-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
- -------------------------------------------------------------------------
Debian Security Advisory DSA-6438-1 [email protected]
https://www.debian.org/security/ Moritz Muehlenhoff
August 13, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : postgresql-17
CVE ID : CVE-2026-6464 CVE-2026-6469 CVE-2026-6470 CVE-2026-6471
CVE-2026-6473 CVE-2026-14662 CVE-2026-14663 CVE-2026-14664
CVE-2026-14666 CVE-2026-14668 CVE-2026-14669 CVE-2026-14670
CVE-2026-14671 CVE-2026-14672 CVE-2026-14673 CVE-2026-14677
CVE-2026-14678 CVE-2026-14679 CVE-2026-14680 CVE-2026-14681
CVE-2026-15741 CVE-2026-15742 CVE-2026-16239 CVE-2026-16241
CVE-2026-18024 CVE-2026-18408 CVE-2026-19385
Multiple security issues were discovered in PostgreSQL, which may
result in execution of arbitrary code, incorrect authentication,
information disclosure, or privilege escalation.
The upstream fix to address CVE-2026-6471 requires additional changes
to the configuration if some extensions are used. This affects the
postgresql-17-wal2json, postgresql-17-squeeze, postgresql-17-pg-rewrite
and postgresql-17-decoderbufs extensions included in Debian.
Quoting from the changelog:
| Restrict logical decoding output plugins to the set specified by
| a new server parameter `output_plugin_libraries` (Jacob
| Champion)
| Previously, a replication user could select any loadable library
|
| Restrict logical decoding output plugins to the set specified by
| a new server parameter `output_plugin_libraries` (Jacob
| Champion)
| Previously, a replication user could select any loadable library
| for logical decoding, allowing exploits of various sorts. To
| allow locking this down without breaking setups that worked
| before, introduce a whitelist of allowed output plugins.
|
| By default, only the output plugins shipped as part of
| PostgreSQL (`pgoutput` and `test_decoding`) are included in
|`output_plugin_libraries`. Installations that rely on other
| output plugins must add them after updating the server, for
| example
|
| output_plugin_libraries = 'pgoutput, test_decoding, my_trusted_decoder'
For the stable distribution (trixie), these problems have been fixed in
version 17.11-0+deb13u1.
We recommend that you upgrade your postgresql-17 packages.
For the detailed security status of postgresql-17 please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/postgresql-17
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
Mailing list: [email protected]
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmp+M0AACgkQEMKTtsN8
TjYSkRAAq+WCKgv0P/U+a/CIvcmXuXcqcpKrd3C+qpaKwj5B7zjNykzti6fOD+4Q
IyBjfe+WwywKbovPJF4wxN0jKugkp2LXYPI+LEx/IQVJojxrBsWB+lFuXsZidyFC
NEVijFy5IVEbqne9KNbZWII6fDBbToPBjGl+cuMnF7uhAq+Hq5zXPtF1jKVeHzyy
RzdfJ5MCFUnFddvHOPQhAAAFiKGph67Tn4IZs+Y/TxIYKR6tINHt81ajia5FiP8+
IZVkgWFa+J4AUEaCLsHcB6naLmAu8KmjJTCWJ2vmlOBbGFQxML6NNvxExY1tDHGd
h7SVDZ0aRp2cWTQjHL8AVGYhYGt+93l02TNsOfEgi4jx8V0z2knU8HypGGoIWN7d
1XrGLJBUP0GONlqjd022HiD3JWMDi7qC5+yieo3LQ5I3dp8cvYAGrt+1GZa0ZR64
8buWndiHxKFZFLtr09c+/A3o/3hvNm1axFwMf1B2M3RPNzr7Yni2iihLjsq4Q81I
XrQeY5+ojyFegBizgb7VEImnHZhZImBZw5/KCqWjJ/EG3HwwkKFUXz/5MdXc8UmT
ncqpCblsvRKoFvC4J3ydd8O/pg8J+Uexh+w9aIWQus17WqnZiCDN+k5+10w1Kht/
kRu+txr8Jlns2gmj83xiW7MXcuMskmaMMcYYBL7nPKrodek0tyo=
=HIP3
-----END PGP SIGNATURE-----