portal"/cursor lifecycle allows a user to execute arbitrary code as the operating system user running the database, via re-creation of a cursor or other portal with different types. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Heap buffer overflow in PostgreSQL pg_dump of long function transform lists allows an object creator to execute arbitrary code as the operating system user running pg_dump, via a crafted transform list. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection. If the "COPY FROM STDIN" or "\copy FROM STDIN" command fails before the server indicates that it awaits input rows, psql processes the in-line data rows as psql commands. "COPY FROM" with a filename is unaffected. The server administrator has no inherent control over the data rows, so a complete attack requires the attacker to separately acquire control of both the server and the data rows. Alternatively, an attacker controlling data rows alone might complete an attack through a coincidental error that they don't control. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice of logical decoding plugin. This in turn runs arbitrary code as that account. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
N/A
SRPMS
- pgaudit-1.4.0-7.module+el8+2053+7296a9bb.ML.1.src.rpm
MD5: 5cccd8a8d844e3552ff5e5c36f8db9b9
SHA-256: c369a8c4e62df547fb41dcabb92459348bf2e6e1cdd62b86b8b2644d1c0f45f2
Size: 42.40 kB - pg_repack-1.4.6-3.module+el8+2053+7296a9bb.src.rpm
MD5: ccee6073775c7d7a330b7abff5da7423
SHA-256: f683ffc5b5d76da7920cee9ac578a8ffa4c50179b36803abc5278965a8f15316
Size: 100.99 kB - postgres-decoderbufs-0.10.0-2.module+el8+2053+7296a9bb.src.rpm
MD5: 6216be7de3cfea12466f3cf48014ee45
SHA-256: 4bdb3c5877fe4d23b23cb468746eac038565239641a4d562fbc50a28b9118c17
Size: 21.13 kB - postgresql-12.22-10.module+el8+2053+7296a9bb.src.rpm
MD5: 8032119d869ed99be73712af7edb4d8a
SHA-256: 48c01757c52a00fb96db05fd4a803dfed64e10f440240981a1fcef7b7aa772fe
Size: 46.86 MB
Asianux Server 8 for x86_64
- pgaudit-1.4.0-7.module+el8+2053+7296a9bb.ML.1.x86_64.rpm
MD5: 037f67ea9f859708d7d5d53b326b42f0
SHA-256: a766b0c99a7c36d7f0d720900ea0fa50e014913cd181583b1dab6c73ba58ff79
Size: 26.92 kB - pgaudit-debugsource-1.4.0-7.module+el8+2053+7296a9bb.ML.1.x86_64.rpm
MD5: 2d213bbe4635d9fe93a8cbe4c96f70fe
SHA-256: 106b81e4bb75e8606d9bc656dd12c07302496fd806a4b3f2ed280d02b6bf5c49
Size: 23.04 kB - pg_repack-1.4.6-3.module+el8+2053+7296a9bb.x86_64.rpm
MD5: 8d2184eac57c212c0423cac40d57be73
SHA-256: cd1ced123019b97c1224961523039f8833e8a3ecc436a19db291f277a27a2e85
Size: 89.43 kB - pg_repack-debugsource-1.4.6-3.module+el8+2053+7296a9bb.x86_64.rpm
MD5: 2d57f755239c2104d8e71e2cff532e12
SHA-256: ff4b4bd23343a3ff823cfae3d34fea79929cf2f7fb124ea537953ab4a0f35dc3
Size: 49.69 kB - postgres-decoderbufs-0.10.0-2.module+el8+2053+7296a9bb.x86_64.rpm
MD5: 757c44bd327916e6b59f8a4bb51c1b4a
SHA-256: e8b1944b1a31db0aba201c94e767be40c0c488286445463d6c7f569bd60cbf10
Size: 21.65 kB - postgres-decoderbufs-debugsource-0.10.0-2.module+el8+2053+7296a9bb.x86_64.rpm
MD5: 107b871fc877b8a2e66b71dc58ddaa11
SHA-256: 44721c70bc926c68b755cf402059e56ad9ed2c5611ac603793b2b41e13909a8c
Size: 16.81 kB - postgresql-12.22-10.module+el8+2053+7296a9bb.x86_64.rpm
MD5: 1f3fe39181226352682b41c80f437e87
SHA-256: 380f06ebbbc56047b4eb6531bde84759a3cd62b5019719b72aa0e7b51260ddfd
Size: 1.53 MB - postgresql-contrib-12.22-10.module+el8+2053+7296a9bb.x86_64.rpm
MD5: d2fc481460d3799ef91741b4959c7ffc
SHA-256: b36d9ed70d9c548c8fb7cfa81802ec8ce119d1bf5e0bd8d8e95b69074af6cb47
Size: 877.08 kB - postgresql-debugsource-12.22-10.module+el8+2053+7296a9bb.x86_64.rpm
MD5: dbe57ee04f8e2fd62ccb6b4f9b627219
SHA-256: 571c448d5df5f29236be2bfc4e02563388e63633eff2c448e98e6d12a36ca79e
Size: 17.01 MB - postgresql-docs-12.22-10.module+el8+2053+7296a9bb.x86_64.rpm
MD5: 3ee6142a68235d9e5ae7c210ae4cdee4
SHA-256: 9c96ad29864be266cdb755ba20dd85e2b2e57ddeeb52e992a7d5db3b96a82fec
Size: 9.85 MB - postgresql-plperl-12.22-10.module+el8+2053+7296a9bb.x86_64.rpm
MD5: e280b084928ebab3f9f2d3824600948a
SHA-256: 8030fee24ebab283d2f8cdfbef5091e8aa1637abf360918c584fff8adb9d2867
Size: 110.94 kB - postgresql-plpython3-12.22-10.module+el8+2053+7296a9bb.x86_64.rpm
MD5: 90f87736219cc6c42c935c8d5085f9b0
SHA-256: f2bf3783460912143dc615de5e858794faaf3778611c75bfb5945e8fb4cd3228
Size: 130.87 kB - postgresql-pltcl-12.22-10.module+el8+2053+7296a9bb.x86_64.rpm
MD5: 5cf373234fe852169c56110fe1bf8322
SHA-256: 1b8b3a6a8cd78f099f275c8738758b32e730992f3132f609814e9e183e0b64e1
Size: 86.42 kB - postgresql-server-12.22-10.module+el8+2053+7296a9bb.x86_64.rpm
MD5: d2c27335803482da44cd24ae88181fe0
SHA-256: fedfd3e0afc3537aeeca9758428061bd9c54acb237f892b3d1b51860b7a6555e
Size: 5.56 MB - postgresql-server-devel-12.22-10.module+el8+2053+7296a9bb.x86_64.rpm
MD5: 627ff8d56a7e3b280bd08ab45f35f58a
SHA-256: 270d165e5374c5f59a2413b8f910791cc1a01a3ccdf23ce74ebb3cf6a7e0a655
Size: 1.23 MB - postgresql-static-12.22-10.module+el8+2053+7296a9bb.x86_64.rpm
MD5: 0e4f41068094814465693e12deba8f0f
SHA-256: 048248d5a14b62a6dcaaf4f78e299014fb8d18cf77d69a6d0797587d4fe18cf6
Size: 159.01 kB - postgresql-test-12.22-10.module+el8+2053+7296a9bb.x86_64.rpm
MD5: eda1bf93ebc9d9e16177940ec24b9606
SHA-256: 6e5e3968731176f9f28d343e0fcbebd61f6b3f50caf43f0c712b62d8cebbba28
Size: 1.97 MB - postgresql-test-rpm-macros-12.22-10.module+el8+2053+7296a9bb.noarch.rpm
MD5: 4061f9234ddecd9ebfd3da0c931b25df
SHA-256: 77a7af1d4200708f30ff8ef7a465f6bdf786d050326fca76796acf0ec12233c7
Size: 54.37 kB - postgresql-upgrade-12.22-10.module+el8+2053+7296a9bb.x86_64.rpm
MD5: e9c12c46b40e560df71477dddced5f25
SHA-256: b921c50df7e64520016936c6cef9bfda16b75019649ad7018fe616e5d216dc7b
Size: 4.07 MB - postgresql-upgrade-devel-12.22-10.module+el8+2053+7296a9bb.x86_64.rpm
MD5: 428409edb8906dac8232335eb3e9f797
SHA-256: d49f28b8fe3c9d2f31ea9e686403ba2d018d507fae76f810e14d259c9280e547
Size: 1.13 MB