Ubuntu alert USN-8294-1 (postgresql-14, postgresql-16, postgresql-17, postgresql-18)
| From: | noreply+usn-bot@canonical.com | |
| To: | ubuntu-security-announce@lists.ubuntu.com | |
| Subject: | [USN-8294-1] PostgreSQL vulnerabilities | |
| Date: | Thu, 21 May 2026 21:43:49 +0000 | |
| Message-ID: | <E1wQBBF-0008MA-EC@lists.ubuntu.com> |
========================================================================== Ubuntu Security Notice USN-8294-1 May 21, 2026 postgresql-14, postgresql-16, postgresql-17, postgresql-18 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Several security issues were fixed in PostgreSQL. Software Description: - postgresql-18: Object-relational SQL database - postgresql-17: Object-relational SQL database - postgresql-16: Object-relational SQL database - postgresql-14: Object-relational SQL database Details: It was discovered that PostgreSQL did not correctly enforce authorization for CREATE TYPE. An attacker could possibly use this issue to execute arbitrary SQL functions. (CVE-2026-6472) It was discovered that PostgreSQL incorrectly handled large user input in multiple server features. An attacker could possibly use this issue to cause PostgreSQL to crash, resulting in a denial of service, or execute arbitrary code. (CVE-2026-6473) It was discovered that PostgreSQL incorrectly handled format strings in the timeofday() function. An attacker could possibly use this issue to obtain sensitive information. (CVE-2026-6474) It was discovered that PostgreSQL incorrectly followed symbolic links in pg_basebackup and pg_rewind. An attacker could possibly use this issue to overwrite local files and execute arbitrary code. (CVE-2026-6475) It was discovered that PostgreSQL had an SQL injection vulnerability in pg_createsubscriber. An attacker could possibly use this issue to execute arbitrary SQL as a superuser. This issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-6476) It was discovered that PostgreSQL used an unsafe libpq function in large object operations. An attacker could possibly use this issue to overwrite client memory and execute arbitrary code. (CVE-2026-6477) It was discovered that PostgreSQL did not compare MD5-hashed passwords in constant time. An attacker could possibly use this issue to obtain sensitive information. (CVE-2026-6478) It was discovered that PostgreSQL had uncontrolled recursion during SSL and GSS negotiation. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-6479) It was discovered that PostgreSQL incorrectly handled array length mismatches in pg_restore_attribute_stats(). An attacker could possibly use this issue to obtain sensitive information. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-6575) It was discovered that PostgreSQL had a stack buffer overflow in the refint module. An attacker could use this issue to cause PostgreSQL to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2026-6637) It was discovered that PostgreSQL had an SQL injection vulnerability in logical replication REFRESH PUBLICATION. An attacker could possibly use this issue to execute arbitrary SQL. This issue only affected Ubuntu 24.04 LTS, Ubuntu 25.10, and Ubuntu 26.04 LTS. (CVE-2026-6638) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS postgresql-18 18.4-0ubuntu0.26.04.1 Ubuntu 25.10 postgresql-17 17.10-0ubuntu0.25.10.1 Ubuntu 24.04 LTS postgresql-16 16.14-0ubuntu0.24.04.1 Ubuntu 22.04 LTS postgresql-14 14.23-0ubuntu0.22.04.1 This update uses a new upstream release, which includes additional bug fixes. After a standard system update you need to restart PostgreSQL to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8294-1 CVE-2026-6472, CVE-2026-6473, CVE-2026-6474, CVE-2026-6475, CVE-2026-6476, CVE-2026-6477, CVE-2026-6478, CVE-2026-6479, CVE-2026-6575, CVE-2026-6637, CVE-2026-6638 Package Information: https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0... https://launchpad.net/ubuntu/+source/postgresql-17/17.10-... https://launchpad.net/ubuntu/+source/postgresql-16/16.14-... https://launchpad.net/ubuntu/+source/postgresql-14/14.23-...
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmoPfIcACgkQcpJm3tlz hgG4Kw/9F1D4qSguzy71BwvAEgEj5oM0zv/5qIvuZ36lWBN5MQ3/j0rlRcb0ftdZ Z4S2JCoY09bQMmWz7TWgT7SKeksSZRP5kiy3Wqr8jFIQGdRh71FjxYpxqUltFEd3 /aoDxiqfgd5TV8EXsm2SvYWpGU33ntwdeee5VU6r30sIXPJuGcxL8BUSrROgODP2 TSsbbfAdaKMD6elf/9Uuurg+Lmz1afPaP7Ze1YH97yNIpE+I8YmKSudzCqrbeN41 sd7uJldlKoQAuMETDoPS1WfR27M4kJq7mdixCR3/KqF58mYEUDjmZQHBJYfjxHj3 laR44mGhTvo5d1k2nn0sCRyPVhfUJB4QvrY/HIpNQf2rGl1NnVQVP//ImlbRCjL6 yJemqFyhwJyFExdjvoK2S0U3eZ7xZs7MRoAPfVLd51vPUNjytq9CXN9tHwC1FChl 1ZyfHhFzBjrJ8vBUS7XERwm5+yH5ErgAnTgXx7rSdHHO3DfWXYIY8JC5au155cg9 HAW83sfGj1mez/8Sh60878yt+uXItsMHejiZ0Tddo1dcevOL3RFVTNqQmBM+om37 cicfADjvVjOtQe+tt9WWjJGy7o60wOkYresmyAvCfbdn9H3iH65192Pb8HzCx5R+ rSOO57OhMqUhfZIvQtMtydlW0UAA1ULBzfg0omBOG0WhenRCDEI= =vN5z -----END PGP SIGNATURE-----
