SUSE-SU-2026:4015-1

    Dashboard / Vulnerabilities / SUSE-SU-2026:4015-1

    SUSE-SU-2026:4015-1

    Published: 7 Sept 2026Last Modified: 13 Sept 2026

    Summary: Security update for postgresql18

    Details: This update for postgresql18 fixes the following issues: - CVE-2026-6464: `psql` `COPY FROM STDIN` early failure processes data lines as `psql` commands (bsc#1275046). - CVE-2026-6469: `ALTER TABLE ALTER TYPE` resets extended statistics ownership (bsc#1275044). - CVE-2026-6470: failure to check type `USAGE` privilege (bsc#1275043). - CVE-2026-6471: logical decoding can `dlopen` arbitrary file (bsc#1275042). - CVE-2026-14662: `tsvector` and `tsquery` undersize allocations, via integer wraparound (bsc#1275001). - CVE-2026-14663: `pgcrypto`, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext (bsc#1275002). - CVE-2026-14664: `regexp` heap buffer overflow executes arbitrary code (bsc#1275068). - CVE-2026-14666: row security caching disregards role modifications (bsc#1275067). - CVE-2026-14668: `ctid` type confusion in selectivity estimator discloses derivative of arbitrary read (bsc#1275066). - CVE-2026-14669: `to_char` heap buffer overflow executes arbitrary code (bsc#1275065). - CVE-2026-14670: `plperl` tied object heap buffer overflow executes arbitrary code (bsc#1275064). - CVE-2026-14671: `refint` plan cache type confusion executes arbitrary code (bsc#1275063). - CVE-2026-14672: observable response discrepancy with non-default `scram_iterations` provides user existence oracle (bsc#1275062). - CVE-2026-14673: `amcheck` does not clear untrusted search path (bsc#1275061). - CVE-2026-14676: `pg_stat_statements` heap buffer overflow executes arbitrary code (bsc#1275060). - CVE-2026-14677: 32-bit `pltcl` and `plperl` undersize allocations, via integer wraparound (bsc#1275059). - CVE-2026-14678: `pg_trgm` `picksplit` reads past end of buffer (bsc#1275058). - CVE-2026-14679: stack buffer overflow in argument match writes `0x0` and `0x1` to server memory (bsc#1275057). - CVE-2026-14680: type confusion via 'internal' arguments (bsc#1275056). - CVE-2026-14681: improper enforcement of GSSAPI encryption when coupled with SSL (bsc#1275055). - CVE-2026-15741: expression deparse allows SQL injection via `EXTRACT` argument (bsc#1275054). - CVE-2026-15742: `fuzzystrmatch` writes effectively-arbitrary addresses, via integer wraparound (bsc#1275053). - CVE-2026-16238: type confusion in `pg_restore_attribute_stats()` executes arbitrary code (bsc#1275052). - CVE-2026-16239: type confusion in cursor `CLOSE + DECLARE` executes arbitrary code (bsc#1275051). - CVE-2026-16241: ECPG integer underflow can crash the client (bsc#1275050). - CVE-2026-18024: `ascii()` function reads past end of buffer (bsc#1275049). - CVE-2026-18408: `psql` `\unrestrict` lets superuser of `pg_dump` origin server execute arbitrary code in `psql` client (bsc#1275048). - CVE-2026-19385: `pg_dump` heap buffer overflow executes arbitrary code (bsc#1275047). Changes for postgresql18: - Update to version 18.6: * https://www.postgresql.org/docs/18/release-18-6.html * https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/

    References: https://www.suse.com/support/update/announcement/2026/suse-su-20264015-1/, https://bugzilla.suse.com/1275001, https://bugzilla.suse.com/1275002, https://bugzilla.suse.com/1275042, https://bugzilla.suse.com/1275043, https://bugzilla.suse.com/1275044, https://bugzilla.suse.com/1275046, https://bugzilla.suse.com/1275047, https://bugzilla.suse.com/1275048, https://bugzilla.suse.com/1275049, https://bugzilla.suse.com/1275050, https://bugzilla.suse.com/1275051, https://bugzilla.suse.com/1275052, https://bugzilla.suse.com/1275053, https://bugzilla.suse.com/1275054, https://bugzilla.suse.com/1275055, https://bugzilla.suse.com/1275056, https://bugzilla.suse.com/1275057, https://bugzilla.suse.com/1275058, https://bugzilla.suse.com/1275059, https://bugzilla.suse.com/1275060, https://bugzilla.suse.com/1275061, https://bugzilla.suse.com/1275062, https://bugzilla.suse.com/1275063, https://bugzilla.suse.com/1275064, https://bugzilla.suse.com/1275065, https://bugzilla.suse.com/1275066, https://bugzilla.suse.com/1275067, https://bugzilla.suse.com/1275068, https://www.suse.com/security/cve/CVE-2026-14662, https://www.suse.com/security/cve/CVE-2026-14663, https://www.suse.com/security/cve/CVE-2026-14664, https://www.suse.com/security/cve/CVE-2026-14666, https://www.suse.com/security/cve/CVE-2026-14668, https://www.suse.com/security/cve/CVE-2026-14669, https://www.suse.com/security/cve/CVE-2026-14670, https://www.suse.com/security/cve/CVE-2026-14671, https://www.suse.com/security/cve/CVE-2026-14672, https://www.suse.com/security/cve/CVE-2026-14673, https://www.suse.com/security/cve/CVE-2026-14676, https://www.suse.com/security/cve/CVE-2026-14677, https://www.suse.com/security/cve/CVE-2026-14678, https://www.suse.com/security/cve/CVE-2026-14679, https://www.suse.com/security/cve/CVE-2026-14680, https://www.suse.com/security/cve/CVE-2026-14681, https://www.suse.com/security/cve/CVE-2026-15741, https://www.suse.com/security/cve/CVE-2026-15742, https://www.suse.com/security/cve/CVE-2026-16238, https://www.suse.com/security/cve/CVE-2026-16239, https://www.suse.com/security/cve/CVE-2026-16241, https://www.suse.com/security/cve/CVE-2026-18024, https://www.suse.com/security/cve/CVE-2026-18408, https://www.suse.com/security/cve/CVE-2026-19385, https://www.suse.com/security/cve/CVE-2026-6464, https://www.suse.com/security/cve/CVE-2026-6469, https://www.suse.com/security/cve/CVE-2026-6470, https://www.suse.com/security/cve/CVE-2026-6471

    Affected packages

    Package

    Name: postgresql18

    Purl: pkg:rpm/suse/postgresql18&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOS

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -18.6-150200.5.17.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    SUSE-SU-2026:4015-1 | CVE-DB