------------------------------------------------------------------------- Debian LTS Advisory DLA-4740-1 [email protected] https://www.debian.org/lts/security/ Carlos Henrique Lima Melara August 14, 2026 https://wiki.debian.org/LTS -------------------------------------------------------------------------
Package : postgresql-15
Version : 15.19-0+deb12u1
CVE ID : CVE-2025-8714 CVE-2026-6464 CVE-2026-6469 CVE-2026-6470
CVE-2026-6471 CVE-2026-6473 CVE-2026-14662 CVE-2026-14663
CVE-2026-14664 CVE-2026-14666 CVE-2026-14668 CVE-2026-14669
CVE-2026-14670 CVE-2026-14671 CVE-2026-14673 CVE-2026-14677
CVE-2026-14678 CVE-2026-14679 CVE-2026-14680 CVE-2026-15741
CVE-2026-15742 CVE-2026-16239 CVE-2026-16241 CVE-2026-18024
CVE-2026-18408 CVE-2026-19385
Multiple security issues were discovered in PostgreSQL, which may
result in execution of arbitrary code, incorrect authentication,
information disclosure, or privilege escalation.
The upstream fix to address CVE-2026-6471 requires additional
changes to the configuration if some extensions are used. This
affects the postgresql-15-wal2json and postgresql-15-decoderbufs
extensions included in Debian. Quoting from the changelog:
| Restrict logical decoding output plugins to the set specified by
| a new server parameter `output_plugin_libraries` (Jacob
| Champion)
| Previously, a replication user could select any loadable library
|
| Restrict logical decoding output plugins to the set specified by
| a new server parameter `output_plugin_libraries` (Jacob
| Champion)
| Previously, a replication user could select any loadable library
| for logical decoding, allowing exploits of various sorts. To
| allow locking this down without breaking setups that worked
| before, introduce a whitelist of allowed output plugins.
|
| By default, only the output plugins shipped as part of
| PostgreSQL (`pgoutput` and `test_decoding`) are included in
|`output_plugin_libraries`. Installations that rely on other
| output plugins must add them after updating the server, for
| example
|
| output_plugin_libraries = 'pgoutput, test_decoding, my_trusted_decoder'
For Debian 12 bookworm, these problems have been fixed in version
15.19-0+deb12u1.
We recommend that you upgrade your postgresql-15 packages.
For the detailed security status of postgresql-15 please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/postgresql-15
Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
signature.asc
Description: PGP signature
