SUSE-CU-2026:9534-1: Security update of suse/postgres
sle-container-updates at lists.suse.com
sle-container-updates at lists.suse.com
Sun Sep 6 07:43:52 UTC 2026
SUSE Container Update Advisory: suse/postgres
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:9534-1
Container Tags : suse/postgres:16-contrib , suse/postgres:16.15 , suse/postgres:16.15-contrib , suse/postgres:16.15-contrib-93.21
Container Release : 93.21
Severity : important
Type : security
References : 1275001 1275002 1275042 1275043 1275044 1275046 1275047 1275048
1275049 1275050 1275051 1275053 1275054 1275056 1275057 1275058
1275059 1275061 1275062 1275063 1275064 1275065 1275066 1275067
1275068 CVE-2026-14662 CVE-2026-14663 CVE-2026-14664 CVE-2026-14666
CVE-2026-14668 CVE-2026-14669 CVE-2026-14670 CVE-2026-14671 CVE-2026-14672
CVE-2026-14673 CVE-2026-14677 CVE-2026-14678 CVE-2026-14679 CVE-2026-14680
CVE-2026-15741 CVE-2026-15742 CVE-2026-16239 CVE-2026-16241 CVE-2026-18024
CVE-2026-18408 CVE-2026-19385 CVE-2026-6464 CVE-2026-6469 CVE-2026-6470
CVE-2026-6471
-----------------------------------------------------------------
The container suse/postgres was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3963-1
Released: Thu Sep 3 15:33:32 2026
Summary: Security update for postgresql16
Type: security
Severity: important
References: 1275001,1275002,1275042,1275043,1275044,1275046,1275047,1275048,1275049,1275050,1275051,1275053,1275054,1275056,1275057,1275058,1275059,1275061,1275062,1275063,1275064,1275065,1275066,1275067,1275068,CVE-2026-14662,CVE-2026-14663,CVE-2026-14664,CVE-2026-14666,CVE-2026-14668,CVE-2026-14669,CVE-2026-14670,CVE-2026-14671,CVE-2026-14672,CVE-2026-14673,CVE-2026-14677,CVE-2026-14678,CVE-2026-14679,CVE-2026-14680,CVE-2026-15741,CVE-2026-15742,CVE-2026-16239,CVE-2026-16241,CVE-2026-18024,CVE-2026-18408,CVE-2026-19385,CVE-2026-6464,CVE-2026-6469,CVE-2026-6470,CVE-2026-6471
This update for postgresql16 fixes the following issues:
- CVE-2026-6464: `psql` `COPY FROM STDIN` early failure processes data lines as `psql` commands (bsc#1275046).
- CVE-2026-6469: `ALTER TABLE ALTER TYPE` resets extended statistics ownership (bsc#1275044).
- CVE-2026-6470: failure to check type `USAGE` privilege (bsc#1275043).
- CVE-2026-6471: logical decoding can `dlopen` arbitrary file (bsc#1275042).
- CVE-2026-14662: `tsvector` and `tsquery` undersize allocations, via integer wraparound (bsc#1275001).
- CVE-2026-14663: `pgcrypto`, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext
(bsc#1275002).
- CVE-2026-14664: `regexp` heap buffer overflow executes arbitrary code (bsc#1275068).
- CVE-2026-14666: row security caching disregards role modifications (bsc#1275067).
- CVE-2026-14668: `ctid` type confusion in selectivity estimator discloses derivative of arbitrary read
(bsc#1275066).
- CVE-2026-14669: `to_char` heap buffer overflow executes arbitrary code (bsc#1275065).
- CVE-2026-14670: `plperl` tied object heap buffer overflow executes arbitrary code (bsc#1275064).
- CVE-2026-14671: `refint` plan cache type confusion executes arbitrary code (bsc#1275063).
- CVE-2026-14672: observable response discrepancy with non-default `scram_iterations` provides user existence
oracle (bsc#1275062).
- CVE-2026-14673: `amcheck` does not clear untrusted search path (bsc#1275061).
- CVE-2026-14677: 32-bit `pltcl` and `plperl` undersize allocations, via integer wraparound (bsc#1275059).
- CVE-2026-14678: `pg_trgm` `picksplit` reads past end of buffer (bsc#1275058).
- CVE-2026-14679: stack buffer overflow in argument match writes `0x0` and `0x1` to server memory (bsc#1275057).
- CVE-2026-14680: type confusion via 'internal' arguments (bsc#1275056).
- CVE-2026-15741: expression deparse allows SQL injection via `EXTRACT` argument (bsc#1275054).
- CVE-2026-15742: `fuzzystrmatch` writes effectively-arbitrary addresses, via integer wraparound (bsc#1275053).
- CVE-2026-16239: type confusion in cursor `CLOSE + DECLARE` executes arbitrary code (bsc#1275051).
- CVE-2026-16241: ECPG integer underflow can crash the client (bsc#1275050).
- CVE-2026-18024: `ascii()` function reads past end of buffer (bsc#1275049).
- CVE-2026-18408: `psql` `\unrestrict` lets superuser of `pg_dump` origin server execute arbitrary code in `psql`
client (bsc#1275048).
- CVE-2026-19385: `pg_dump` heap buffer overflow executes arbitrary code (bsc#1275047).
Changes for postgresql16:
- Update to version 16.15:
* https://www.postgresql.org/docs/16/release-16-15.html
* https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
The following package changes have been done:
- postgresql16-16.15-150600.16.38.1 updated
- postgresql16-server-16.15-150600.16.38.1 updated
- postgresql16-contrib-16.15-150600.16.38.1 updated
- container:suse-sle15-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated
More information about the sle-container-updates
mailing list