SUSE-SU-2026:3793-1: important: Security update for postgresql14

SLE-SECURITY-UPDATES null at suse.de
Tue Aug 25 17:37:53 UTC 2026


# Security update for postgresql14

Announcement ID: SUSE-SU-2026:3793-1  
Release Date: 2026-08-25T12:32:17Z  
Rating: important  
References:

  * bsc#1275001
  * bsc#1275002
  * bsc#1275042
  * bsc#1275043
  * bsc#1275044
  * bsc#1275046
  * bsc#1275047
  * bsc#1275048
  * bsc#1275049
  * bsc#1275050
  * bsc#1275051
  * bsc#1275053
  * bsc#1275054
  * bsc#1275056
  * bsc#1275057
  * bsc#1275058
  * bsc#1275059
  * bsc#1275061
  * bsc#1275063
  * bsc#1275064
  * bsc#1275065
  * bsc#1275066
  * bsc#1275067
  * bsc#1275068

  
Cross-References:

  * CVE-2026-14662
  * CVE-2026-14663
  * CVE-2026-14664
  * CVE-2026-14666
  * CVE-2026-14668
  * CVE-2026-14669
  * CVE-2026-14670
  * CVE-2026-14671
  * CVE-2026-14673
  * CVE-2026-14677
  * CVE-2026-14678
  * CVE-2026-14679
  * CVE-2026-14680
  * CVE-2026-15741
  * CVE-2026-15742
  * CVE-2026-16239
  * CVE-2026-16241
  * CVE-2026-18024
  * CVE-2026-18408
  * CVE-2026-19385
  * CVE-2026-6464
  * CVE-2026-6469
  * CVE-2026-6470
  * CVE-2026-6471

  
CVSS scores:

  * CVE-2026-14662 ( SUSE ):  8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-14662 ( NVD ):  8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-14663 ( SUSE ):  6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
  * CVE-2026-14663 ( NVD ):  6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
  * CVE-2026-14664 ( SUSE ):  8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-14664 ( NVD ):  8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-14666 ( SUSE ):  4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
  * CVE-2026-14666 ( NVD ):  4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
  * CVE-2026-14668 ( SUSE ):  8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
  * CVE-2026-14668 ( NVD ):  8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
  * CVE-2026-14669 ( SUSE ):  8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-14669 ( NVD ):  8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-14670 ( SUSE ):  8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-14670 ( NVD ):  8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-14671 ( SUSE ):  8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-14671 ( NVD ):  8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-14673 ( SUSE ):  3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
  * CVE-2026-14673 ( NVD ):  3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
  * CVE-2026-14677 ( SUSE ):  8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-14677 ( NVD ):  8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-14678 ( SUSE ):  4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
  * CVE-2026-14678 ( NVD ):  4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
  * CVE-2026-14679 ( SUSE ):  7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
  * CVE-2026-14679 ( NVD ):  8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
  * CVE-2026-14680 ( SUSE ):  8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-14680 ( NVD ):  8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-15741 ( SUSE ):  8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
  * CVE-2026-15741 ( NVD ):  8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
  * CVE-2026-15742 ( SUSE ):  8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-15742 ( NVD ):  8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-16239 ( SUSE ):  8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-16239 ( NVD ):  8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-16241 ( SUSE ):  3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L
  * CVE-2026-16241 ( NVD ):  3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L
  * CVE-2026-18024 ( SUSE ):  4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
  * CVE-2026-18024 ( NVD ):  4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
  * CVE-2026-18408 ( SUSE ):  6.5 CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
  * CVE-2026-18408 ( NVD ):  8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
  * CVE-2026-19385 ( SUSE ):  8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-19385 ( NVD ):  8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-6464 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
  * CVE-2026-6464 ( NVD ):  8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-6469 ( SUSE ):  3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L
  * CVE-2026-6469 ( NVD ):  3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L
  * CVE-2026-6470 ( SUSE ):  4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
  * CVE-2026-6470 ( NVD ):  4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
  * CVE-2026-6471 ( SUSE ):  7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-6471 ( NVD ):  7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

  
Affected Products:

  * SUSE Linux Enterprise High Performance Computing 12 SP5
  * SUSE Linux Enterprise Server 12 SP5
  * SUSE Linux Enterprise Server 12 SP5 LTSS
  * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security
  * SUSE Linux Enterprise Server for SAP Applications 12 SP5

  
  
An update that solves 24 vulnerabilities can now be installed.

## Description:

This update for postgresql14 fixes the following issues:

  * CVE-2026-6464: `psql` `COPY FROM STDIN` early failure processes data lines
    as `psql` commands (bsc#1275046).
  * CVE-2026-6469: `ALTER TABLE ALTER TYPE` resets extended statistics ownership
    (bsc#1275044).
  * CVE-2026-6470: failure to check type `USAGE` privilege (bsc#1275043).
  * CVE-2026-6471: logical decoding can `dlopen` arbitrary file (bsc#1275042).
  * CVE-2026-14662: `tsvector` and `tsquery` undersize allocations, via integer
    wraparound (bsc#1275001).
  * CVE-2026-14663: `pgcrypto`, for OpenSSL-disabled ciphers, silently encrypts
    to and decrypts from cleartext (bsc#1275002).
  * CVE-2026-14664: `regexp` heap buffer overflow executes arbitrary code
    (bsc#1275068).
  * CVE-2026-14666: row security caching disregards role modifications
    (bsc#1275067).
  * CVE-2026-14668: `ctid` type confusion in selectivity estimator discloses
    derivative of arbitrary read (bsc#1275066).
  * CVE-2026-14669: `to_char` heap buffer overflow executes arbitrary code
    (bsc#1275065).
  * CVE-2026-14670: `plperl` tied object heap buffer overflow executes arbitrary
    code (bsc#1275064).
  * CVE-2026-14671: `refint` plan cache type confusion executes arbitrary code
    (bsc#1275063).
  * CVE-2026-14673: `amcheck` does not clear untrusted search path
    (bsc#1275061).
  * CVE-2026-14677: 32-bit `pltcl` and `plperl` undersize allocations, via
    integer wraparound (bsc#1275059).
  * CVE-2026-14678: `pg_trgm` `picksplit` reads past end of buffer
    (bsc#1275058).
  * CVE-2026-14679: stack buffer overflow in argument match writes `0x0` and
    `0x1` to server memory (bsc#1275057).
  * CVE-2026-14680: type confusion via "internal" arguments (bsc#1275056).
  * CVE-2026-15741: expression deparse allows SQL injection via `EXTRACT`
    argument (bsc#1275054).
  * CVE-2026-15742: `fuzzystrmatch` writes effectively-arbitrary addresses, via
    integer wraparound (bsc#1275053).
  * CVE-2026-16239: type confusion in cursor `CLOSE + DECLARE` executes
    arbitrary code (bsc#1275051).
  * CVE-2026-16241: ECPG integer underflow can crash the client (bsc#1275050).
  * CVE-2026-18024: `ascii()` function reads past end of buffer (bsc#1275049).
  * CVE-2026-18408: `psql` `\unrestrict` lets superuser of `pg_dump` origin
    server execute arbitrary code in `psql` client (bsc#1275048).
  * CVE-2026-19385: `pg_dump` heap buffer overflow executes arbitrary code
    (bsc#1275047).

Changes for postgresql14:

  * Let `llvmjit-devel` require the `llc` and `clang` binaries to fix build of
    extensions on SLE-16 and newer.
  * Use LLVM 15 on SLE-15 up to SP5 and LLVM 17 on SP6 and SP7.
  * Update to version 14.24:
  * https://www.postgresql.org/docs/14/release-14-24.html
  *
    https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".  
Alternatively you can run the command listed for your product:

  * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security  
    zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3793=1

  * SUSE Linux Enterprise Server 12 SP5 LTSS  
    zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-3793=1

## Package List:

  * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64)
    * postgresql14-debugsource-14.24-3.75.1
    * postgresql14-plpython-debuginfo-14.24-3.75.1
    * postgresql14-plpython-14.24-3.75.1
    * postgresql14-server-14.24-3.75.1
    * postgresql14-devel-14.24-3.75.1
    * postgresql14-contrib-14.24-3.75.1
    * postgresql14-pltcl-debuginfo-14.24-3.75.1
    * postgresql14-debuginfo-14.24-3.75.1
    * postgresql14-plperl-14.24-3.75.1
    * postgresql14-devel-debuginfo-14.24-3.75.1
    * postgresql14-server-debuginfo-14.24-3.75.1
    * postgresql14-14.24-3.75.1
    * postgresql14-contrib-debuginfo-14.24-3.75.1
    * postgresql14-plperl-debuginfo-14.24-3.75.1
    * postgresql14-pltcl-14.24-3.75.1
  * SUSE Linux Enterprise Server 12 SP5 LTSS (noarch)
    * postgresql14-docs-14.24-3.75.1
  * SUSE Linux Enterprise Server 12 SP5 LTSS (ppc64le s390x x86_64)
    * postgresql14-server-devel-debuginfo-14.24-3.75.1
    * postgresql14-server-devel-14.24-3.75.1
  * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64)
    * postgresql14-debugsource-14.24-3.75.1
    * postgresql14-plpython-debuginfo-14.24-3.75.1
    * postgresql14-plpython-14.24-3.75.1
    * postgresql14-server-devel-debuginfo-14.24-3.75.1
    * postgresql14-server-devel-14.24-3.75.1
    * postgresql14-server-14.24-3.75.1
    * postgresql14-devel-14.24-3.75.1
    * postgresql14-contrib-14.24-3.75.1
    * postgresql14-pltcl-debuginfo-14.24-3.75.1
    * postgresql14-debuginfo-14.24-3.75.1
    * postgresql14-plperl-14.24-3.75.1
    * postgresql14-devel-debuginfo-14.24-3.75.1
    * postgresql14-server-debuginfo-14.24-3.75.1
    * postgresql14-14.24-3.75.1
    * postgresql14-contrib-debuginfo-14.24-3.75.1
    * postgresql14-plperl-debuginfo-14.24-3.75.1
    * postgresql14-pltcl-14.24-3.75.1
  * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch)
    * postgresql14-docs-14.24-3.75.1

## References:

  * https://www.suse.com/security/cve/CVE-2026-14662.html
  * https://www.suse.com/security/cve/CVE-2026-14663.html
  * https://www.suse.com/security/cve/CVE-2026-14664.html
  * https://www.suse.com/security/cve/CVE-2026-14666.html
  * https://www.suse.com/security/cve/CVE-2026-14668.html
  * https://www.suse.com/security/cve/CVE-2026-14669.html
  * https://www.suse.com/security/cve/CVE-2026-14670.html
  * https://www.suse.com/security/cve/CVE-2026-14671.html
  * https://www.suse.com/security/cve/CVE-2026-14673.html
  * https://www.suse.com/security/cve/CVE-2026-14677.html
  * https://www.suse.com/security/cve/CVE-2026-14678.html
  * https://www.suse.com/security/cve/CVE-2026-14679.html
  * https://www.suse.com/security/cve/CVE-2026-14680.html
  * https://www.suse.com/security/cve/CVE-2026-15741.html
  * https://www.suse.com/security/cve/CVE-2026-15742.html
  * https://www.suse.com/security/cve/CVE-2026-16239.html
  * https://www.suse.com/security/cve/CVE-2026-16241.html
  * https://www.suse.com/security/cve/CVE-2026-18024.html
  * https://www.suse.com/security/cve/CVE-2026-18408.html
  * https://www.suse.com/security/cve/CVE-2026-19385.html
  * https://www.suse.com/security/cve/CVE-2026-6464.html
  * https://www.suse.com/security/cve/CVE-2026-6469.html
  * https://www.suse.com/security/cve/CVE-2026-6470.html
  * https://www.suse.com/security/cve/CVE-2026-6471.html
  * https://bugzilla.suse.com/show_bug.cgi?id=1275001
  * https://bugzilla.suse.com/show_bug.cgi?id=1275002
  * https://bugzilla.suse.com/show_bug.cgi?id=1275042
  * https://bugzilla.suse.com/show_bug.cgi?id=1275043
  * https://bugzilla.suse.com/show_bug.cgi?id=1275044
  * https://bugzilla.suse.com/show_bug.cgi?id=1275046
  * https://bugzilla.suse.com/show_bug.cgi?id=1275047
  * https://bugzilla.suse.com/show_bug.cgi?id=1275048
  * https://bugzilla.suse.com/show_bug.cgi?id=1275049
  * https://bugzilla.suse.com/show_bug.cgi?id=1275050
  * https://bugzilla.suse.com/show_bug.cgi?id=1275051
  * https://bugzilla.suse.com/show_bug.cgi?id=1275053
  * https://bugzilla.suse.com/show_bug.cgi?id=1275054
  * https://bugzilla.suse.com/show_bug.cgi?id=1275056
  * https://bugzilla.suse.com/show_bug.cgi?id=1275057
  * https://bugzilla.suse.com/show_bug.cgi?id=1275058
  * https://bugzilla.suse.com/show_bug.cgi?id=1275059
  * https://bugzilla.suse.com/show_bug.cgi?id=1275061
  * https://bugzilla.suse.com/show_bug.cgi?id=1275063
  * https://bugzilla.suse.com/show_bug.cgi?id=1275064
  * https://bugzilla.suse.com/show_bug.cgi?id=1275065
  * https://bugzilla.suse.com/show_bug.cgi?id=1275066
  * https://bugzilla.suse.com/show_bug.cgi?id=1275067
  * https://bugzilla.suse.com/show_bug.cgi?id=1275068

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.suse.com/pipermail/sle-security-updates/attachments/20260825/7f30aa73/attachment-0001.htm>


More information about the sle-security-updates mailing list