[Git][security-tracker-team/security-tracker][master] Correct my mistake about pglogical CVE triage

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Jul 29 05:44:40 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
aabf67a2 by Salvatore Bonaccorso at 2026-07-29T06:44:17+02:00
Correct my mistake about pglogical CVE triage

The product is actually packages (src:pglogical) and the new upstream
version REL_2_4_8 addresses the issues, though no further details are
linked as the advisory at time of commit gives a 404.

Link: https://github.com/2ndQuadrant/pglogical/releases/tag/REL2_4_8
Link: https://www.enterprisedb.com/docs/security/advisories/cve202650735/

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -195,13 +195,25 @@ CVE-2026-51252 (schreibfaul1 ESP32-audioI2S 3.4.5 has a buffer overflow vulnerab
 CVE-2026-51251 (Schreibfaul1 ESP32-audioI2S 3.4.5 has a buffer overflow vulnerability  ...)
 	NOT-FOR-US: schreibfaul1 ESP32-audioI2S
 CVE-2026-50738 (A use-after-free condition exists in pglogical's worker signaling code ...)
-	NOT-FOR-US: EnterpriseDB pglogical
+	- pglogical 2.4.8-1
+	NOTE: https://github.com/2ndQuadrant/pglogical/releases/tag/REL2_4_8
+	NOTE: https://www.enterprisedb.com/docs/security/advisories/cve202650735/
+	NOTE: Fixed by: https://github.com/2ndQuadrant/pglogical/commit/ed330e94cbceb51681eee7516708e142458eb005 (REL2_4_8)
 CVE-2026-50737 (When applying replicated changes for a row that is missing one or more ...)
-	NOT-FOR-US: EnterpriseDB
+	- pglogical 2.4.8-1
+	NOTE: https://github.com/2ndQuadrant/pglogical/releases/tag/REL2_4_8
+	NOTE: https://www.enterprisedb.com/docs/security/advisories/cve202650735/
+	NOTE: Fixed by: https://github.com/2ndQuadrant/pglogical/commit/62deadc86ce62c91cf988ce49373a98fafa77899 (REL2_4_8)
 CVE-2026-50736 (The pglogical queue mechanism, used to convey out-of-band commands suc ...)
-	NOT-FOR-US: EnterpriseDB
+	- pglogical 2.4.8-1
+	NOTE: https://github.com/2ndQuadrant/pglogical/releases/tag/REL2_4_8
+	NOTE: https://www.enterprisedb.com/docs/security/advisories/cve202650735/
+	NOTE: Fixed by: https://github.com/2ndQuadrant/pglogical/commit/62deadc86ce62c91cf988ce49373a98fafa77899 (REL2_4_8)
 CVE-2026-50735 (pglogical's apply worker does not sufficiently validate the length of  ...)
-	NOT-FOR-US: EnterpriseDB
+	- pglogical 2.4.8-1
+	NOTE: https://github.com/2ndQuadrant/pglogical/releases/tag/REL2_4_8
+	NOTE: https://www.enterprisedb.com/docs/security/advisories/cve202650735/
+	NOTE: Fixed by: https://github.com/2ndQuadrant/pglogical/commit/57bc728a6b4fb6c70dc50edd4f385374f88e1e87 (REL2_4_8)
 CVE-2026-4932 (IBM PowerVM Hypervisor FW1110.00 through FW1110.20, and FW1060.00 thro ...)
 	NOT-FOR-US: IBM
 CVE-2026-4912 (The Media Cleaner: Clean your WordPress! plugin for WordPress is vulne ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/aabf67a266d80ba748d427cef983c34086652fd8

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/aabf67a266d80ba748d427cef983c34086652fd8
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260729/1ccd4111/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list