openSUSE-SU-2026:21699-1: important: Security update for postgresql14

[email protected]
Newsgroups gmane.linux.suse.security.announce
Message-ID <[email protected]>
openSUSE security update: security update for postgresql14
-------------------------------------------------------------

Announcement ID: openSUSE-SU-2026:21699-1
Rating: important
References:

  * bsc#1275001
  * bsc#1275002
  * bsc#1275042
  * bsc#1275043
  * bsc#1275044
  * bsc#1275046
  * bsc#1275047
  * bsc#1275048
  * bsc#1275049
  * bsc#1275050
  * bsc#1275051
  * bsc#1275053
  * bsc#1275054
  * bsc#1275056
  * bsc#1275057
  * bsc#1275058
  * bsc#1275059
  * bsc#1275061
  * bsc#1275063
  * bsc#1275064
  * bsc#1275065
  * bsc#1275066
  * bsc#1275067
  * bsc#1275068



Cross-References:

  * CVE-2026-14662
  * CVE-2026-14663
  * CVE-2026-14664
  * CVE-2026-14666
  * CVE-2026-14668
  * CVE-2026-14669
  * CVE-2026-14670
  * CVE-2026-14671
  * CVE-2026-14673
  * CVE-2026-14677
  * CVE-2026-14678
  * CVE-2026-14679
  * CVE-2026-14680
  * CVE-2026-15741
  * CVE-2026-15742
  * CVE-2026-16239
  * CVE-2026-16241
  * CVE-2026-18024
  * CVE-2026-18408
  * CVE-2026-19385
  * CVE-2026-6464
  * CVE-2026-6469
  * CVE-2026-6470
  * CVE-2026-6471



CVSS scores:

  * CVE-2026-14662 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-14663 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
  * CVE-2026-14664 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-14666 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
  * CVE-2026-14668 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
  * CVE-2026-14669 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-14670 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-14671 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-14673 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
  * CVE-2026-14677 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-14678 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
  * CVE-2026-14679 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
  * CVE-2026-14680 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-15741 ( SUSE ): 8 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
  * CVE-2026-15742 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-16239 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-16241 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L
  * CVE-2026-18024 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
  * CVE-2026-18408 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
  * CVE-2026-19385 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-6464 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
  * CVE-2026-6469 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L
  * CVE-2026-6470 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
  * CVE-2026-6471 ( SUSE ): 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Affected Products:

         openSUSE Leap 16.0

-------------------------------------------------------------

An update that solves 24 vulnerabilities and has 24 bug fixes can now be installed.

Description:

This update for postgresql14 fixes the following issues:

- CVE-2026-6464: `psql` `COPY FROM STDIN` early failure processes data lines as `psql` commands (bsc#1275046).
- CVE-2026-6469: `ALTER TABLE ALTER TYPE` resets extended statistics ownership (bsc#1275044).
- CVE-2026-6470: failure to check type `USAGE` privilege (bsc#1275043).
- CVE-2026-6471: logical decoding can `dlopen` arbitrary file (bsc#1275042).
- CVE-2026-14662: `tsvector` and `tsquery` undersize allocations, via integer wraparound (bsc#1275001).
- CVE-2026-14663: `pgcrypto`, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext
  (bsc#1275002).
- CVE-2026-14664: `regexp` heap buffer overflow executes arbitrary code (bsc#1275068).
- CVE-2026-14666: row security caching disregards role modifications (bsc#1275067).
- CVE-2026-14668: `ctid` type confusion in selectivity estimator discloses derivative of arbitrary read
  (bsc#1275066).
- CVE-2026-14669: `to_char` heap buffer overflow executes arbitrary code (bsc#1275065).
- CVE-2026-14670: `plperl` tied object heap buffer overflow executes arbitrary code (bsc#1275064).
- CVE-2026-14671: `refint` plan cache type confusion executes arbitrary code (bsc#1275063).
- CVE-2026-14673: `amcheck` does not clear untrusted search path (bsc#1275061).
- CVE-2026-14677: 32-bit `pltcl` and `plperl` undersize allocations, via integer wraparound (bsc#1275059).
- CVE-2026-14678: `pg_trgm` `picksplit` reads past end of buffer (bsc#1275058).
- CVE-2026-14679: stack buffer overflow in argument match writes `0x0` and `0x1` to server memory (bsc#1275057).
- CVE-2026-14680: type confusion via "internal" arguments (bsc#1275056).
- CVE-2026-15741: expression deparse allows SQL injection via `EXTRACT` argument (bsc#1275054).
- CVE-2026-15742: `fuzzystrmatch` writes effectively-arbitrary addresses, via integer wraparound (bsc#1275053).
- CVE-2026-16239: type confusion in cursor `CLOSE + DECLARE` executes arbitrary code (bsc#1275051).
- CVE-2026-16241: ECPG integer underflow can crash the client (bsc#1275050).
- CVE-2026-18024: `ascii()` function reads past end of buffer (bsc#1275049).
- CVE-2026-18408: `psql` `\unrestrict` lets superuser of `pg_dump` origin server execute arbitrary code in `psql`
  client (bsc#1275048).
- CVE-2026-19385: `pg_dump` heap buffer overflow executes arbitrary code (bsc#1275047).

Changes for postgresql14:

- Let `llvmjit-devel` require the `llc` and `clang` binaries to fix build of extensions on SLE-16 and newer.
- Use LLVM 15 on SLE-15 up to SP5 and LLVM 17 on SP6 and SP7.
- Update to version 14.24:
  * https://www.postgresql.org/docs/14/release-14-24.html
  * https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/


Patch instructions:

   To install this openSUSE security update use the suse recommended installation methods
   like YaST online_update or "zypper patch".
   Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

   zypper in -t patch openSUSE-Leap-16.0-1555=1

Package List:

- openSUSE Leap 16.0:

  postgresql14-14.24-160000.1.1
  postgresql14-contrib-14.24-160000.1.1
  postgresql14-devel-14.24-160000.1.1
  postgresql14-docs-14.24-160000.1.1
  postgresql14-llvmjit-14.24-160000.1.1
  postgresql14-llvmjit-devel-14.24-160000.1.1
  postgresql14-plperl-14.24-160000.1.1
  postgresql14-plpython-14.24-160000.1.1
  postgresql14-pltcl-14.24-160000.1.1
  postgresql14-server-14.24-160000.1.1
  postgresql14-server-devel-14.24-160000.1.1
  postgresql14-test-14.24-160000.1.1

References:

  * https://www.suse.com/security/cve/CVE-2026-14662.html
  * https://www.suse.com/security/cve/CVE-2026-14663.html
  * https://www.suse.com/security/cve/CVE-2026-14664.html
  * https://www.suse.com/security/cve/CVE-2026-14666.html
  * https://www.suse.com/security/cve/CVE-2026-14668.html
  * https://www.suse.com/security/cve/CVE-2026-14669.html
  * https://www.suse.com/security/cve/CVE-2026-14670.html
  * https://www.suse.com/security/cve/CVE-2026-14671.html
  * https://www.suse.com/security/cve/CVE-2026-14673.html
  * https://www.suse.com/security/cve/CVE-2026-14677.html
  * https://www.suse.com/security/cve/CVE-2026-14678.html
  * https://www.suse.com/security/cve/CVE-2026-14679.html
  * https://www.suse.com/security/cve/CVE-2026-14680.html
  * https://www.suse.com/security/cve/CVE-2026-15741.html
  * https://www.suse.com/security/cve/CVE-2026-15742.html
  * https://www.suse.com/security/cve/CVE-2026-16239.html
  * https://www.suse.com/security/cve/CVE-2026-16241.html
  * https://www.suse.com/security/cve/CVE-2026-18024.html
  * https://www.suse.com/security/cve/CVE-2026-18408.html
  * https://www.suse.com/security/cve/CVE-2026-19385.html
  * https://www.suse.com/security/cve/CVE-2026-6464.html
  * https://www.suse.com/security/cve/CVE-2026-6469.html
  * https://www.suse.com/security/cve/CVE-2026-6470.html
  * https://www.suse.com/security/cve/CVE-2026-6471.html
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.