Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package postgresql18 for openSUSE:Factory checked in at 2026-08-21 16:49:55 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/postgresql18 (Old) and /work/SRC/openSUSE:Factory/.postgresql18.new.1258 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "postgresql18" Fri Aug 21 16:49:55 2026 rev:9 rq:1372214 version:18.6 Changes: -------- --- /work/SRC/openSUSE:Factory/postgresql18/postgresql18.changes 2026-06-16 13:46:20.463482164 +0200 +++ /work/SRC/openSUSE:Factory/.postgresql18.new.1258/postgresql18.changes 2026-08-21 16:50:27.095831511 +0200 @@ -1,0 +2,77 @@ +Wed Aug 19 11:00:44 UTC 2026 - Reinhard Max <[email protected]> + +- Let llvmjit-devel require the llc and clang binaries to fix + build of extensions on SLE-16.1 and newer. + +------------------------------------------------------------------- +Sat Aug 15 14:44:25 UTC 2026 - Marcus Rueckert <[email protected]> + +- Update to version 18.6: + https://www.postgresql.org/docs/18/release-18-6.html + https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/ + + Security Fixes: + - bsc#1275046, CVE-2026-6464: psql COPY FROM STDIN early failure + processes data lines as psql commands (CVSS v3.1: 8.1) + - bsc#1275044, CVE-2026-6469: ALTER TABLE ALTER TYPE resets + extended statistics ownership (CVSS v3.1: 3.8) + - bsc#1275043, CVE-2026-6470: Fails to check type USAGE privilege + (CVSS v3.1: 4.3) + - bsc#1275042, CVE-2026-6471: Logical decoding can dlopen + arbitrary file (CVSS v3.1: 7.2) + - bsc#1275001, CVE-2026-14662: tsvector and tsquery undersize + allocations, via integer wraparound (CVSS v3.1: 8.8) + - bsc#1275002, CVE-2026-14663: pgcrypto, for OpenSSL-disabled + ciphers, silently encrypts to and decrypts from cleartext (CVSS + v3.1: 6.5) + - bsc#1275068, CVE-2026-14664: Regexp heap buffer overflow + executes arbitrary code (CVSS v3.1: 8.8) + - bsc#1275067, CVE-2026-14666: Row security caching disregards + role modifications (CVSS v3.1: 4.2) + - bsc#1275066, CVE-2026-14668: ctid type confusion in selectivity + estimator discloses derivative of arbitrary read (CVSS v3.1: + 8.1) + - bsc#1275065, CVE-2026-14669: to_char heap buffer overflow + executes arbitrary code (CVSS v3.1: 8.8) + - bsc#1275064, CVE-2026-14670: plperl tied object heap buffer + overflow executes arbitrary code (CVSS v3.1: 8.8) + - bsc#1275063, CVE-2026-14671: refint plan cache type confusion + executes arbitrary code (CVSS v3.1: 8.8) + - bsc#1275062, CVE-2026-14672: Observable response discrepancy + with non-default scram_iterations provides user existence + oracle (CVSS v3.1: 5.3) + - bsc#1275061, CVE-2026-14673: amcheck does not clear untrusted + search path (CVSS v3.1: 3.8) + - bsc#1275060, CVE-2026-14676: pg_stat_statements heap buffer + overflow executes arbitrary code (CVSS v3.1: 8.8) + - bsc#1275059, CVE-2026-14677: 32-bit pltcl and plperl undersize + allocations, via integer wraparound (CVSS v3.1: 8.8) + - bsc#1275058, CVE-2026-14678: pg_trgm picksplit reads past end + of buffer (CVSS v3.1: 4.3) + - bsc#1275057, CVE-2026-14679: Stack buffer overflow in argument + match writes 0x0 and 0x1 to server memory (CVSS v3.1: 8.2) + - bsc#1275056, CVE-2026-14680: Type confusion via "internal" + arguments (CVSS v3.1: 8.8) + - bsc#1275055, CVE-2026-14681: Improper enforcement of GSSAPI + encryption when coupled with SSL (CVSS v3.1: 4.2) + - bsc#1275054, CVE-2026-15741: Expression deparse allows SQL + injection via EXTRACT argument (CVSS v3.1: 8.8) + - bsc#1275053, CVE-2026-15742: fuzzystrmatch writes + effectively-arbitrary addresses, via integer wraparound (CVSS + v3.1: 8.8) + - bsc#1275052, CVE-2026-16238: Type confusion in + pg_restore_attribute_stats() executes arbitrary code (CVSS + v3.1: 8.8) + - bsc#1275051, CVE-2026-16239: Type confusion in cursor CLOSE + + DECLARE executes arbitrary code (CVSS v3.1: 8.8) + - bsc#1275050, CVE-2026-16241: ECPG integer underflow can crash + the client (CVSS v3.1: 3.8) + - bsc#1275049, CVE-2026-18024: ascii() function reads past end of + buffer (CVSS v3.1: 4.3) + - bsc#1275048, CVE-2026-18408: psql \unrestrict lets superuser of + pg_dump origin server execute arbitrary code in psql client + (CVSS v3.1: 8.8) + - bsc#1275047, CVE-2026-19385: pg_dump heap buffer overflow + executes arbitrary code (CVSS v3.1: 8.8) + +------------------------------------------------------------------- Old: ---- postgresql-18.4.tar.bz2 postgresql-18.4.tar.bz2.sha256 New: ---- postgresql-18.6.tar.bz2 postgresql-18.6.tar.bz2.sha256 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ postgresql18.spec ++++++ --- /var/tmp/diff_new_pack.UgAjIi/_old 2026-08-21 16:50:28.156869178 +0200 +++ /var/tmp/diff_new_pack.UgAjIi/_new 2026-08-21 16:50:28.160869320 +0200 @@ -17,7 +17,7 @@ %define pgmajor 18 -%define pgminor 4 +%define pgminor 6 ### CUT HERE ### %define pgname postgresql%pgmajor @@ -423,8 +423,8 @@ Requires: %pgname-llvmjit = %version Requires(post): postgresql-llvmjit-devel-noarch >= %packaging_level Requires(postun): postgresql-llvmjit-devel-noarch >= %packaging_level -%requires_file %_bindir/llc -%requires_file %_bindir/clang +Requires: %_bindir/llc +Requires: %_bindir/clang %endif %description llvmjit-devel ++++++ postgresql-18.4.tar.bz2 -> postgresql-18.6.tar.bz2 ++++++ /work/SRC/openSUSE:Factory/postgresql18/postgresql-18.4.tar.bz2 /work/SRC/openSUSE:Factory/.postgresql18.new.1258/postgresql-18.6.tar.bz2 differ: char 11, line 1 ++++++ postgresql-18.4.tar.bz2.sha256 -> postgresql-18.6.tar.bz2.sha256 ++++++ --- /work/SRC/openSUSE:Factory/postgresql18/postgresql-18.4.tar.bz2.sha256 2026-05-20 15:24:07.773171682 +0200 +++ /work/SRC/openSUSE:Factory/.postgresql18.new.1258/postgresql-18.6.tar.bz2.sha256 2026-08-21 16:50:26.844822600 +0200 @@ -1 +1 @@ -81a81ec695fb0c7901407defaa1d2f7973617154cf27ba74e3a7ab8e64436094 postgresql-18.4.tar.bz2 +555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f postgresql-18.6.tar.bz2
