[DSA 6438-1] postgresql-17 security update

Moritz Muehlenhoff <[email protected]>
Newsgroups gmane.linux.debian.user.security.announce
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-6438-1                   [email protected]
https://www.debian.org/security/                       Moritz Muehlenhoff
August 13, 2026                       https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : postgresql-17
CVE ID         : CVE-2026-6464 CVE-2026-6469 CVE-2026-6470 CVE-2026-6471 
                 CVE-2026-6473 CVE-2026-14662 CVE-2026-14663 CVE-2026-14664 
                 CVE-2026-14666 CVE-2026-14668 CVE-2026-14669 CVE-2026-14670 
                 CVE-2026-14671 CVE-2026-14672 CVE-2026-14673 CVE-2026-14677 
                 CVE-2026-14678 CVE-2026-14679 CVE-2026-14680 CVE-2026-14681 
                 CVE-2026-15741 CVE-2026-15742 CVE-2026-16239 CVE-2026-16241 
                 CVE-2026-18024 CVE-2026-18408 CVE-2026-19385

Multiple security issues were discovered in PostgreSQL, which may
result in execution of arbitrary code, incorrect authentication,
information disclosure, or privilege escalation.

The upstream fix to address CVE-2026-6471 requires additional changes
to the configuration if some extensions are used. This affects the
postgresql-17-wal2json, postgresql-17-squeeze, postgresql-17-pg-rewrite
and postgresql-17-decoderbufs extensions included in Debian.
Quoting from the changelog:

| Restrict logical decoding output plugins to the set specified by
| a new server parameter `output_plugin_libraries` (Jacob
| Champion)
| Previously, a replication user could select any loadable library
|
| Restrict logical decoding output plugins to the set specified by
| a new server parameter `output_plugin_libraries` (Jacob
| Champion)
| Previously, a replication user could select any loadable library
| for logical decoding, allowing exploits of various sorts. To
| allow locking this down without breaking setups that worked
| before, introduce a whitelist of allowed output plugins.
|
| By default, only the output plugins shipped as part of
| PostgreSQL (`pgoutput` and `test_decoding`) are included in
|`output_plugin_libraries`. Installations that rely on other
| output plugins must add them after updating the server, for
| example
|
| output_plugin_libraries = 'pgoutput, test_decoding, my_trusted_decoder'

For the stable distribution (trixie), these problems have been fixed in
version 17.11-0+deb13u1.

We recommend that you upgrade your postgresql-17 packages.

For the detailed security status of postgresql-17 please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/postgresql-17

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: [email protected]
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmp+M0AACgkQEMKTtsN8
TjYSkRAAq+WCKgv0P/U+a/CIvcmXuXcqcpKrd3C+qpaKwj5B7zjNykzti6fOD+4Q
IyBjfe+WwywKbovPJF4wxN0jKugkp2LXYPI+LEx/IQVJojxrBsWB+lFuXsZidyFC
NEVijFy5IVEbqne9KNbZWII6fDBbToPBjGl+cuMnF7uhAq+Hq5zXPtF1jKVeHzyy
RzdfJ5MCFUnFddvHOPQhAAAFiKGph67Tn4IZs+Y/TxIYKR6tINHt81ajia5FiP8+
IZVkgWFa+J4AUEaCLsHcB6naLmAu8KmjJTCWJ2vmlOBbGFQxML6NNvxExY1tDHGd
h7SVDZ0aRp2cWTQjHL8AVGYhYGt+93l02TNsOfEgi4jx8V0z2knU8HypGGoIWN7d
1XrGLJBUP0GONlqjd022HiD3JWMDi7qC5+yieo3LQ5I3dp8cvYAGrt+1GZa0ZR64
8buWndiHxKFZFLtr09c+/A3o/3hvNm1axFwMf1B2M3RPNzr7Yni2iihLjsq4Q81I
XrQeY5+ojyFegBizgb7VEImnHZhZImBZw5/KCqWjJ/EG3HwwkKFUXz/5MdXc8UmT
ncqpCblsvRKoFvC4J3ydd8O/pg8J+Uexh+w9aIWQus17WqnZiCDN+k5+10w1Kht/
kRu+txr8Jlns2gmj83xiW7MXcuMskmaMMcYYBL7nPKrodek0tyo=
=HIP3
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.