[Git][security-tracker-team/security-tracker][master] pglogical triagging

Bastien Roucariès (@rouca) rouca at debian.org
Wed Aug 5 09:12:58 BST 2026



Bastien Roucariès pushed to branch master at Debian Security Tracker / security-tracker


Commits:
bd1be042 by Bastien Roucariès at 2026-08-05T10:12:26+02:00
pglogical triagging

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -5841,16 +5841,22 @@ CVE-2026-50738 (A use-after-free condition exists in pglogical's worker signalin
 	NOTE: Fixed by: https://github.com/2ndQuadrant/pglogical/commit/ed330e94cbceb51681eee7516708e142458eb005 (REL2_4_8)
 CVE-2026-50737 (When applying replicated changes for a row that is missing one or more ...)
 	- pglogical 2.4.8-1
+	[bookworm] - pglogical <postponed> (minor issue; need privilegied user)
+	[bullseye] - pglogical <postponed> (minor issue; need privilegied user)
 	NOTE: https://github.com/2ndQuadrant/pglogical/releases/tag/REL2_4_8
 	NOTE: https://www.enterprisedb.com/docs/security/advisories/cve202650735/
 	NOTE: Fixed by: https://github.com/2ndQuadrant/pglogical/commit/62deadc86ce62c91cf988ce49373a98fafa77899 (REL2_4_8)
 CVE-2026-50736 (The pglogical queue mechanism, used to convey out-of-band commands suc ...)
 	- pglogical 2.4.8-1
+	[bookworm] - pglogical <postponed> (minor issue; need privilegied user)
+	[bullseye] - pglogical <postponed> (minor issue; need privilegied user)
 	NOTE: https://github.com/2ndQuadrant/pglogical/releases/tag/REL2_4_8
 	NOTE: https://www.enterprisedb.com/docs/security/advisories/cve202650735/
 	NOTE: Fixed by: https://github.com/2ndQuadrant/pglogical/commit/62deadc86ce62c91cf988ce49373a98fafa77899 (REL2_4_8)
 CVE-2026-50735 (pglogical's apply worker does not sufficiently validate the length of  ...)
 	- pglogical 2.4.8-1
+	[bookworm] - pglogical <postponed> (minor issue; need privilegied user)
+	[bullseye] - pglogical <postponed> (minor issue; need privilegied user)
 	NOTE: https://github.com/2ndQuadrant/pglogical/releases/tag/REL2_4_8
 	NOTE: https://www.enterprisedb.com/docs/security/advisories/cve202650735/
 	NOTE: Fixed by: https://github.com/2ndQuadrant/pglogical/commit/57bc728a6b4fb6c70dc50edd4f385374f88e1e87 (REL2_4_8)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bd1be042f852c30b73c45ee136eaca4c5c4fe409

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bd1be042f852c30b73c45ee136eaca4c5c4fe409
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260805/f9d8456c/attachment.htm>


More information about the debian-security-tracker-commits mailing list