Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
8fa2feba by Salvatore Bonaccorso at 2026-08-14T06:29:09+02:00
Track fixed version for postgresql-18 issues via unstable upload
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -649,196 +649,196 @@ CVE-2026-13048 (Data::MuForm::Localizer versions
through 0.05 for Perl execute P
CVE-2026-13051 (Form::Processor::Field::HtmlArea versions from 0.06 through
1.162360 f ...)
NOT-FOR-US: Form::Processor Perl module
CVE-2026-6464 (Untrusted data inclusion in PostgreSQL psql COPY may allow a
server ad ...)
- - postgresql-18 <unfixed>
+ - postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
- postgresql-13 <unfixed>
NOTE: https://www.postgresql.org/support/security/CVE-2026-6464/
NOTE:
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-6469 (Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER
TYPE co ...)
- - postgresql-18 <unfixed>
+ - postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
- postgresql-13 <unfixed>
NOTE: https://www.postgresql.org/support/security/CVE-2026-6469/
NOTE:
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-6470 (Missing authorization in PostgreSQL DDL commands allows an
object crea ...)
- - postgresql-18 <unfixed>
+ - postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
- postgresql-13 <unfixed>
NOTE: https://www.postgresql.org/support/security/CVE-2026-6470/
NOTE:
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-6471 (Missing authorization in PostgreSQL logical decoding allows a
non-supe ...)
- - postgresql-18 <unfixed>
+ - postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
- postgresql-13 <unfixed>
NOTE: https://www.postgresql.org/support/security/CVE-2026-6471/
NOTE:
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-14662 (Integer wraparound in PostgreSQL tsvector and tsquery data
type functi ...)
- - postgresql-18 <unfixed>
+ - postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
- postgresql-13 <unfixed>
NOTE: https://www.postgresql.org/support/security/CVE-2026-14662/
NOTE:
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-14663 (Cleartext storage in PostgreSQL pgcrypto disabled ciphers
allows a use ...)
- - postgresql-18 <unfixed>
+ - postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
- postgresql-13 <unfixed>
NOTE: https://www.postgresql.org/support/security/CVE-2026-14663/
NOTE:
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-14664 (Heap buffer overflow in PostgreSQL regexp allows the query
author to e ...)
- - postgresql-18 <unfixed>
+ - postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
- postgresql-13 <unfixed>
NOTE: https://www.postgresql.org/support/security/CVE-2026-14664/
NOTE:
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-14666 (Incomplete tracking in PostgreSQL of changes to role
membership, role ...)
- - postgresql-18 <unfixed>
+ - postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
- postgresql-13 <unfixed>
NOTE: https://www.postgresql.org/support/security/CVE-2026-14666/
NOTE:
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-14668 (Type confusion regarding input of PostgreSQL ctid data type
selectivit ...)
- - postgresql-18 <unfixed>
+ - postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
- postgresql-13 <unfixed>
NOTE: https://www.postgresql.org/support/security/CVE-2026-14668/
NOTE:
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-14669 (Heap buffer overflow in PostgreSQL to_char(timestamptz) allows
the par ...)
- - postgresql-18 <unfixed>
+ - postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
- postgresql-13 <unfixed>
NOTE: https://www.postgresql.org/support/security/CVE-2026-14669/
NOTE:
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-14670 (Heap buffer overflow in PostgreSQL plperl return of a tied
hash allows ...)
- - postgresql-18 <unfixed>
+ - postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
- postgresql-13 <unfixed>
NOTE: https://www.postgresql.org/support/security/CVE-2026-14670/
NOTE:
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-14671 (Type confusion in PostgreSQL module "refint" allows an object
creator ...)
- - postgresql-18 <unfixed>
+ - postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
- postgresql-13 <unfixed>
NOTE: https://www.postgresql.org/support/security/CVE-2026-14671/
NOTE:
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-14672 (Observable response discrepancy in PostgreSQL SCRAM
authentication all ...)
- - postgresql-18 <unfixed>
+ - postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <not-affected> ((Vulnerable code not present)
- postgresql-13 <not-affected> ((Vulnerable code not present)
NOTE: https://www.postgresql.org/support/security/CVE-2026-14672/
NOTE:
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-14673 (Untrusted search path in PostgreSQL amcheck allows a grantee
of amchec ...)
- - postgresql-18 <unfixed>
+ - postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
- postgresql-13 <unfixed>
NOTE: https://www.postgresql.org/support/security/CVE-2026-14673/
NOTE:
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-14676 (Heap buffer overflow in PostgreSQL pg_stat_statements allows
the query ...)
- - postgresql-18 <unfixed>
+ - postgresql-18 18.6-1
- postgresql-17 <not-affected> (Vulnerable code not present)
- postgresql-15 <not-affected> (Vulnerable code not present)
- postgresql-13 <not-affected> (Vulnerable code not present)
NOTE: https://www.postgresql.org/support/security/CVE-2026-14676/
NOTE:
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-14677 (Integer wraparound in PostgreSQL 32-bit builds of pltcl and
plperl all ...)
- - postgresql-18 <unfixed>
+ - postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
- postgresql-13 <unfixed>
NOTE: https://www.postgresql.org/support/security/CVE-2026-14677/
NOTE:
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-14678 (Buffer over-read in PostgreSQL pg_trgm index picksplit
function reads ...)
- - postgresql-18 <unfixed>
+ - postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
- postgresql-13 <unfixed>
NOTE: https://www.postgresql.org/support/security/CVE-2026-14678/
NOTE:
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-14679 (Stack buffer overflow in PostgreSQL argument name matching
allows an o ...)
- - postgresql-18 <unfixed>
+ - postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
- postgresql-13 <unfixed>
NOTE: https://www.postgresql.org/support/security/CVE-2026-14679/
NOTE:
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-14680 (Type confusion with PostgreSQL "internal" data type arguments
allows a ...)
- - postgresql-18 <unfixed>
+ - postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
- postgresql-13 <unfixed>
NOTE: https://www.postgresql.org/support/security/CVE-2026-14680/
NOTE:
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-14681 (Improper enforcement of message integrity in PostgreSQL GSSAPI
support ...)
- - postgresql-18 <unfixed>
+ - postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <not-affected> (Vulnerable code not present)
- postgresql-13 <not-affected> (Vulnerable code not present)
NOTE: https://www.postgresql.org/support/security/CVE-2026-14681/
NOTE:
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-15741 (SQL injection in PostgreSQL EXTRACT() deparse allows an object
owner t ...)
- - postgresql-18 <unfixed>
+ - postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
- postgresql-13 <unfixed>
NOTE: https://www.postgresql.org/support/security/CVE-2026-15741/
NOTE:
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-15742 (Integer wraparound in PostgreSQL fuzzystrmatch allows a user
to direct ...)
- - postgresql-18 <unfixed>
+ - postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
- postgresql-13 <unfixed>
NOTE: https://www.postgresql.org/support/security/CVE-2026-15742/
NOTE:
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-16238 (Type confusion in PostgreSQL pg_restore_attribute_stats()
allows an ob ...)
- - postgresql-18 <unfixed>
+ - postgresql-18 18.6-1
- postgresql-17 <not-affected> (Vulnerable code not present)
- postgresql-15 <not-affected> (Vulnerable code not present)
- postgresql-13 <not-affected> (Vulnerable code not present)
NOTE: https://www.postgresql.org/support/security/CVE-2026-16238/
NOTE:
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-16239 (Type confusion in PostgreSQL "portal"/cursor lifecycle allows
a user t ...)
- - postgresql-18 <unfixed>
+ - postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
- postgresql-13 <unfixed>
NOTE: https://www.postgresql.org/support/security/CVE-2026-16239/
NOTE:
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-16241 (Integer underflow in PostgreSQL ECPG allows a database server
administ ...)
- - postgresql-18 <unfixed>
+ - postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
- postgresql-13 <unfixed>
NOTE: https://www.postgresql.org/support/security/CVE-2026-16241/
NOTE:
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-18024 (Buffer over-read in PostgreSQL ascii() SQL function allows a
user to d ...)
- - postgresql-18 <unfixed>
+ - postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
- postgresql-13 <unfixed>
NOTE: https://www.postgresql.org/support/security/CVE-2026-18024/
NOTE:
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-18408 (Untrusted data inclusion in pg_dump in PostgreSQL allows a
malicious s ...)
- - postgresql-18 <unfixed>
+ - postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
- postgresql-13 <unfixed>
NOTE: https://www.postgresql.org/support/security/CVE-2026-18408/
NOTE:
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-19385 (Heap buffer overflow in PostgreSQL pg_dump of long function
transform ...)
- - postgresql-18 <unfixed>
+ - postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
- postgresql-13 <unfixed>
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8fa2feba9afd7381a65f86bb6aec66b253a4c44a
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8fa2feba9afd7381a65f86bb6aec66b253a4c44a
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits