SUSE-CU-2026:10130-1: Security update of suse/postgres

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Sat Sep 12 08:34:15 UTC 2026


SUSE Container Update Advisory: suse/postgres
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:10130-1
Container Tags        : suse/postgres:17 , suse/postgres:17.11 , suse/postgres:17.11 , suse/postgres:17.11-83.24
Container Release     : 83.24
Severity              : important
Type                  : security
References            : 1266343 1266786 1269489 1274740 1274774 1274777 1274788 1274790
                        1274791 1274792 1274795 1274796 1274797 1274798 1275001 1275001
                        1275002 1275002 1275042 1275042 1275043 1275043 1275044 1275044
                        1275046 1275046 1275047 1275047 1275048 1275048 1275049 1275049
                        1275050 1275050 1275051 1275051 1275052 1275053 1275053 1275054
                        1275054 1275055 1275055 1275056 1275056 1275057 1275057 1275058
                        1275058 1275059 1275059 1275060 1275061 1275062 1275062 1275063
                        1275063 1275064 1275064 1275065 1275065 1275066 1275066 1275067
                        1275067 1275068 1275068 1275837 1277476 1277479 1277480 CVE-2026-13608
                        CVE-2026-14456 CVE-2026-14457 CVE-2026-14662 CVE-2026-14662 CVE-2026-14663
                        CVE-2026-14663 CVE-2026-14664 CVE-2026-14664 CVE-2026-14666 CVE-2026-14666
                        CVE-2026-14668 CVE-2026-14668 CVE-2026-14669 CVE-2026-14669 CVE-2026-14670
                        CVE-2026-14670 CVE-2026-14671 CVE-2026-14671 CVE-2026-14672 CVE-2026-14672
                        CVE-2026-14673 CVE-2026-14676 CVE-2026-14677 CVE-2026-14677 CVE-2026-14678
                        CVE-2026-14678 CVE-2026-14679 CVE-2026-14679 CVE-2026-14680 CVE-2026-14680
                        CVE-2026-14681 CVE-2026-14681 CVE-2026-15741 CVE-2026-15741 CVE-2026-15742
                        CVE-2026-15742 CVE-2026-16238 CVE-2026-16239 CVE-2026-16239 CVE-2026-16241
                        CVE-2026-16241 CVE-2026-18024 CVE-2026-18024 CVE-2026-18408 CVE-2026-18408
                        CVE-2026-18798 CVE-2026-19385 CVE-2026-19385 CVE-2026-34181 CVE-2026-42250
                        CVE-2026-54874 CVE-2026-58055 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074
                        CVE-2026-63075 CVE-2026-63076 CVE-2026-6464 CVE-2026-6464 CVE-2026-6469
                        CVE-2026-6469 CVE-2026-6470 CVE-2026-6470 CVE-2026-6471 CVE-2026-6471
                        CVE-2026-75803 CVE-2026-80229 CVE-2026-80230 
-----------------------------------------------------------------

The container suse/postgres was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3980-1
Released:    Sun Sep  6 09:44:23 2026
Summary:     Recommended update for libtirpc
Type:        recommended
Severity:    important
References:  1274740
This update for libtirpc fixes the following issues:

- Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740):
    * rpcb_clnt.c: fix memory leak in destroy_addr

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:4014-1
Released:    Mon Sep  7 09:36:08 2026
Summary:     Security update for postgresql18
Type:        security
Severity:    important
References:  1275001,1275002,1275042,1275043,1275044,1275046,1275047,1275048,1275049,1275050,1275051,1275052,1275053,1275054,1275055,1275056,1275057,1275058,1275059,1275060,1275061,1275062,1275063,1275064,1275065,1275066,1275067,1275068,CVE-2026-14662,CVE-2026-14663,CVE-2026-14664,CVE-2026-14666,CVE-2026-14668,CVE-2026-14669,CVE-2026-14670,CVE-2026-14671,CVE-2026-14672,CVE-2026-14673,CVE-2026-14676,CVE-2026-14677,CVE-2026-14678,CVE-2026-14679,CVE-2026-14680,CVE-2026-14681,CVE-2026-15741,CVE-2026-15742,CVE-2026-16238,CVE-2026-16239,CVE-2026-16241,CVE-2026-18024,CVE-2026-18408,CVE-2026-19385,CVE-2026-6464,CVE-2026-6469,CVE-2026-6470,CVE-2026-6471
This update for postgresql18 fixes the following issues:

- CVE-2026-6464: `psql` `COPY FROM STDIN` early failure processes data lines as `psql` commands (bsc#1275046).
- CVE-2026-6469: `ALTER TABLE ALTER TYPE` resets extended statistics ownership (bsc#1275044).
- CVE-2026-6470: failure to check type `USAGE` privilege (bsc#1275043).
- CVE-2026-6471: logical decoding can `dlopen` arbitrary file (bsc#1275042).
- CVE-2026-14662: `tsvector` and `tsquery` undersize allocations, via integer wraparound (bsc#1275001).
- CVE-2026-14663: `pgcrypto`, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext
  (bsc#1275002).
- CVE-2026-14664: `regexp` heap buffer overflow executes arbitrary code (bsc#1275068).
- CVE-2026-14666: row security caching disregards role modifications (bsc#1275067).
- CVE-2026-14668: `ctid` type confusion in selectivity estimator discloses derivative of arbitrary read
  (bsc#1275066).
- CVE-2026-14669: `to_char` heap buffer overflow executes arbitrary code (bsc#1275065).
- CVE-2026-14670: `plperl` tied object heap buffer overflow executes arbitrary code (bsc#1275064).
- CVE-2026-14671: `refint` plan cache type confusion executes arbitrary code (bsc#1275063).
- CVE-2026-14672:  observable response discrepancy with non-default `scram_iterations` provides user existence
  oracle (bsc#1275062).
- CVE-2026-14673: `amcheck` does not clear untrusted search path (bsc#1275061).
- CVE-2026-14676: `pg_stat_statements` heap buffer overflow executes arbitrary code (bsc#1275060).
- CVE-2026-14677: 32-bit `pltcl` and `plperl` undersize allocations, via integer wraparound (bsc#1275059).
- CVE-2026-14678: `pg_trgm` `picksplit` reads past end of buffer (bsc#1275058).
- CVE-2026-14679: stack buffer overflow in argument match writes `0x0` and `0x1` to server memory (bsc#1275057).
- CVE-2026-14680: type confusion via 'internal' arguments (bsc#1275056).
- CVE-2026-14681: improper enforcement of GSSAPI encryption when coupled with SSL (bsc#1275055).
- CVE-2026-15741: expression deparse allows SQL injection via `EXTRACT` argument (bsc#1275054).
- CVE-2026-15742: `fuzzystrmatch` writes effectively-arbitrary addresses, via integer wraparound (bsc#1275053).
- CVE-2026-16238: type confusion in `pg_restore_attribute_stats()` executes arbitrary code (bsc#1275052).
- CVE-2026-16239: type confusion in cursor `CLOSE + DECLARE` executes arbitrary code (bsc#1275051).
- CVE-2026-16241: ECPG integer underflow can crash the client (bsc#1275050).
- CVE-2026-18024: `ascii()` function reads past end of buffer (bsc#1275049).
- CVE-2026-18408: `psql` `\unrestrict` lets superuser of `pg_dump` origin server execute arbitrary code in `psql`
  client (bsc#1275048).
- CVE-2026-19385: `pg_dump` heap buffer overflow executes arbitrary code (bsc#1275047).

Changes for postgresql18:

- Update to version 18.6:
  * https://www.postgresql.org/docs/18/release-18-6.html
  * https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:4016-1
Released:    Mon Sep  7 09:37:47 2026
Summary:     Security update for postgresql17
Type:        security
Severity:    important
References:  1275001,1275002,1275042,1275043,1275044,1275046,1275047,1275048,1275049,1275050,1275051,1275053,1275054,1275055,1275056,1275057,1275058,1275059,1275062,1275063,1275064,1275065,1275066,1275067,1275068,CVE-2026-14662,CVE-2026-14663,CVE-2026-14664,CVE-2026-14666,CVE-2026-14668,CVE-2026-14669,CVE-2026-14670,CVE-2026-14671,CVE-2026-14672,CVE-2026-14677,CVE-2026-14678,CVE-2026-14679,CVE-2026-14680,CVE-2026-14681,CVE-2026-15741,CVE-2026-15742,CVE-2026-16239,CVE-2026-16241,CVE-2026-18024,CVE-2026-18408,CVE-2026-19385,CVE-2026-6464,CVE-2026-6469,CVE-2026-6470,CVE-2026-6471
This update for postgresql17 fixes the following issues:

- CVE-2026-6464: `psql` `COPY FROM STDIN` early failure processes data lines as `psql` commands (bsc#1275046).
- CVE-2026-6469: `ALTER TABLE ALTER TYPE` resets extended statistics ownership (bsc#1275044).
- CVE-2026-6470: failure to check type `USAGE` privilege (bsc#1275043).
- CVE-2026-6471: logical decoding can `dlopen` arbitrary file (bsc#1275042).
- CVE-2026-14662: `tsvector` and `tsquery` undersize allocations, via integer wraparound (bsc#1275001).
- CVE-2026-14663: `pgcrypto`, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext
  (bsc#1275002).
- CVE-2026-14664: `regexp` heap buffer overflow executes arbitrary code (bsc#1275068).
- CVE-2026-14666: row security caching disregards role modifications (bsc#1275067).
- CVE-2026-14668: `ctid` type confusion in selectivity estimator discloses derivative of arbitrary read
  (bsc#1275066).
- CVE-2026-14669: `to_char` heap buffer overflow executes arbitrary code (bsc#1275065).
- CVE-2026-14670: `plperl` tied object heap buffer overflow executes arbitrary code (bsc#1275064).
- CVE-2026-14671: `refint` plan cache type confusion executes arbitrary code (bsc#1275063).
- CVE-2026-14672:  observable response discrepancy with non-default `scram_iterations` provides user existence
  oracle (bsc#1275062).
- CVE-2026-14677: 32-bit `pltcl` and `plperl` undersize allocations, via integer wraparound (bsc#1275059).
- CVE-2026-14678: `pg_trgm` `picksplit` reads past end of buffer (bsc#1275058).
- CVE-2026-14679: stack buffer overflow in argument match writes `0x0` and `0x1` to server memory (bsc#1275057).
- CVE-2026-14680: type confusion via 'internal' arguments (bsc#1275056).
- CVE-2026-14681: improper enforcement of GSSAPI encryption when coupled with SSL (bsc#1275055).
- CVE-2026-15741: expression deparse allows SQL injection via `EXTRACT` argument (bsc#1275054).
- CVE-2026-15742: `fuzzystrmatch` writes effectively-arbitrary addresses, via integer wraparound (bsc#1275053).
- CVE-2026-16239: type confusion in cursor `CLOSE + DECLARE` executes arbitrary code (bsc#1275051).
- CVE-2026-16241: ECPG integer underflow can crash the client (bsc#1275050).
- CVE-2026-18024: `ascii()` function reads past end of buffer (bsc#1275049).
- CVE-2026-18408: `psql` `\unrestrict` lets superuser of `pg_dump` origin server execute arbitrary code in `psql`
  client (bsc#1275048).
- CVE-2026-19385: `pg_dump` heap buffer overflow executes arbitrary code (bsc#1275047).

Changes for postgresql17:

- Update to version 17.11:
  * https://www.postgresql.org/docs/17/release-17-11.html
  * https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:4029-1
Released:    Mon Sep  7 09:45:31 2026
Summary:     Security update for nghttp2
Type:        security
Severity:    moderate
References:  1269489,CVE-2026-58055
This update for nghttp2 fixes the following issue:

- CVE-2026-58055: HTTP/1.1 Upgrade request can lead to HTTP request smuggling and cross-client response-queue poisoning
  (bsc#1269489).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:4039-1
Released:    Mon Sep  7 10:29:11 2026
Summary:     Security update for openssl-3
Type:        security
Severity:    important
References:  1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803
This update for openssl-3 fixes the following issues:

August 2026 release.
  
- CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791).
- CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792).
- CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777).
- CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343).
- CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795).
- CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788).
- CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796).
- CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797).
- CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798).
- CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790).
- CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:4048-1
Released:    Mon Sep  7 15:54:05 2026
Summary:     Security update for curl
Type:        security
Severity:    low
References:  1277476,1277479,1277480,CVE-2026-13608,CVE-2026-80229,CVE-2026-80230
This update for curl fixes the following issues:

- CVE-2026-13608: flow in OpenLDAP SASL negotiation can cause an authentication bypass (bsc#1277476).
- CVE-2026-80229: premature free can lead to OpenSSL provider use-after-free (bsc#1277479).
- CVE-2026-80230: OpenSSL pinning bypass can allow unauthenticated connections to succeed (bsc#1277480).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:4055-1
Released:    Mon Sep  7 17:48:12 2026
Summary:     Security update for bzip2
Type:        security
Severity:    low
References:  1266786,CVE-2026-42250
This update for bzip2 fixes the following issue:

- CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a
  crash (bsc#1266786).


The following package changes have been done:

- libbz2-1-1.0.8-150400.3.4.1 updated
- libnghttp2-14-1.64.0-150700.3.6.1 updated
- libtirpc-netconfig-1.3.4-150300.3.26.1 updated
- libopenssl3-3.5.0-150700.5.50.1 updated
- libtirpc3-1.3.4-150300.3.26.1 updated
- libcurl4-8.14.1-150700.7.26.1 updated
- libpq5-18.6-150600.13.16.1 updated
- postgresql17-17.11-150600.13.32.1 updated
- postgresql17-server-17.11-150600.13.32.1 updated
- container:suse-sle15-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated
- bash-4.4-150400.27.6.1 removed
- bash-sh-4.4-150400.27.6.1 removed
- filesystem-15.0-11.8.1 removed
- glibc-2.38-150600.14.52.1 removed
- libacl1-2.2.52-4.3.1 removed
- libattr1-2.4.47-2.19 removed
- libcap2-2.63-150400.3.6.1 removed
- libgcc_s1-15.3.0+git11272-150000.1.12.1 removed
- libgmp10-6.1.2-4.9.1 removed
- libncurses6-6.1-150000.5.33.1 removed
- libpcre2-8-0-10.42-150600.1.26 removed
- libreadline7-7.0-150400.27.6.1 removed
- libselinux1-3.5-150600.3.3.1 removed
- libstdc++6-15.3.0+git11272-150000.1.12.1 removed
- system-user-root-20190513-3.3.1 removed
- terminfo-base-6.1-150000.5.33.1 removed


More information about the sle-container-updates mailing list