SUSE-SU-2026:4018-1
Dashboard / Vulnerabilities / SUSE-SU-2026:4018-1
SUSE-SU-2026:4018-1
Summary: Security update for postgresql15
Details: This update for postgresql15 fixes the following issues: - CVE-2026-6464: `psql` `COPY FROM STDIN` early failure processes data lines as `psql` commands (bsc#1275046). - CVE-2026-6469: `ALTER TABLE ALTER TYPE` resets extended statistics ownership (bsc#1275044). - CVE-2026-6470: failure to check type `USAGE` privilege (bsc#1275043). - CVE-2026-6471: logical decoding can `dlopen` arbitrary file (bsc#1275042). - CVE-2026-14662: `tsvector` and `tsquery` undersize allocations, via integer wraparound (bsc#1275001). - CVE-2026-14663: `pgcrypto`, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext (bsc#1275002). - CVE-2026-14664: `regexp` heap buffer overflow executes arbitrary code (bsc#1275068). - CVE-2026-14666: row security caching disregards role modifications (bsc#1275067). - CVE-2026-14668: `ctid` type confusion in selectivity estimator discloses derivative of arbitrary read (bsc#1275066). - CVE-2026-14669: `to_char` heap buffer overflow executes arbitrary code (bsc#1275065). - CVE-2026-14670: `plperl` tied object heap buffer overflow executes arbitrary code (bsc#1275064). - CVE-2026-14671: `refint` plan cache type confusion executes arbitrary code (bsc#1275063). - CVE-2026-14673: `amcheck` does not clear untrusted search path (bsc#1275061). - CVE-2026-14677: 32-bit `pltcl` and `plperl` undersize allocations, via integer wraparound (bsc#1275059). - CVE-2026-14678: `pg_trgm` `picksplit` reads past end of buffer (bsc#1275058). - CVE-2026-14679: stack buffer overflow in argument match writes `0x0` and `0x1` to server memory (bsc#1275057). - CVE-2026-14680: type confusion via 'internal' arguments (bsc#1275056). - CVE-2026-15741: expression deparse allows SQL injection via `EXTRACT` argument (bsc#1275054). - CVE-2026-15742: `fuzzystrmatch` writes effectively-arbitrary addresses, via integer wraparound (bsc#1275053). - CVE-2026-16239: type confusion in cursor `CLOSE + DECLARE` executes arbitrary code (bsc#1275051). - CVE-2026-16241: ECPG integer underflow can crash the client (bsc#1275050). - CVE-2026-18024: `ascii()` function reads past end of buffer (bsc#1275049). - CVE-2026-18408: `psql` `\unrestrict` lets superuser of `pg_dump` origin server execute arbitrary code in `psql` client (bsc#1275048). - CVE-2026-19385: `pg_dump` heap buffer overflow executes arbitrary code (bsc#1275047). Changes for postgresql15: - Update to version 15.19: * https://www.postgresql.org/docs/15/release-15-19.html * https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
References: https://www.suse.com/support/update/announcement/2026/suse-su-20264018-1/, https://bugzilla.suse.com/1275001, https://bugzilla.suse.com/1275002, https://bugzilla.suse.com/1275042, https://bugzilla.suse.com/1275043, https://bugzilla.suse.com/1275044, https://bugzilla.suse.com/1275046, https://bugzilla.suse.com/1275047, https://bugzilla.suse.com/1275048, https://bugzilla.suse.com/1275049, https://bugzilla.suse.com/1275050, https://bugzilla.suse.com/1275051, https://bugzilla.suse.com/1275053, https://bugzilla.suse.com/1275054, https://bugzilla.suse.com/1275056, https://bugzilla.suse.com/1275057, https://bugzilla.suse.com/1275058, https://bugzilla.suse.com/1275059, https://bugzilla.suse.com/1275061, https://bugzilla.suse.com/1275063, https://bugzilla.suse.com/1275064, https://bugzilla.suse.com/1275065, https://bugzilla.suse.com/1275066, https://bugzilla.suse.com/1275067, https://bugzilla.suse.com/1275068, https://www.suse.com/security/cve/CVE-2026-14662, https://www.suse.com/security/cve/CVE-2026-14663, https://www.suse.com/security/cve/CVE-2026-14664, https://www.suse.com/security/cve/CVE-2026-14666, https://www.suse.com/security/cve/CVE-2026-14668, https://www.suse.com/security/cve/CVE-2026-14669, https://www.suse.com/security/cve/CVE-2026-14670, https://www.suse.com/security/cve/CVE-2026-14671, https://www.suse.com/security/cve/CVE-2026-14673, https://www.suse.com/security/cve/CVE-2026-14677, https://www.suse.com/security/cve/CVE-2026-14678, https://www.suse.com/security/cve/CVE-2026-14679, https://www.suse.com/security/cve/CVE-2026-14680, https://www.suse.com/security/cve/CVE-2026-15741, https://www.suse.com/security/cve/CVE-2026-15742, https://www.suse.com/security/cve/CVE-2026-16239, https://www.suse.com/security/cve/CVE-2026-16241, https://www.suse.com/security/cve/CVE-2026-18024, https://www.suse.com/security/cve/CVE-2026-18408, https://www.suse.com/security/cve/CVE-2026-19385, https://www.suse.com/security/cve/CVE-2026-6464, https://www.suse.com/security/cve/CVE-2026-6469, https://www.suse.com/security/cve/CVE-2026-6470, https://www.suse.com/security/cve/CVE-2026-6471
Affected packages
Package
Name: postgresql15
Purl: pkg:rpm/suse/postgresql15&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOS
Affected ranges
Type: ECOSYSTEM
Events:
