[security - high] postgresql:15 security update, postgresql-15.19-1.module+el9+1200+ce050a73

エラータID: AXSA:2026-1952:01

リリース日: 
2026/10/02 Friday - 15:08
題名: 
[security - high] postgresql:15 security update, postgresql-15.19-1.module+el9+1200+ce050a73
影響のあるチャネル: 
MIRACLE LINUX 9 for x86_64
Severity: 
High
Description: 

PostgreSQL is an advanced object-relational database management system (DBMS).

Security Fix(es):

* postgresql: PostgreSQL: Arbitrary code execution via integer wraparound in tsvector and tsquery functions (CVE-2026-14662)
* postgresql: PostgreSQL: Arbitrary code execution via untrusted data inclusion in pg_dump (CVE-2026-18408)
* postgresql: PostgreSQL psql: Arbitrary command execution via untrusted data in COPY FROM STDIN (CVE-2026-6464)
* postgresql: PostgreSQL: Arbitrary code execution via logical decoding plugin (CVE-2026-6471)
* postgresql: PostgreSQL: Arbitrary code execution via type confusion with "internal" arguments (CVE-2026-14680)
* postgresql: PostgreSQL: Arbitrary code execution via heap buffer overflow in regexp (CVE-2026-14664)
* postgresql: pltcl: plperl: PostgreSQL: Arbitrary code execution in 32-bit pltcl and plperl (CVE-2026-14677)
* postgresql-fuzzystrmatch: PostgreSQL fuzzystrmatch: Arbitrary code execution via integer wraparound (CVE-2026-15742)
* postgresql: PostgreSQL: Arbitrary code execution via type confusion in cursor lifecycle (CVE-2026-16239)
* postgresql: PostgreSQL: Arbitrary code execution via long POSIX timezone abbreviation (CVE-2026-14669)
* postgresql: PostgreSQL: Stack buffer overflow via OUT parameter count manipulation (CVE-2026-14679)
* postgresql: PostgreSQL: Arbitrary code execution via type confusion in 'refint' module (CVE-2026-14671)
* postgresql: PostgreSQL: Arbitrary code execution via plperl tied hash heap buffer overflow (CVE-2026-14670)
* postgresql: PostgreSQL: Information disclosure via type confusion in ctid selectivity estimator (CVE-2026-14668)
* postgresql: PostgreSQL pg_dump: Arbitrary code execution via crafted transform lists (CVE-2026-19385)
* postgresql: PostgreSQL: Privilege escalation via SQL injection in EXTRACT() deparse (CVE-2026-15741)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-14662
Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds, via crafted large inputs. This may execute arbitrary code as the operating system user running the database. These types are typically sourced from application logic, not taken from the application's user. Hence, application users attacking the database, through the application as a conduit, are unlikely. CVE-2026-6473 had fixed similar problems. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
CVE-2026-14664
Heap buffer overflow in PostgreSQL regexp allows the query author to execute arbitrary code as the operating system user running the database, via text that would not pass encoding validation. This shares heritage with CVE-2026-2006, but this case involved unanticipated data growth when round-tripped through pg_wchar. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
CVE-2026-14668
Type confusion regarding input of PostgreSQL ctid data type selectivity estimator allows an object creator to view a calculation derived from the value of an arbitrary 4-byte span of memory, via a chosen non-ctid input. While the calculation loses precision, substantial memory value recovery appears possible. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
CVE-2026-14669
Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosing the timezone to execute arbitrary code as the operating system user running the database, via a long POSIX timezone abbreviation. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
CVE-2026-14670
Heap buffer overflow in PostgreSQL plperl return of a tied hash allows the function owner to execute arbitrary code as the operating system user running the database, via a crafted function body. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
CVE-2026-14671
Type confusion in PostgreSQL module "refint" allows an object creator to execute arbitrary code as the operating system user running the database. The fix for this emerged as a non-security bug report, and the fix appear in the git repository with subject "refint: Remove plan cache.", without a CVE number. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
CVE-2026-14677
Integer wraparound in PostgreSQL 32-bit builds of pltcl and plperl allows an object creator to cause the server to undersize an allocation and write out-of-bounds via crafted function bodies. This may execute arbitrary code as the operating system user running the database. CVE-2026-6473 had fixed similar problems. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
CVE-2026-14679
Stack buffer overflow in PostgreSQL argument name matching allows an object creator to achieve unknown impacts via OUT parameter count. The attack can write only 0x0 and 0x1 bytes. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
CVE-2026-14680
Type confusion with PostgreSQL "internal" data type arguments allows any user to execute arbitrary code as the operating system user running the database, via calls to functions with that argument type. Type "internal" represents a class of mutually-incompatible data structures not intended for access from SQL. The system intended to prevent such function calls, but this prevention had gaps. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
CVE-2026-15741
SQL injection in PostgreSQL EXTRACT() deparse allows an object owner to execute arbitrary SQL as a superuser via a hostile object definition. Attacks affect expression deparse consumers broadly, including pg_dump, psql commands like \sf, and any similar usage in non-core tools. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
CVE-2026-15742
Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct writes to a huge range of addresses, executing arbitrary code as the operating system user running the database, via extreme inputs to SQL function levenshtein() or levenshtein_less_equal(). Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
CVE-2026-16239
Type confusion in PostgreSQL "portal"/cursor lifecycle allows a user to execute arbitrary code as the operating system user running the database, via re-creation of a cursor or other portal with different types. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
CVE-2026-18408
Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql \restrict meta-command input expansion. The fix for CVE-2025-8714 introduced \restrict and \unrestrict to block this attack, but \unrestrict itself was sufficient for an attack. pg_dumpall is also affected. pg_restore is affected when used to generate a plain-format dump. Non-core use of \restrict would be affected, but we've not identified non-core use. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
CVE-2026-19385
Heap buffer overflow in PostgreSQL pg_dump of long function transform lists allows an object creator to execute arbitrary code as the operating system user running pg_dump, via a crafted transform list. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
CVE-2026-6464
Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection. If the "COPY FROM STDIN" or "\copy FROM STDIN" command fails before the server indicates that it awaits input rows, psql processes the in-line data rows as psql commands. "COPY FROM" with a filename is unaffected. The server administrator has no inherent control over the data rows, so a complete attack requires the attacker to separately acquire control of both the server and the data rows. Alternatively, an attacker controlling data rows alone might complete an attack through a coincidental error that they don't control. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
CVE-2026-6471
Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice of logical decoding plugin. This in turn runs arbitrary code as that account. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Modularity name: "postgresql"
Stream name: "15"

解決策: 

Update packages.

追加情報: 

N/A

ダウンロード: 

SRPMS
  1. pgaudit-1.7.0-1.module+el9+1200+ce050a73.src.rpm
    MD5: ed98a886676018ec449404bcaec5e807
    SHA-256: edce20ca8f72a4f611b7f683c411ee67eb8ace40065470c9c5178431f1b1922c
    Size: 51.24 kB
  2. pg_repack-1.4.8-2.module+el9+1200+ce050a73.src.rpm
    MD5: bb8451e4120f7b19677eeaeb8aaff1ac
    SHA-256: d2a3e484eb018dcf7ebc1ae3b2e7c90d8eb8e44c61d53e6c0c814df1b267611a
    Size: 102.34 kB
  3. postgres-decoderbufs-1.9.7-1.Final.module+el9+1200+ce050a73.src.rpm
    MD5: 2e6d853dc2254f20a9b86414cc5f8982
    SHA-256: 9fd5e3bb0528ce80d30e05ced7be6607c576dc03e616483f087eaef2585bb7e5
    Size: 21.45 kB
  4. postgresql-15.19-1.module+el9+1200+ce050a73.src.rpm
    MD5: 0321bffaf0476870423afd045c0ad608
    SHA-256: ba9c50cb7a88a7d7e5b24540d0a88660b8e0414229af1b21c9fac18f9db6282d
    Size: 51.35 MB

Asianux Server 9 for x86_64
  1. pgaudit-1.7.0-1.module+el9+1200+ce050a73.x86_64.rpm
    MD5: dc3202629f48b6f97228e82f6f104332
    SHA-256: 7791133e97853c3fb5fd7ea26bda1eaf77de0405f94fb9b30abc155232ca4811
    Size: 27.49 kB
  2. pgaudit-debugsource-1.7.0-1.module+el9+1200+ce050a73.x86_64.rpm
    MD5: 9f8a5becd069cdca916fd388128bfd36
    SHA-256: 535832b5e00af166706954e2eb4cd063928c54df50977e775ffa0837fe6fb362
    Size: 22.29 kB
  3. pg_repack-1.4.8-2.module+el9+1200+ce050a73.x86_64.rpm
    MD5: 3811225cbeb93825c866eb0db58b6bcf
    SHA-256: 82da960a39aa0129e8dbd9ff0fcd5b34e07d36778209488ec8fdd3cea10f23f5
    Size: 90.95 kB
  4. pg_repack-debugsource-1.4.8-2.module+el9+1200+ce050a73.x86_64.rpm
    MD5: 18aa186c237222326764617f38310b3c
    SHA-256: 59da358550ac97c925f80e7183d8855502d79b8ac6c35df73b81ae871be56adc
    Size: 48.09 kB
  5. postgres-decoderbufs-1.9.7-1.Final.module+el9+1200+ce050a73.x86_64.rpm
    MD5: 91e4e4d3da181205c983528304ca1f18
    SHA-256: d9de0fdc825bbd789fa9880f2d8a55a106f6ee785bce40d81e0b1248fb8e0219
    Size: 22.72 kB
  6. postgres-decoderbufs-debugsource-1.9.7-1.Final.module+el9+1200+ce050a73.x86_64.rpm
    MD5: 14e1a30dd98eaa2b241d112a24bc88ba
    SHA-256: 2320394a450c19c3aa7bfc8b7cfa4762db37c0e124c9115df18fdb78b600ddc6
    Size: 16.55 kB
  7. postgresql-15.19-1.module+el9+1200+ce050a73.x86_64.rpm
    MD5: 76f80dd527cb9abde42dcf65788fac84
    SHA-256: eea5f540da5465311b570d07ac6c638f52a834b8d3f36fa1d31863cef5e3b831
    Size: 1.75 MB
  8. postgresql-contrib-15.19-1.module+el9+1200+ce050a73.x86_64.rpm
    MD5: 22847a96812280c3828633a726c91835
    SHA-256: 433d07bfcbbac643334de554ea60ab33b7369841a94e06522b14cdd882f72f85
    Size: 0.98 MB
  9. postgresql-debugsource-15.19-1.module+el9+1200+ce050a73.x86_64.rpm
    MD5: 15a12fa653430b7cca2400ef894ba8c6
    SHA-256: 8615823bb5117067ee7b8bf561018da5820e7f851dc1b498365ebb2d3fd72e90
    Size: 16.22 MB
  10. postgresql-docs-15.19-1.module+el9+1200+ce050a73.x86_64.rpm
    MD5: 1e04a27f40161ccf7a968be094dc545e
    SHA-256: 043e5c1ed357aa8fec605ca092668219475b3c1de3657e585481b969f6fc73c9
    Size: 10.17 MB
  11. postgresql-plperl-15.19-1.module+el9+1200+ce050a73.x86_64.rpm
    MD5: 531b37e508ac165c3472ac4c6776f828
    SHA-256: 5b2fc5f25d779d1193011c092b5c8a2199130d40eacf92562f60aa487ff7a96e
    Size: 77.76 kB
  12. postgresql-plpython3-15.19-1.module+el9+1200+ce050a73.x86_64.rpm
    MD5: cd37969aa92765ad9023f0f23b350ba0
    SHA-256: 64c9bbd9a2b2fc09f8b5200c4fc50b63c8ca8f522a2c8e276754e6a625c782b5
    Size: 100.65 kB
  13. postgresql-pltcl-15.19-1.module+el9+1200+ce050a73.x86_64.rpm
    MD5: c07d93f950809808e8216b3f9be67ab5
    SHA-256: 633fc5b3875b23d9e7bab175eadfafb589112a17763f024dd72c9ff86c9debb3
    Size: 51.57 kB
  14. postgresql-private-devel-15.19-1.module+el9+1200+ce050a73.x86_64.rpm
    MD5: acbbab49344392e9911f7f4ef19bf52f
    SHA-256: b266d5e03fbd11d0f50d4edd4c615fe3eef14d3abe6a39037caafcd4909e9a3f
    Size: 67.33 kB
  15. postgresql-private-libs-15.19-1.module+el9+1200+ce050a73.x86_64.rpm
    MD5: 3c72532ab58cd292aec1f4cc1b780a29
    SHA-256: 596826e864d0a97b91129951721b9ea48d7669fc631c713c56c46bd5de33f9be
    Size: 144.16 kB
  16. postgresql-server-15.19-1.module+el9+1200+ce050a73.x86_64.rpm
    MD5: 523df40014ab598872de1a43ae74eea6
    SHA-256: e875df374ce7d9211a4fea051a473f9c3c50e8119f6245a2d73a6fe3b93d260c
    Size: 6.37 MB
  17. postgresql-server-devel-15.19-1.module+el9+1200+ce050a73.x86_64.rpm
    MD5: 6d0fed70525d23c2999bee1524ee92af
    SHA-256: c9f89ba086caa7cc92194980a95158e724e75139cca14236dab8cce9cd997265
    Size: 1.46 MB
  18. postgresql-static-15.19-1.module+el9+1200+ce050a73.x86_64.rpm
    MD5: fc26f552616580c1bdee2229f1749c3e
    SHA-256: 82aac866d834ad28def489eabb50be59adc78feb65e46e437f26948b05290bd9
    Size: 130.34 kB
  19. postgresql-test-15.19-1.module+el9+1200+ce050a73.x86_64.rpm
    MD5: 247a77b576748a99378b35db6f7f4cd0
    SHA-256: 24d6ea1052dce43a04e3dafbc3a048c218a01ab08f454d708f18c5b27182b1e1
    Size: 1.72 MB
  20. postgresql-test-rpm-macros-15.19-1.module+el9+1200+ce050a73.noarch.rpm
    MD5: 6e43d561fcceec4a06872c00f44ba96f
    SHA-256: d52e5d719103d7d074b050cc85aceac0f75be9477f70a1223669bbb0f8b02d4f
    Size: 9.49 kB
  21. postgresql-upgrade-15.19-1.module+el9+1200+ce050a73.x86_64.rpm
    MD5: bcbec62dd23650a51f4ebfa4b31d2b21
    SHA-256: be5cd4d3793b48c2cb5f5ce5b1e4929e97f96ee5614fcc228d412118df6ab9fa
    Size: 4.77 MB
  22. postgresql-upgrade-devel-15.19-1.module+el9+1200+ce050a73.x86_64.rpm
    MD5: 516a16b04dd860631f6bcfaed76c7099
    SHA-256: 2baf94fc5d01bbd54f1acfcff2281f7a52acfa7ee94e6327009bfe47e1504b5e
    Size: 1.24 MB