[ GLSA 202608-15 ] PostgreSQL: Multiple Vulnerabilities

[email protected]
Newsgroups gmane.linux.gentoo.announce
Message-ID <178694883611.1.13213746624127538382@f5bc8f6d682b>
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 202608-15
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                           https://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

 Severity: High
    Title: PostgreSQL: Multiple Vulnerabilities
     Date: August 17, 2026
     Bugs: #949747, #955658, #961496, #966064, #969976, #974982
       ID: 202608-15

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

Multiple vulnerabilities have been found in PostgreSQL, the worst of
which could result in arbitrary code execution.

Background
==========

PostgreSQL is an open source object-relational database management
system.

Affected packages
=================

Package            Vulnerable     Unaffected
-----------------  -------------  --------------
dev-db/postgresql  < 14.23-r1:14  >= 14.23-r1:14
                   < 15.18-r1:15  >= 15.18-r1:15
                   < 16.14-r1:16  >= 16.14-r1:16
                   < 17.10:17     >= 17.10:17
                   < 18.4:18      >= 18.4:18

Description
===========

Multiple vulnerabilities have been discovered in PostgreSQL. Please
review the CVE identifiers referenced below for details.

Impact
======

Please review the referenced CVE identifiers for details.

Workaround
==========

There is no known workaround at this time.

Resolution
==========

All PostgreSQL 14 users should upgrade to the latest version:

  # emerge --sync
  # emerge --ask --oneshot --verbose ">=dev-db/postgresql-14.23-r1:14"

All PostgreSQL 15 users should upgrade to the latest version:

  # emerge --sync
  # emerge --ask --oneshot --verbose ">=dev-db/postgresql-15.18-r1:15"

All PostgreSQL 16 users should upgrade to the latest version:

  # emerge --sync
  # emerge --ask --oneshot --verbose ">=dev-db/postgresql-16.14-r1:16"

All PostgreSQL 17 users should upgrade to the latest version:

  # emerge --sync
  # emerge --ask --oneshot --verbose ">=dev-db/postgresql-17.10:17"

All PostgreSQL 18 users should upgrade to the latest version:

  # emerge --sync
  # emerge --ask --oneshot --verbose ">=dev-db/postgresql-18.4:18"

References
==========

[ 1 ] CVE-2025-1094
      https://nvd.nist.gov/vuln/detail/CVE-2025-1094
[ 2 ] CVE-2025-4207
      https://nvd.nist.gov/vuln/detail/CVE-2025-4207
[ 3 ] CVE-2025-8713
      https://nvd.nist.gov/vuln/detail/CVE-2025-8713
[ 4 ] CVE-2025-8714
      https://nvd.nist.gov/vuln/detail/CVE-2025-8714
[ 5 ] CVE-2025-8715
      https://nvd.nist.gov/vuln/detail/CVE-2025-8715
[ 6 ] CVE-2025-12817
      https://nvd.nist.gov/vuln/detail/CVE-2025-12817
[ 7 ] CVE-2026-2003
      https://nvd.nist.gov/vuln/detail/CVE-2026-2003
[ 8 ] CVE-2026-2004
      https://nvd.nist.gov/vuln/detail/CVE-2026-2004
[ 9 ] CVE-2026-2005
      https://nvd.nist.gov/vuln/detail/CVE-2026-2005
[ 10 ] CVE-2026-2006
      https://nvd.nist.gov/vuln/detail/CVE-2026-2006
[ 11 ] CVE-2026-2007
      https://nvd.nist.gov/vuln/detail/CVE-2026-2007
[ 12 ] CVE-2026-6472
      https://nvd.nist.gov/vuln/detail/CVE-2026-6472
[ 13 ] CVE-2026-6473
      https://nvd.nist.gov/vuln/detail/CVE-2026-6473
[ 14 ] CVE-2026-6474
      https://nvd.nist.gov/vuln/detail/CVE-2026-6474
[ 15 ] CVE-2026-6475
      https://nvd.nist.gov/vuln/detail/CVE-2026-6475
[ 16 ] CVE-2026-6476
      https://nvd.nist.gov/vuln/detail/CVE-2026-6476
[ 17 ] CVE-2026-6477
      https://nvd.nist.gov/vuln/detail/CVE-2026-6477
[ 18 ] CVE-2026-6478
      https://nvd.nist.gov/vuln/detail/CVE-2026-6478
[ 19 ] CVE-2026-6479
      https://nvd.nist.gov/vuln/detail/CVE-2026-6479
[ 20 ] CVE-2026-6575
      https://nvd.nist.gov/vuln/detail/CVE-2026-6575
[ 21 ] CVE-2026-6637
      https://nvd.nist.gov/vuln/detail/CVE-2026-6637
[ 22 ] CVE-2026-6638
      https://nvd.nist.gov/vuln/detail/CVE-2026-6638

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

 https://security.gentoo.org/glsa/202608-15

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
[email protected] or alternatively, you may file a bug at
https://bugs.gentoo.org.

License
=======

Copyright 2026 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

https://creativecommons.org/licenses/by-sa/2.5
signature.asc (application/pgp-signature, 870 B)
-----BEGIN PGP SIGNATURE-----

iQJPBAEBCAA5FiEEpqTA6ABLMxh/aChGFMQkOaVy+9kFAmqCrOMbFIAAAAAABAAO
bWFudTIsMi41KzEuMTIsMiwyAAoJEBTEJDmlcvvZW2cP/izxwHmZ2EdszXDOUPgA
udpU4VdkQPsthXEWJ0Cwp8prHXr7bY3zb/Npe7U0r4/k/TKLHQ8bWAiTvdehUsz9
+hKkcoAe9DL8WqkP/4yvtkDNtVsTWVCkytdOJLWmlP4Jj8KM7zHxzXp3YkcEXhhS
jGm4QWs75DIAfTJxpEee5rG1ZEvF1rvVx2ANybNiIuWqiwdczMXs+IN38p5cyt2V
mfTpdITH2ueVBPRTdMYUkAvEYn+/okK6lvSEeSClSpQPvObBmXN//xib1vc9Eutq
f3LxaOldw+4vjlm+QKruB04VywJmsOfosSWGMsz8kWPENz7YfKOOfCWH02H25w9R
nck+BWPlq1KRIkxXGgXaLJiWi2N7ncev5YuRWcXlsdPjpmIky4OE1Umyce3BbVzU
U8MRNd5Bi6CZ1QRc82s+TywnK5KN0OfeC42DCcyKrGdW9y2iTY3sIVeTpmj7acdo
IF/8T01gr2FPOQfW/mSCU7mxwfPsCkXusGC2hI5agoQMxUwF2d6PD3HODBt957co
cKiYf+AVQlc3h/xV7hefrA1ksK5olGrYux2lkjYJq81hW9NE7jDwljt/Cr5U5xKj
SvC3kmPuy/1ekJyVCsWzA9ZdGoEqi5aiQOhXGLaaeLosM1/xLOsGMc0cQaqLwVPP
viwzll2PI82WJj2/enca3Y0f
=AO5z
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.