-------------------------------------------------------------------------
Debian LTS Advisory DLA-4740-1                [email protected]
https://www.debian.org/lts/security/          Carlos Henrique Lima Melara
August 14, 2026                               https://wiki.debian.org/LTS
-------------------------------------------------------------------------

Package        : postgresql-15
Version        : 15.19-0+deb12u1
CVE ID         : CVE-2025-8714 CVE-2026-6464 CVE-2026-6469 CVE-2026-6470 
                 CVE-2026-6471 CVE-2026-6473 CVE-2026-14662 CVE-2026-14663 
                 CVE-2026-14664 CVE-2026-14666 CVE-2026-14668 CVE-2026-14669 
                 CVE-2026-14670 CVE-2026-14671 CVE-2026-14673 CVE-2026-14677 
                 CVE-2026-14678 CVE-2026-14679 CVE-2026-14680 CVE-2026-15741 
                 CVE-2026-15742 CVE-2026-16239 CVE-2026-16241 CVE-2026-18024 
                 CVE-2026-18408 CVE-2026-19385

Multiple security issues were discovered in PostgreSQL, which may
result in execution of arbitrary code, incorrect authentication,
information disclosure, or privilege escalation.

The upstream fix to address CVE-2026-6471 requires additional
changes to the configuration if some extensions are used. This
affects the postgresql-15-wal2json and postgresql-15-decoderbufs
extensions included in Debian. Quoting from the changelog:

| Restrict logical decoding output plugins to the set specified by
| a new server parameter `output_plugin_libraries` (Jacob
| Champion)
| Previously, a replication user could select any loadable library
|
| Restrict logical decoding output plugins to the set specified by
| a new server parameter `output_plugin_libraries` (Jacob
| Champion)
| Previously, a replication user could select any loadable library
| for logical decoding, allowing exploits of various sorts. To
| allow locking this down without breaking setups that worked
| before, introduce a whitelist of allowed output plugins.
|
| By default, only the output plugins shipped as part of
| PostgreSQL (`pgoutput` and `test_decoding`) are included in
|`output_plugin_libraries`. Installations that rely on other
| output plugins must add them after updating the server, for
| example
|
| output_plugin_libraries = 'pgoutput, test_decoding, my_trusted_decoder'

For Debian 12 bookworm, these problems have been fixed in version
15.19-0+deb12u1.

We recommend that you upgrade your postgresql-15 packages.

For the detailed security status of postgresql-15 please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/postgresql-15

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

Attachment: signature.asc
Description: PGP signature

Reply via email to