Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
8fa2feba by Salvatore Bonaccorso at 2026-08-14T06:29:09+02:00
Track fixed version for postgresql-18 issues via unstable upload

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -649,196 +649,196 @@ CVE-2026-13048 (Data::MuForm::Localizer versions 
through 0.05 for Perl execute P
 CVE-2026-13051 (Form::Processor::Field::HtmlArea versions from 0.06 through 
1.162360 f ...)
        NOT-FOR-US: Form::Processor Perl module
 CVE-2026-6464 (Untrusted data inclusion in PostgreSQL psql COPY may allow a 
server ad ...)
-       - postgresql-18 <unfixed>
+       - postgresql-18 18.6-1
        - postgresql-17 <removed>
        - postgresql-15 <removed>
        - postgresql-13 <unfixed>
        NOTE: https://www.postgresql.org/support/security/CVE-2026-6464/
        NOTE: 
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-6469 (Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER 
TYPE co ...)
-       - postgresql-18 <unfixed>
+       - postgresql-18 18.6-1
        - postgresql-17 <removed>
        - postgresql-15 <removed>
        - postgresql-13 <unfixed>
        NOTE: https://www.postgresql.org/support/security/CVE-2026-6469/
        NOTE: 
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-6470 (Missing authorization in PostgreSQL DDL commands allows an 
object crea ...)
-       - postgresql-18 <unfixed>
+       - postgresql-18 18.6-1
        - postgresql-17 <removed>
        - postgresql-15 <removed>
        - postgresql-13 <unfixed>
        NOTE: https://www.postgresql.org/support/security/CVE-2026-6470/
        NOTE: 
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-6471 (Missing authorization in PostgreSQL logical decoding allows a 
non-supe ...)
-       - postgresql-18 <unfixed>
+       - postgresql-18 18.6-1
        - postgresql-17 <removed>
        - postgresql-15 <removed>
        - postgresql-13 <unfixed>
        NOTE: https://www.postgresql.org/support/security/CVE-2026-6471/
        NOTE: 
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-14662 (Integer wraparound in PostgreSQL tsvector and tsquery data 
type functi ...)
-       - postgresql-18 <unfixed>
+       - postgresql-18 18.6-1
        - postgresql-17 <removed>
        - postgresql-15 <removed>
        - postgresql-13 <unfixed>
        NOTE: https://www.postgresql.org/support/security/CVE-2026-14662/
        NOTE: 
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-14663 (Cleartext storage in PostgreSQL pgcrypto disabled ciphers 
allows a use ...)
-       - postgresql-18 <unfixed>
+       - postgresql-18 18.6-1
        - postgresql-17 <removed>
        - postgresql-15 <removed>
        - postgresql-13 <unfixed>
        NOTE: https://www.postgresql.org/support/security/CVE-2026-14663/
        NOTE: 
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-14664 (Heap buffer overflow in PostgreSQL regexp allows the query 
author to e ...)
-       - postgresql-18 <unfixed>
+       - postgresql-18 18.6-1
        - postgresql-17 <removed>
        - postgresql-15 <removed>
        - postgresql-13 <unfixed>
        NOTE: https://www.postgresql.org/support/security/CVE-2026-14664/
        NOTE: 
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-14666 (Incomplete tracking in PostgreSQL of changes to role 
membership, role  ...)
-       - postgresql-18 <unfixed>
+       - postgresql-18 18.6-1
        - postgresql-17 <removed>
        - postgresql-15 <removed>
        - postgresql-13 <unfixed>
        NOTE: https://www.postgresql.org/support/security/CVE-2026-14666/
        NOTE: 
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-14668 (Type confusion regarding input of PostgreSQL ctid data type 
selectivit ...)
-       - postgresql-18 <unfixed>
+       - postgresql-18 18.6-1
        - postgresql-17 <removed>
        - postgresql-15 <removed>
        - postgresql-13 <unfixed>
        NOTE: https://www.postgresql.org/support/security/CVE-2026-14668/
        NOTE: 
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-14669 (Heap buffer overflow in PostgreSQL to_char(timestamptz) allows 
the par ...)
-       - postgresql-18 <unfixed>
+       - postgresql-18 18.6-1
        - postgresql-17 <removed>
        - postgresql-15 <removed>
        - postgresql-13 <unfixed>
        NOTE: https://www.postgresql.org/support/security/CVE-2026-14669/
        NOTE: 
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-14670 (Heap buffer overflow in PostgreSQL plperl return of a tied 
hash allows ...)
-       - postgresql-18 <unfixed>
+       - postgresql-18 18.6-1
        - postgresql-17 <removed>
        - postgresql-15 <removed>
        - postgresql-13 <unfixed>
        NOTE: https://www.postgresql.org/support/security/CVE-2026-14670/
        NOTE: 
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-14671 (Type confusion in PostgreSQL module "refint" allows an object 
creator  ...)
-       - postgresql-18 <unfixed>
+       - postgresql-18 18.6-1
        - postgresql-17 <removed>
        - postgresql-15 <removed>
        - postgresql-13 <unfixed>
        NOTE: https://www.postgresql.org/support/security/CVE-2026-14671/
        NOTE: 
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-14672 (Observable response discrepancy in PostgreSQL SCRAM 
authentication all ...)
-       - postgresql-18 <unfixed>
+       - postgresql-18 18.6-1
        - postgresql-17 <removed>
        - postgresql-15 <not-affected> ((Vulnerable code not present)
        - postgresql-13 <not-affected> ((Vulnerable code not present)
        NOTE: https://www.postgresql.org/support/security/CVE-2026-14672/
        NOTE: 
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-14673 (Untrusted search path in PostgreSQL amcheck allows a grantee 
of amchec ...)
-       - postgresql-18 <unfixed>
+       - postgresql-18 18.6-1
        - postgresql-17 <removed>
        - postgresql-15 <removed>
        - postgresql-13 <unfixed>
        NOTE: https://www.postgresql.org/support/security/CVE-2026-14673/
        NOTE: 
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-14676 (Heap buffer overflow in PostgreSQL pg_stat_statements allows 
the query ...)
-       - postgresql-18 <unfixed>
+       - postgresql-18 18.6-1
        - postgresql-17 <not-affected> (Vulnerable code not present)
        - postgresql-15 <not-affected> (Vulnerable code not present)
        - postgresql-13 <not-affected> (Vulnerable code not present)
        NOTE: https://www.postgresql.org/support/security/CVE-2026-14676/
        NOTE: 
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-14677 (Integer wraparound in PostgreSQL 32-bit builds of pltcl and 
plperl all ...)
-       - postgresql-18 <unfixed>
+       - postgresql-18 18.6-1
        - postgresql-17 <removed>
        - postgresql-15 <removed>
        - postgresql-13 <unfixed>
        NOTE: https://www.postgresql.org/support/security/CVE-2026-14677/
        NOTE: 
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-14678 (Buffer over-read in PostgreSQL pg_trgm index picksplit 
function reads  ...)
-       - postgresql-18 <unfixed>
+       - postgresql-18 18.6-1
        - postgresql-17 <removed>
        - postgresql-15 <removed>
        - postgresql-13 <unfixed>
        NOTE: https://www.postgresql.org/support/security/CVE-2026-14678/
        NOTE: 
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-14679 (Stack buffer overflow in PostgreSQL argument name matching 
allows an o ...)
-       - postgresql-18 <unfixed>
+       - postgresql-18 18.6-1
        - postgresql-17 <removed>
        - postgresql-15 <removed>
        - postgresql-13 <unfixed>
        NOTE: https://www.postgresql.org/support/security/CVE-2026-14679/
        NOTE: 
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-14680 (Type confusion with PostgreSQL "internal" data type arguments 
allows a ...)
-       - postgresql-18 <unfixed>
+       - postgresql-18 18.6-1
        - postgresql-17 <removed>
        - postgresql-15 <removed>
        - postgresql-13 <unfixed>
        NOTE: https://www.postgresql.org/support/security/CVE-2026-14680/
        NOTE: 
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-14681 (Improper enforcement of message integrity in PostgreSQL GSSAPI 
support ...)
-       - postgresql-18 <unfixed>
+       - postgresql-18 18.6-1
        - postgresql-17 <removed>
        - postgresql-15 <not-affected> (Vulnerable code not present)
        - postgresql-13 <not-affected> (Vulnerable code not present)
        NOTE: https://www.postgresql.org/support/security/CVE-2026-14681/
        NOTE: 
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-15741 (SQL injection in PostgreSQL EXTRACT() deparse allows an object 
owner t ...)
-       - postgresql-18 <unfixed>
+       - postgresql-18 18.6-1
        - postgresql-17 <removed>
        - postgresql-15 <removed>
        - postgresql-13 <unfixed>
        NOTE: https://www.postgresql.org/support/security/CVE-2026-15741/
        NOTE: 
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-15742 (Integer wraparound in PostgreSQL fuzzystrmatch allows a user 
to direct ...)
-       - postgresql-18 <unfixed>
+       - postgresql-18 18.6-1
        - postgresql-17 <removed>
        - postgresql-15 <removed>
        - postgresql-13 <unfixed>
        NOTE: https://www.postgresql.org/support/security/CVE-2026-15742/
        NOTE: 
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-16238 (Type confusion in PostgreSQL pg_restore_attribute_stats() 
allows an ob ...)
-       - postgresql-18 <unfixed>
+       - postgresql-18 18.6-1
        - postgresql-17 <not-affected> (Vulnerable code not present)
        - postgresql-15 <not-affected> (Vulnerable code not present)
        - postgresql-13 <not-affected> (Vulnerable code not present)
        NOTE: https://www.postgresql.org/support/security/CVE-2026-16238/
        NOTE: 
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-16239 (Type confusion in PostgreSQL "portal"/cursor lifecycle allows 
a user t ...)
-       - postgresql-18 <unfixed>
+       - postgresql-18 18.6-1
        - postgresql-17 <removed>
        - postgresql-15 <removed>
        - postgresql-13 <unfixed>
        NOTE: https://www.postgresql.org/support/security/CVE-2026-16239/
        NOTE: 
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-16241 (Integer underflow in PostgreSQL ECPG allows a database server 
administ ...)
-       - postgresql-18 <unfixed>
+       - postgresql-18 18.6-1
        - postgresql-17 <removed>
        - postgresql-15 <removed>
        - postgresql-13 <unfixed>
        NOTE: https://www.postgresql.org/support/security/CVE-2026-16241/
        NOTE: 
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-18024 (Buffer over-read in PostgreSQL ascii() SQL function allows a 
user to d ...)
-       - postgresql-18 <unfixed>
+       - postgresql-18 18.6-1
        - postgresql-17 <removed>
        - postgresql-15 <removed>
        - postgresql-13 <unfixed>
        NOTE: https://www.postgresql.org/support/security/CVE-2026-18024/
        NOTE: 
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-18408 (Untrusted data inclusion in pg_dump in PostgreSQL allows a 
malicious s ...)
-       - postgresql-18 <unfixed>
+       - postgresql-18 18.6-1
        - postgresql-17 <removed>
        - postgresql-15 <removed>
        - postgresql-13 <unfixed>
        NOTE: https://www.postgresql.org/support/security/CVE-2026-18408/
        NOTE: 
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-19385 (Heap buffer overflow in PostgreSQL pg_dump of long function 
transform  ...)
-       - postgresql-18 <unfixed>
+       - postgresql-18 18.6-1
        - postgresql-17 <removed>
        - postgresql-15 <removed>
        - postgresql-13 <unfixed>



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8fa2feba9afd7381a65f86bb6aec66b253a4c44a

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8fa2feba9afd7381a65f86bb6aec66b253a4c44a
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to