rlsa-2026:69923

CVSS 8.8 osv_rocky
Description

PostgreSQL is an advanced object-relational database management system (DBMS). Security Fix(es): * postgresql: PostgreSQL: Arbitrary code execution via integer wraparound in tsvector and tsquery functions (CVE-2026-14662) * postgresql: PostgreSQL: Arbitrary code execution via untrusted data inclusion in pg_dump (CVE-2026-18408) * postgresql: PostgreSQL psql: Arbitrary command execution via untrusted data in COPY FROM STDIN (CVE-2026-6464) * postgresql: PostgreSQL: Arbitrary code execution via logical decoding plugin (CVE-2026-6471) * postgresql: PostgreSQL: Arbitrary code execution via type confusion with "internal" arguments (CVE-2026-14680) * postgresql: PostgreSQL: Arbitrary code execution via heap buffer overflow in regexp (CVE-2026-14664) * postgresql: pltcl: plperl: PostgreSQL: Arbitrary code execution in 32-bit pltcl and plperl (CVE-2026-14677) * postgresql-fuzzystrmatch: PostgreSQL fuzzystrmatch: Arbitrary code execution via integer wraparound (CVE-2026-15742) * postgresql: PostgreSQL: Arbitrary code execution via type confusion in cursor lifecycle (CVE-2026-16239) * postgresql: PostgreSQL: Arbitrary code execution via long POSIX timezone abbreviation (CVE-2026-14669) * postgresql: PostgreSQL: Stack buffer overflow via OUT parameter count manipulation (CVE-2026-14679) * postgresql: PostgreSQL: Arbitrary code execution via type confusion in 'refint' module (CVE-2026-14671) * postgresql: PostgreSQL: Arbitrary code execution via plperl tied hash heap buffer overflow (CVE-2026-14670) * postgresql: PostgreSQL: Information disclosure via type confusion in ctid selectivity estimator (CVE-2026-14668) * postgresql: PostgreSQL pg_dump: Arbitrary code execution via crafted transform lists (CVE-2026-19385) * postgresql: PostgreSQL: Privilege escalation via SQL injection in EXTRACT() deparse (CVE-2026-15741) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Timeline
Published
unknown
Last Modified
unknown
CVSS Details

CVSS details not available.

Affected Products

No product information available.

References
Linked Vulnerabilities

No linked vulnerabilities found.

{
  "affected": [
    {
      "database_specific": {
        "source": "https://storage.googleapis.com/resf-osv-data/RLSA-2026:69923.json"
      },
      "package": {
        "ecosystem": "Rocky Linux:8",
        "name": "pgaudit",
        "purl": "pkg:rpm/rocky-linux/pgaudit?distro=rocky-linux-8&epoch=0"
      },
      "ranges": [
        {
          "database_specific": {
            "yum_repository": "AppStream"
          },
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0:1.7.0-1.module+el8.9.0+1525+fc91df60"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "database_specific": {
        "source": "https://storage.googleapis.com/resf-osv-data/RLSA-2026:69923.json"
      },
      "package": {
        "ecosystem": "Rocky Linux:8",
        "name": "pgaudit",
        "purl": "pkg:rpm/rocky-linux/pgaudit?distro=rocky-linux-8&epoch=0"
      },
      "ranges": [
        {
          "database_specific": {
            "yum_repository": "AppStream"
          },
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0:1.7.0-1.module+el8.10.0+40056+df351139"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "database_specific": {
        "source": "https://storage.googleapis.com/resf-osv-data/RLSA-2026:69923.json"
      },
      "package": {
        "ecosystem": "Rocky Linux:8",
        "name": "pg_repack",
        "purl": "pkg:rpm/rocky-linux/pg_repack?distro=rocky-linux-8&epoch=0"
      },
      "ranges": [
        {
          "database_specific": {
            "yum_repository": "AppStream"
          },
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0:1.4.8-1.module+el8.10.0+40056+df351139"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "database_specific": {
        "source": "https://storage.googleapis.com/resf-osv-data/RLSA-2026:69923.json"
      },
      "package": {
        "ecosystem": "Rocky Linux:8",
        "name": "pg_repack",
        "purl": "pkg:rpm/rocky-linux/pg_repack?distro=rocky-linux-8&epoch=0"
      },
      "ranges": [
        {
          "database_specific": {
            "yum_repository": "AppStream"
          },
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0:1.4.8-1.module+el8.9.0+1525+fc91df60"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "database_specific": {
        "source": "https://storage.googleapis.com/resf-osv-data/RLSA-2026:69923.json"
      },
      "package": {
        "ecosystem": "Rocky Linux:8",
        "name": "pg_repack",
        "purl": "pkg:rpm/rocky-linux/pg_repack?distro=rocky-linux-8&epoch=0"
      },
      "ranges": [
        {
          "database_specific": {
            "yum_repository": "AppStream"
          },
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0:1.4.8-1.module+el8.10.0+1622+bd25b19c"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "database_specific": {
        "source": "https://storage.googleapis.com/resf-osv-data/RLSA-2026:69923.json"
      },
      "package": {
        "ecosystem": "Rocky Linux:8",
        "name": "pg_repack",
        "purl": "pkg:rpm/rocky-linux/pg_repack?distro=rocky-linux-8&epoch=0"
      },
      "ranges": [
        {
          "database_specific": {
            "yum_repository": "AppStream"
          },
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0:1.4.8-1.module+el8.10.0+1858+fcc46a79"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "database_specific": {
        "source": "https://storage.googleapis.com/resf-osv-data/RLSA-2026:69923.json"
      },
      "package": {
        "ecosystem": "Rocky Linux:8",
        "name": "postgres-decoderbufs",
        "purl": "pkg:rpm/rocky-linux/postgres-decoderbufs?distro=rocky-linux-8&epoch=0"
      },
      "ranges": [
        {
          "database_specific": {
            "yum_repository": "AppStream"
          },
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0:1.9.7-1.Final.module+el8.10.0+40056+df351139"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "database_specific": {
        "source": "https://storage.googleapis.com/resf-osv-data/RLSA-2026:69923.json"
      },
      "package": {
        "ecosystem": "Rocky Linux:8",
        "name": "postgres-decoderbufs",
        "purl": "pkg:rpm/rocky-linux/postgres-decoderbufs?distro=rocky-linux-8&epoch=0"
      },
      "ranges": [
        {
          "database_specific": {
            "yum_repository": "AppStream"
          },
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0:1.9.7-1.Final.module+el8.9.0+1525+fc91df60"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "credits": [
    {
      "name": "Rocky Enterprise Software Foundation"
    },
    {
      "name": "Red Hat"
    }
  ],
  "database_specific": {
    "license": "CC-BY-4.0",
    "license_url": "https://creativecommons.org/licenses/by/4.0/",
    "source_advisory": "RHSA-2026:69923"
  },
  "details": "PostgreSQL is an advanced object-relational database management system (DBMS).\n\nSecurity Fix(es):\n\n* postgresql: PostgreSQL: Arbitrary code execution via integer wraparound in tsvector and tsquery functions (CVE-2026-14662)\n\n* postgresql: PostgreSQL: Arbitrary code execution via untrusted data inclusion in pg_dump (CVE-2026-18408)\n\n* postgresql: PostgreSQL psql: Arbitrary command execution via untrusted data in COPY FROM STDIN (CVE-2026-6464)\n\n* postgresql: PostgreSQL: Arbitrary code execution via logical decoding plugin (CVE-2026-6471)\n\n* postgresql: PostgreSQL: Arbitrary code execution via type confusion with \"internal\" arguments (CVE-2026-14680)\n\n* postgresql: PostgreSQL: Arbitrary code execution via heap buffer overflow in regexp (CVE-2026-14664)\n\n* postgresql: pltcl: plperl: PostgreSQL: Arbitrary code execution in 32-bit pltcl and plperl (CVE-2026-14677)\n\n* postgresql-fuzzystrmatch: PostgreSQL fuzzystrmatch: Arbitrary code execution via integer wraparound (CVE-2026-15742)\n\n* postgresql: PostgreSQL: Arbitrary code execution via type confusion in cursor lifecycle (CVE-2026-16239)\n\n* postgresql: PostgreSQL: Arbitrary code execution via long POSIX timezone abbreviation (CVE-2026-14669)\n\n* postgresql: PostgreSQL: Stack buffer overflow via OUT parameter count manipulation (CVE-2026-14679)\n\n* postgresql: PostgreSQL: Arbitrary code execution via type confusion in 'refint' module (CVE-2026-14671)\n\n* postgresql: PostgreSQL: Arbitrary code execution via plperl tied hash heap buffer overflow (CVE-2026-14670)\n\n* postgresql: PostgreSQL: Information disclosure via type confusion in ctid selectivity estimator (CVE-2026-14668)\n\n* postgresql: PostgreSQL pg_dump: Arbitrary code execution via crafted transform lists (CVE-2026-19385)\n\n* postgresql: PostgreSQL: Privilege escalation via SQL injection in EXTRACT() deparse (CVE-2026-15741)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.",
  "id": "RLSA-2026:69923",
  "modified": "2026-09-22T18:24:41.629834294Z",
  "published": "2026-09-22T18:01:18.994578Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://errata.rockylinux.org/RLSA-2026:69923"
    },
    {
      "type": "REPORT",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515302"
    },
    {
      "type": "REPORT",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515303"
    },
    {
      "type": "REPORT",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515306"
    },
    {
      "type": "REPORT",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515307"
    },
    {
      "type": "REPORT",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515308"
    },
    {
      "type": "REPORT",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515311"
    },
    {
      "type": "REPORT",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515313"
    },
    {
      "type": "REPORT",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515314"
    },
    {
      "type": "REPORT",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515316"
    },
    {
      "type": "REPORT",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515317"
    },
    {
      "type": "REPORT",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515321"
    },
    {
      "type": "REPORT",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515322"
    },
    {
      "type": "REPORT",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515325"
    },
    {
      "type": "REPORT",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515326"
    },
    {
      "type": "REPORT",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515328"
    },
    {
      "type": "REPORT",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515332"
    },
    {
      "type": "ADVISORY",
      "url": "https://access.redhat.com/errata/RHSA-2026:69923"
    }
  ],
  "schema_version": "1.9.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "summary": "Important: postgresql:15 security update",
  "upstream": [
    "CVE-2026-14662",
    "CVE-2026-14664",
    "CVE-2026-14668",
    "CVE-2026-14669",
    "CVE-2026-14670",
    "CVE-2026-14671",
    "CVE-2026-14677",
    "CVE-2026-14679",
    "CVE-2026-14680",
    "CVE-2026-15741",
    "CVE-2026-15742",
    "CVE-2026-16239",
    "CVE-2026-18408",
    "CVE-2026-19385",
    "CVE-2026-6464",
    "CVE-2026-6471"
  ]
}
View JSON API Download JSON