[DSA 6438-1] postgresql-17 security update
Moritz Muehlenhoff <[email protected]>
| Newsgroups | gmane.linux.debian.user.security.announce |
|---|---|
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-6438-1 [email protected] https://www.debian.org/security/ Moritz Muehlenhoff August 13, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : postgresql-17 CVE ID : CVE-2026-6464 CVE-2026-6469 CVE-2026-6470 CVE-2026-6471 CVE-2026-6473 CVE-2026-14662 CVE-2026-14663 CVE-2026-14664 CVE-2026-14666 CVE-2026-14668 CVE-2026-14669 CVE-2026-14670 CVE-2026-14671 CVE-2026-14672 CVE-2026-14673 CVE-2026-14677 CVE-2026-14678 CVE-2026-14679 CVE-2026-14680 CVE-2026-14681 CVE-2026-15741 CVE-2026-15742 CVE-2026-16239 CVE-2026-16241 CVE-2026-18024 CVE-2026-18408 CVE-2026-19385 Multiple security issues were discovered in PostgreSQL, which may result in execution of arbitrary code, incorrect authentication, information disclosure, or privilege escalation. The upstream fix to address CVE-2026-6471 requires additional changes to the configuration if some extensions are used. This affects the postgresql-17-wal2json, postgresql-17-squeeze, postgresql-17-pg-rewrite and postgresql-17-decoderbufs extensions included in Debian. Quoting from the changelog: | Restrict logical decoding output plugins to the set specified by | a new server parameter `output_plugin_libraries` (Jacob | Champion) | Previously, a replication user could select any loadable library | | Restrict logical decoding output plugins to the set specified by | a new server parameter `output_plugin_libraries` (Jacob | Champion) | Previously, a replication user could select any loadable library | for logical decoding, allowing exploits of various sorts. To | allow locking this down without breaking setups that worked | before, introduce a whitelist of allowed output plugins. | | By default, only the output plugins shipped as part of | PostgreSQL (`pgoutput` and `test_decoding`) are included in |`output_plugin_libraries`. Installations that rely on other | output plugins must add them after updating the server, for | example | | output_plugin_libraries = 'pgoutput, test_decoding, my_trusted_decoder' For the stable distribution (trixie), these problems have been fixed in version 17.11-0+deb13u1. We recommend that you upgrade your postgresql-17 packages. For the detailed security status of postgresql-17 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/postgresql-17 Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: [email protected] -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmp+M0AACgkQEMKTtsN8 TjYSkRAAq+WCKgv0P/U+a/CIvcmXuXcqcpKrd3C+qpaKwj5B7zjNykzti6fOD+4Q IyBjfe+WwywKbovPJF4wxN0jKugkp2LXYPI+LEx/IQVJojxrBsWB+lFuXsZidyFC NEVijFy5IVEbqne9KNbZWII6fDBbToPBjGl+cuMnF7uhAq+Hq5zXPtF1jKVeHzyy RzdfJ5MCFUnFddvHOPQhAAAFiKGph67Tn4IZs+Y/TxIYKR6tINHt81ajia5FiP8+ IZVkgWFa+J4AUEaCLsHcB6naLmAu8KmjJTCWJ2vmlOBbGFQxML6NNvxExY1tDHGd h7SVDZ0aRp2cWTQjHL8AVGYhYGt+93l02TNsOfEgi4jx8V0z2knU8HypGGoIWN7d 1XrGLJBUP0GONlqjd022HiD3JWMDi7qC5+yieo3LQ5I3dp8cvYAGrt+1GZa0ZR64 8buWndiHxKFZFLtr09c+/A3o/3hvNm1axFwMf1B2M3RPNzr7Yni2iihLjsq4Q81I XrQeY5+ojyFegBizgb7VEImnHZhZImBZw5/KCqWjJ/EG3HwwkKFUXz/5MdXc8UmT ncqpCblsvRKoFvC4J3ydd8O/pg8J+Uexh+w9aIWQus17WqnZiCDN+k5+10w1Kht/ kRu+txr8Jlns2gmj83xiW7MXcuMskmaMMcYYBL7nPKrodek0tyo= =HIP3 -----END PGP SIGNATURE-----