|
|
Log in / Subscribe / Register

SUSE alert openSUSE-SU-2026:21699-1 (postgresql14)

From:  null@suse.de
To:  security-announce@lists.opensuse.org
Subject:  openSUSE-SU-2026:21699-1: important: Security update for postgresql14
Date:  Mon, 31 Aug 2026 17:54:04 +0200
Message-ID:  <20260831155404.14E62FF49@maintenance.suse.de>
Archive-link:  Article

openSUSE security update: security update for postgresql14 ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:21699-1 Rating: important References: * bsc#1275001 * bsc#1275002 * bsc#1275042 * bsc#1275043 * bsc#1275044 * bsc#1275046 * bsc#1275047 * bsc#1275048 * bsc#1275049 * bsc#1275050 * bsc#1275051 * bsc#1275053 * bsc#1275054 * bsc#1275056 * bsc#1275057 * bsc#1275058 * bsc#1275059 * bsc#1275061 * bsc#1275063 * bsc#1275064 * bsc#1275065 * bsc#1275066 * bsc#1275067 * bsc#1275068 Cross-References: * CVE-2026-14662 * CVE-2026-14663 * CVE-2026-14664 * CVE-2026-14666 * CVE-2026-14668 * CVE-2026-14669 * CVE-2026-14670 * CVE-2026-14671 * CVE-2026-14673 * CVE-2026-14677 * CVE-2026-14678 * CVE-2026-14679 * CVE-2026-14680 * CVE-2026-15741 * CVE-2026-15742 * CVE-2026-16239 * CVE-2026-16241 * CVE-2026-18024 * CVE-2026-18408 * CVE-2026-19385 * CVE-2026-6464 * CVE-2026-6469 * CVE-2026-6470 * CVE-2026-6471 CVSS scores: * CVE-2026-14662 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14663 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14664 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14666 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14668 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-14669 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14670 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14671 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14673 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14677 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14678 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-14679 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-14680 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-15741 ( SUSE ): 8 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-15742 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16239 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16241 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-18024 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-18408 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H * CVE-2026-19385 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6464 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-6469 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-6470 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-6471 ( SUSE ): 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 24 vulnerabilities and has 24 bug fixes can now be installed. Description: This update for postgresql14 fixes the following issues: - CVE-2026-6464: `psql` `COPY FROM STDIN` early failure processes data lines as `psql` commands (bsc#1275046). - CVE-2026-6469: `ALTER TABLE ALTER TYPE` resets extended statistics ownership (bsc#1275044). - CVE-2026-6470: failure to check type `USAGE` privilege (bsc#1275043). - CVE-2026-6471: logical decoding can `dlopen` arbitrary file (bsc#1275042). - CVE-2026-14662: `tsvector` and `tsquery` undersize allocations, via integer wraparound (bsc#1275001). - CVE-2026-14663: `pgcrypto`, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext (bsc#1275002). - CVE-2026-14664: `regexp` heap buffer overflow executes arbitrary code (bsc#1275068). - CVE-2026-14666: row security caching disregards role modifications (bsc#1275067). - CVE-2026-14668: `ctid` type confusion in selectivity estimator discloses derivative of arbitrary read (bsc#1275066). - CVE-2026-14669: `to_char` heap buffer overflow executes arbitrary code (bsc#1275065). - CVE-2026-14670: `plperl` tied object heap buffer overflow executes arbitrary code (bsc#1275064). - CVE-2026-14671: `refint` plan cache type confusion executes arbitrary code (bsc#1275063). - CVE-2026-14673: `amcheck` does not clear untrusted search path (bsc#1275061). - CVE-2026-14677: 32-bit `pltcl` and `plperl` undersize allocations, via integer wraparound (bsc#1275059). - CVE-2026-14678: `pg_trgm` `picksplit` reads past end of buffer (bsc#1275058). - CVE-2026-14679: stack buffer overflow in argument match writes `0x0` and `0x1` to server memory (bsc#1275057). - CVE-2026-14680: type confusion via "internal" arguments (bsc#1275056). - CVE-2026-15741: expression deparse allows SQL injection via `EXTRACT` argument (bsc#1275054). - CVE-2026-15742: `fuzzystrmatch` writes effectively-arbitrary addresses, via integer wraparound (bsc#1275053). - CVE-2026-16239: type confusion in cursor `CLOSE + DECLARE` executes arbitrary code (bsc#1275051). - CVE-2026-16241: ECPG integer underflow can crash the client (bsc#1275050). - CVE-2026-18024: `ascii()` function reads past end of buffer (bsc#1275049). - CVE-2026-18408: `psql` `\unrestrict` lets superuser of `pg_dump` origin server execute arbitrary code in `psql` client (bsc#1275048). - CVE-2026-19385: `pg_dump` heap buffer overflow executes arbitrary code (bsc#1275047). Changes for postgresql14: - Let `llvmjit-devel` require the `llc` and `clang` binaries to fix build of extensions on SLE-16 and newer. - Use LLVM 15 on SLE-15 up to SP5 and LLVM 17 on SP6 and SP7. - Update to version 14.24: * https://www.postgresql.org/docs/14/release-14-24.html * https://www.postgresql.org/about/news/postgresql-186-1711... Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-1555=1 Package List: - openSUSE Leap 16.0: postgresql14-14.24-160000.1.1 postgresql14-contrib-14.24-160000.1.1 postgresql14-devel-14.24-160000.1.1 postgresql14-docs-14.24-160000.1.1 postgresql14-llvmjit-14.24-160000.1.1 postgresql14-llvmjit-devel-14.24-160000.1.1 postgresql14-plperl-14.24-160000.1.1 postgresql14-plpython-14.24-160000.1.1 postgresql14-pltcl-14.24-160000.1.1 postgresql14-server-14.24-160000.1.1 postgresql14-server-devel-14.24-160000.1.1 postgresql14-test-14.24-160000.1.1 References: * https://www.suse.com/security/cve/CVE-2026-14662.html * https://www.suse.com/security/cve/CVE-2026-14663.html * https://www.suse.com/security/cve/CVE-2026-14664.html * https://www.suse.com/security/cve/CVE-2026-14666.html * https://www.suse.com/security/cve/CVE-2026-14668.html * https://www.suse.com/security/cve/CVE-2026-14669.html * https://www.suse.com/security/cve/CVE-2026-14670.html * https://www.suse.com/security/cve/CVE-2026-14671.html * https://www.suse.com/security/cve/CVE-2026-14673.html * https://www.suse.com/security/cve/CVE-2026-14677.html * https://www.suse.com/security/cve/CVE-2026-14678.html * https://www.suse.com/security/cve/CVE-2026-14679.html * https://www.suse.com/security/cve/CVE-2026-14680.html * https://www.suse.com/security/cve/CVE-2026-15741.html * https://www.suse.com/security/cve/CVE-2026-15742.html * https://www.suse.com/security/cve/CVE-2026-16239.html * https://www.suse.com/security/cve/CVE-2026-16241.html * https://www.suse.com/security/cve/CVE-2026-18024.html * https://www.suse.com/security/cve/CVE-2026-18408.html * https://www.suse.com/security/cve/CVE-2026-19385.html * https://www.suse.com/security/cve/CVE-2026-6464.html * https://www.suse.com/security/cve/CVE-2026-6469.html * https://www.suse.com/security/cve/CVE-2026-6470.html * https://www.suse.com/security/cve/CVE-2026-6471.html


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds