[Git][security-tracker-team/security-tracker][master] Track fixed version for postgresql-18 issues via unstable upload

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Aug 14 05:30:01 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
8fa2feba by Salvatore Bonaccorso at 2026-08-14T06:29:09+02:00
Track fixed version for postgresql-18 issues via unstable upload

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -649,196 +649,196 @@ CVE-2026-13048 (Data::MuForm::Localizer versions through 0.05 for Perl execute P
 CVE-2026-13051 (Form::Processor::Field::HtmlArea versions from 0.06 through 1.162360 f ...)
 	NOT-FOR-US: Form::Processor Perl module
 CVE-2026-6464 (Untrusted data inclusion in PostgreSQL psql COPY may allow a server ad ...)
-	- postgresql-18 <unfixed>
+	- postgresql-18 18.6-1
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
 	- postgresql-13 <unfixed>
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-6464/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-6469 (Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE co ...)
-	- postgresql-18 <unfixed>
+	- postgresql-18 18.6-1
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
 	- postgresql-13 <unfixed>
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-6469/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-6470 (Missing authorization in PostgreSQL DDL commands allows an object crea ...)
-	- postgresql-18 <unfixed>
+	- postgresql-18 18.6-1
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
 	- postgresql-13 <unfixed>
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-6470/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-6471 (Missing authorization in PostgreSQL logical decoding allows a non-supe ...)
-	- postgresql-18 <unfixed>
+	- postgresql-18 18.6-1
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
 	- postgresql-13 <unfixed>
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-6471/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-14662 (Integer wraparound in PostgreSQL tsvector and tsquery data type functi ...)
-	- postgresql-18 <unfixed>
+	- postgresql-18 18.6-1
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
 	- postgresql-13 <unfixed>
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-14662/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-14663 (Cleartext storage in PostgreSQL pgcrypto disabled ciphers allows a use ...)
-	- postgresql-18 <unfixed>
+	- postgresql-18 18.6-1
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
 	- postgresql-13 <unfixed>
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-14663/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-14664 (Heap buffer overflow in PostgreSQL regexp allows the query author to e ...)
-	- postgresql-18 <unfixed>
+	- postgresql-18 18.6-1
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
 	- postgresql-13 <unfixed>
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-14664/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-14666 (Incomplete tracking in PostgreSQL of changes to role membership, role  ...)
-	- postgresql-18 <unfixed>
+	- postgresql-18 18.6-1
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
 	- postgresql-13 <unfixed>
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-14666/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-14668 (Type confusion regarding input of PostgreSQL ctid data type selectivit ...)
-	- postgresql-18 <unfixed>
+	- postgresql-18 18.6-1
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
 	- postgresql-13 <unfixed>
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-14668/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-14669 (Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the par ...)
-	- postgresql-18 <unfixed>
+	- postgresql-18 18.6-1
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
 	- postgresql-13 <unfixed>
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-14669/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-14670 (Heap buffer overflow in PostgreSQL plperl return of a tied hash allows ...)
-	- postgresql-18 <unfixed>
+	- postgresql-18 18.6-1
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
 	- postgresql-13 <unfixed>
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-14670/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-14671 (Type confusion in PostgreSQL module "refint" allows an object creator  ...)
-	- postgresql-18 <unfixed>
+	- postgresql-18 18.6-1
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
 	- postgresql-13 <unfixed>
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-14671/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-14672 (Observable response discrepancy in PostgreSQL SCRAM authentication all ...)
-	- postgresql-18 <unfixed>
+	- postgresql-18 18.6-1
 	- postgresql-17 <removed>
 	- postgresql-15 <not-affected> ((Vulnerable code not present)
 	- postgresql-13 <not-affected> ((Vulnerable code not present)
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-14672/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-14673 (Untrusted search path in PostgreSQL amcheck allows a grantee of amchec ...)
-	- postgresql-18 <unfixed>
+	- postgresql-18 18.6-1
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
 	- postgresql-13 <unfixed>
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-14673/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-14676 (Heap buffer overflow in PostgreSQL pg_stat_statements allows the query ...)
-	- postgresql-18 <unfixed>
+	- postgresql-18 18.6-1
 	- postgresql-17 <not-affected> (Vulnerable code not present)
 	- postgresql-15 <not-affected> (Vulnerable code not present)
 	- postgresql-13 <not-affected> (Vulnerable code not present)
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-14676/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-14677 (Integer wraparound in PostgreSQL 32-bit builds of pltcl and plperl all ...)
-	- postgresql-18 <unfixed>
+	- postgresql-18 18.6-1
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
 	- postgresql-13 <unfixed>
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-14677/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-14678 (Buffer over-read in PostgreSQL pg_trgm index picksplit function reads  ...)
-	- postgresql-18 <unfixed>
+	- postgresql-18 18.6-1
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
 	- postgresql-13 <unfixed>
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-14678/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-14679 (Stack buffer overflow in PostgreSQL argument name matching allows an o ...)
-	- postgresql-18 <unfixed>
+	- postgresql-18 18.6-1
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
 	- postgresql-13 <unfixed>
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-14679/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-14680 (Type confusion with PostgreSQL "internal" data type arguments allows a ...)
-	- postgresql-18 <unfixed>
+	- postgresql-18 18.6-1
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
 	- postgresql-13 <unfixed>
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-14680/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-14681 (Improper enforcement of message integrity in PostgreSQL GSSAPI support ...)
-	- postgresql-18 <unfixed>
+	- postgresql-18 18.6-1
 	- postgresql-17 <removed>
 	- postgresql-15 <not-affected> (Vulnerable code not present)
 	- postgresql-13 <not-affected> (Vulnerable code not present)
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-14681/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-15741 (SQL injection in PostgreSQL EXTRACT() deparse allows an object owner t ...)
-	- postgresql-18 <unfixed>
+	- postgresql-18 18.6-1
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
 	- postgresql-13 <unfixed>
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-15741/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-15742 (Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct ...)
-	- postgresql-18 <unfixed>
+	- postgresql-18 18.6-1
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
 	- postgresql-13 <unfixed>
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-15742/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-16238 (Type confusion in PostgreSQL pg_restore_attribute_stats() allows an ob ...)
-	- postgresql-18 <unfixed>
+	- postgresql-18 18.6-1
 	- postgresql-17 <not-affected> (Vulnerable code not present)
 	- postgresql-15 <not-affected> (Vulnerable code not present)
 	- postgresql-13 <not-affected> (Vulnerable code not present)
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-16238/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-16239 (Type confusion in PostgreSQL "portal"/cursor lifecycle allows a user t ...)
-	- postgresql-18 <unfixed>
+	- postgresql-18 18.6-1
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
 	- postgresql-13 <unfixed>
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-16239/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-16241 (Integer underflow in PostgreSQL ECPG allows a database server administ ...)
-	- postgresql-18 <unfixed>
+	- postgresql-18 18.6-1
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
 	- postgresql-13 <unfixed>
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-16241/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-18024 (Buffer over-read in PostgreSQL ascii() SQL function allows a user to d ...)
-	- postgresql-18 <unfixed>
+	- postgresql-18 18.6-1
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
 	- postgresql-13 <unfixed>
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-18024/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-18408 (Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious s ...)
-	- postgresql-18 <unfixed>
+	- postgresql-18 18.6-1
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
 	- postgresql-13 <unfixed>
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-18408/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
 CVE-2026-19385 (Heap buffer overflow in PostgreSQL pg_dump of long function transform  ...)
-	- postgresql-18 <unfixed>
+	- postgresql-18 18.6-1
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
 	- postgresql-13 <unfixed>



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8fa2feba9afd7381a65f86bb6aec66b253a4c44a

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8fa2feba9afd7381a65f86bb6aec66b253a4c44a
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260814/98bfd19f/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list