[CLSA-2026:1789730254] Fix CVE(s): CVE-2026-14673, CVE-2026-19385
Type:
security
Severity:
Critical
Release date:
2026-09-18 11:17:45 UTC
Description:
* SECURITY UPDATE: Heap buffer overflow in pg_dump of long transform lists - debian/patches/CVE-2026-19385.patch: make parseOidArray() allocate the OID array itself and verify the element count, add parseIntArray() for the potentially-signed callers, and drop dumpFunc()'s fixed FUNC_MAX_ARGS allocation for pg_proc.protrftypes, so a crafted transform list can no longer overrun the array or run the caller loop off its end - CVE-2026-19385 * SECURITY UPDATE: Untrusted search path in amcheck - debian/patches/CVE-2026-14673.patch: set search_path to "pg_catalog, pg_temp" inside the security-restricted context that bt_index_check_internal() establishes, so index expressions and predicates run by amcheck cannot resolve to attacker-supplied functions placed on the caller's search_path - CVE-2026-14673
Updated packages:
  • libecpg-compat3-13_13.23-1~bookworm+tuxcare.els14_amd64.deb
    sha:d5e855426ce43a7e3436b83bfd7a197b5b6deb55
  • libecpg-dev-13_13.23-1~bookworm+tuxcare.els14_amd64.deb
    sha:6a02d0b85f35d5c4b5471ec48ec8352bcbc9b1aa
  • libecpg6-13_13.23-1~bookworm+tuxcare.els14_amd64.deb
    sha:d3ea54f7058a6779dec7ad1203d7e6fef7df3198
  • libpgtypes3-13_13.23-1~bookworm+tuxcare.els14_amd64.deb
    sha:c1ca1b027d4ac1fccb06e5eaaaec752ca33ca5d0
  • libpq-dev-13_13.23-1~bookworm+tuxcare.els14_amd64.deb
    sha:8f50087aa9cb5318e75a20eba9c4edb7c0205290
  • libpq5-13_13.23-1~bookworm+tuxcare.els14_amd64.deb
    sha:8faed90fcae593f178f34e9747d85368b92c9150
  • postgresql13_13.23-1~bookworm+tuxcare.els14_amd64.deb
    sha:246a88208913b915622598a89d0952a050241a59
  • postgresql13-client_13.23-1~bookworm+tuxcare.els14_amd64.deb
    sha:e2051b68062f011b945806cc6b26a35df4417fa1
  • postgresql13-doc_13.23-1~bookworm+tuxcare.els14_all.deb
    sha:317aaf79fbadc6baa8f8608c0199e48d8e8d8672
  • postgresql13-plperl_13.23-1~bookworm+tuxcare.els14_amd64.deb
    sha:b4756af54feff33cdcdbee1322f45badcc450ab3
  • postgresql13-plpython3_13.23-1~bookworm+tuxcare.els14_amd64.deb
    sha:cb1ca2c4f9a3ea31e3c4f7dc15a92226431bb2d3
  • postgresql13-pltcl_13.23-1~bookworm+tuxcare.els14_amd64.deb
    sha:dcfabe0b58aa11677c311e46440ab47bfd33b5ad
  • postgresql13-server-dev_13.23-1~bookworm+tuxcare.els14_amd64.deb
    sha:47765bb57c9182e25a5c53d079656ad10789358c
  • libecpg-compat3-13_13.23-1~bookworm+tuxcare.els14_arm64.deb
    sha:3bcec7216833b0e59e638eedced98460ea333d8a
  • libecpg-dev-13_13.23-1~bookworm+tuxcare.els14_arm64.deb
    sha:741361b83f0c674581431bfbc7d6ea1fe877ba53
  • libecpg6-13_13.23-1~bookworm+tuxcare.els14_arm64.deb
    sha:0e31697f6c56c60e8290e1358ca4d4312bed93ac
  • libpgtypes3-13_13.23-1~bookworm+tuxcare.els14_arm64.deb
    sha:99522335d62ff7c392787a5451ba5625c982ce10
  • libpq-dev-13_13.23-1~bookworm+tuxcare.els14_arm64.deb
    sha:14eade8bd8dd5022437ab23e3e7f95aef8913c02
  • libpq5-13_13.23-1~bookworm+tuxcare.els14_arm64.deb
    sha:de02491d23937e217bc64611716cf05d9a779734
  • postgresql13_13.23-1~bookworm+tuxcare.els14_arm64.deb
    sha:760e9111582b36131780545c8673e2c3a4d776da
  • postgresql13-client_13.23-1~bookworm+tuxcare.els14_arm64.deb
    sha:0de3245b78c8961fd797b129e238a8e73e6184aa
  • postgresql13-plperl_13.23-1~bookworm+tuxcare.els14_arm64.deb
    sha:d5e7ab375852ba264ebadfa3c49f31660421094e
  • postgresql13-plpython3_13.23-1~bookworm+tuxcare.els14_arm64.deb
    sha:fb5ccf366777c52dfef65f6e0dc3b52b5bbc415e
  • postgresql13-pltcl_13.23-1~bookworm+tuxcare.els14_arm64.deb
    sha:7b652600749d05cfc372749f3ce3a772db32ca22
  • postgresql13-server-dev_13.23-1~bookworm+tuxcare.els14_arm64.deb
    sha:70cae6f1ff209c467df9625db52cf61ef22994f5
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.