{"cves":[{"id":"CVE-2026-6479","published":"2026-05-14T14:16:00","updated_at":"2026-05-22T18:08:29.942822+00:00","description":"\nUncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an\nattacker able to connect to a PostgreSQL AF_UNIX socket to achieve\nsustained denial of service. If SSL and GSS are both disabled, an attacker\ncan do the same via access to a PostgreSQL TCP socket. Versions before\nPostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.","ubuntu_description":"","notes":[{"author":"leosilva","note":"PostgreSQL 9.3 is end of life upstream, and no updates are\nare available. Marking as deferred in -esm-main releases."}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-6479","https://www.postgresql.org/about/news/postgresql-184-1710-1614-1518-and-1423-released-3297/","https://www.postgresql.org/support/security/CVE-2026-6479/","https://ubuntu.com/security/notices/USN-8294-1"],"bugs":[""],"patches":{"postgresql-18":[],"postgresql-17":[],"postgresql-16":[],"postgresql-14":[],"postgresql-12":[],"postgresql-10":[],"postgresql-9.5":[],"postgresql-9.3":[]},"tags":{},"packages":[{"name":"postgresql-10","source":"https://ubuntu.com/security/cve?package=postgresql-10","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-10","debian":"https://tracker.debian.org/pkg/postgresql-10","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"postgresql-12","source":"https://ubuntu.com/security/cve?package=postgresql-12","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-12","debian":"https://tracker.debian.org/pkg/postgresql-12","statuses":[{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"postgresql-14","source":"https://ubuntu.com/security/cve?package=postgresql-14","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-14","debian":"https://tracker.debian.org/pkg/postgresql-14","statuses":[{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"14.23-0ubuntu0.22.04.1","component":null,"pocket":"security"}]},{"name":"postgresql-16","source":"https://ubuntu.com/security/cve?package=postgresql-16","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-16","debian":"https://tracker.debian.org/pkg/postgresql-16","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"16.14-0ubuntu0.24.04.1","component":null,"pocket":"security"}]},{"name":"postgresql-17","source":"https://ubuntu.com/security/cve?package=postgresql-17","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-17","debian":"https://tracker.debian.org/pkg/postgresql-17","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"17.10-0ubuntu0.25.10.1","component":null,"pocket":"security"}]},{"name":"postgresql-18","source":"https://ubuntu.com/security/cve?package=postgresql-18","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-18","debian":"https://tracker.debian.org/pkg/postgresql-18","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"18.4-0ubuntu0.26.04.1","component":null,"pocket":"security"}]},{"name":"postgresql-9.3","source":"https://ubuntu.com/security/cve?package=postgresql-9.3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-9.3","debian":"https://tracker.debian.org/pkg/postgresql-9.3","statuses":[{"release_codename":"trusty","status":"deferred","description":"2019-08-23","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"postgresql-9.5","source":"https://ubuntu.com/security/cve?package=postgresql-9.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-9.5","debian":"https://tracker.debian.org/pkg/postgresql-9.5","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":["USN-8294-1"],"notices":[{"id":"USN-8294-1","title":"PostgreSQL vulnerabilities","summary":"Several security issues were fixed in PostgreSQL.","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart PostgreSQL to\nmake all the necessary changes.","references":[],"published":"2026-05-21T20:39:48.706022","description":"It was discovered that PostgreSQL did not correctly enforce authorization\nfor CREATE TYPE. An attacker could possibly use this issue to execute\narbitrary SQL functions. (CVE-2026-6472)\n\nIt was discovered that PostgreSQL incorrectly handled large user input in\nmultiple server features. An attacker could possibly use this issue to\ncause PostgreSQL to crash, resulting in a denial of service, or execute\narbitrary code. (CVE-2026-6473)\n\nIt was discovered that PostgreSQL incorrectly handled format strings in\nthe timeofday() function. An attacker could possibly use this issue to\nobtain sensitive information. (CVE-2026-6474)\n\nIt was discovered that PostgreSQL incorrectly followed symbolic links in\npg_basebackup and pg_rewind. An attacker could possibly use this issue to\noverwrite local files and execute arbitrary code. (CVE-2026-6475)\n\nIt was discovered that PostgreSQL had an SQL injection vulnerability in\npg_createsubscriber. An attacker could possibly use this issue to execute\narbitrary SQL as a superuser. This issue only affected Ubuntu 25.10 and\nUbuntu 26.04 LTS. (CVE-2026-6476)\n\nIt was discovered that PostgreSQL used an unsafe libpq function in large\nobject operations. An attacker could possibly use this issue to overwrite\nclient memory and execute arbitrary code. (CVE-2026-6477)\n\nIt was discovered that PostgreSQL did not compare MD5-hashed passwords in\nconstant time. An attacker could possibly use this issue to obtain\nsensitive information. (CVE-2026-6478)\n\nIt was discovered that PostgreSQL had uncontrolled recursion during SSL and\nGSS negotiation. An attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-6479)\n\nIt was discovered that PostgreSQL incorrectly handled array length\nmismatches in pg_restore_attribute_stats(). An attacker could possibly use\nthis issue to obtain sensitive information. This issue only affected Ubuntu\n26.04 LTS. (CVE-2026-6575)\n\nIt was discovered that PostgreSQL had a stack buffer overflow in the refint\nmodule. An attacker could use this issue to cause PostgreSQL to crash,\nresulting in a denial of service, or possibly execute arbitrary code.\n(CVE-2026-6637)\n\nIt was discovered that PostgreSQL had an SQL injection vulnerability in\nlogical replication REFRESH PUBLICATION. An attacker could possibly use\nthis issue to execute arbitrary SQL. This issue only affected Ubuntu 24.04\nLTS, Ubuntu 25.10, and Ubuntu 26.04 LTS. (CVE-2026-6638)","is_hidden":false,"release_packages":{"jammy":[{"name":"postgresql-14","version":"14.23-0ubuntu0.22.04.1","description":"Object-relational SQL database","is_source":true},{"name":"libecpg-compat3","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"libecpg-dev","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"libecpg6","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"libpgtypes3","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"libpq-dev","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"libpq5","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-client-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-doc-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-plperl-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-plpython3-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-pltcl-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-server-dev-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"}],"noble":[{"name":"postgresql-16","version":"16.14-0ubuntu0.24.04.1","description":"Object-relational SQL database","is_source":true},{"name":"libecpg-compat3","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"libecpg-dev","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"libecpg6","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"libpgtypes3","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"libpq-dev","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"libpq5","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-client-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-doc-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-plperl-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-plpython3-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-pltcl-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-server-dev-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"}],"questing":[{"name":"postgresql-17","version":"17.10-0ubuntu0.25.10.1","description":"Object-relational SQL database","is_source":true},{"name":"libecpg-compat3","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"libecpg-dev","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"libecpg6","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"libpgtypes3","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"libpq-dev","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"libpq5","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-client-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-doc-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-plperl-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-plpython3-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-pltcl-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-server-dev-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"}],"resolute":[{"name":"postgresql-18","version":"18.4-0ubuntu0.26.04.1","description":"Object-relational SQL database","is_source":true},{"name":"libecpg-compat3","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libecpg-dev","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libecpg6","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libpgtypes3","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libpq-dev","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libpq-oauth","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libpq5","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-18-jit","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-client-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-doc-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-plperl-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-plpython3-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-pltcl-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-server-dev-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-6475","CVE-2026-6637","CVE-2026-6575","CVE-2026-6478","CVE-2026-6473","CVE-2026-6477","CVE-2026-6638","CVE-2026-6472","CVE-2026-6476","CVE-2026-6474","CVE-2026-6479"]}]},{"id":"CVE-2026-6478","published":"2026-05-14T14:16:00","updated_at":"2026-05-22T18:07:47.423203+00:00","description":"\nCovert timing channel in comparison of MD5-hashed password in PostgreSQL\nauthentication allows an attacker to recover user credentials sufficient to\nauthenticate. This does not affect scram-sha-256 passwords, the default in\nall supported releases. However, current databases may have MD5-hashed\npasswords originating in upgrades from PostgreSQL 13 or earlier. Versions\nbefore PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.","ubuntu_description":"","notes":[{"author":"leosilva","note":"PostgreSQL 9.3 is end of life upstream, and no updates are\nare available. Marking as deferred in -esm-main releases."}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-6478","https://www.postgresql.org/about/news/postgresql-184-1710-1614-1518-and-1423-released-3297/","https://www.postgresql.org/support/security/CVE-2026-6478/","https://ubuntu.com/security/notices/USN-8294-1"],"bugs":[""],"patches":{"postgresql-18":[],"postgresql-17":[],"postgresql-16":[],"postgresql-14":[],"postgresql-12":[],"postgresql-10":[],"postgresql-9.5":[],"postgresql-9.3":[]},"tags":{},"packages":[{"name":"postgresql-10","source":"https://ubuntu.com/security/cve?package=postgresql-10","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-10","debian":"https://tracker.debian.org/pkg/postgresql-10","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"postgresql-12","source":"https://ubuntu.com/security/cve?package=postgresql-12","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-12","debian":"https://tracker.debian.org/pkg/postgresql-12","statuses":[{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"postgresql-14","source":"https://ubuntu.com/security/cve?package=postgresql-14","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-14","debian":"https://tracker.debian.org/pkg/postgresql-14","statuses":[{"release_codename":"jammy","status":"released","description":"14.23-0ubuntu0.22.04.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"postgresql-16","source":"https://ubuntu.com/security/cve?package=postgresql-16","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-16","debian":"https://tracker.debian.org/pkg/postgresql-16","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"16.14-0ubuntu0.24.04.1","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"postgresql-17","source":"https://ubuntu.com/security/cve?package=postgresql-17","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-17","debian":"https://tracker.debian.org/pkg/postgresql-17","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"17.10-0ubuntu0.25.10.1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"postgresql-18","source":"https://ubuntu.com/security/cve?package=postgresql-18","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-18","debian":"https://tracker.debian.org/pkg/postgresql-18","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"18.4-0ubuntu0.26.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"postgresql-9.3","source":"https://ubuntu.com/security/cve?package=postgresql-9.3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-9.3","debian":"https://tracker.debian.org/pkg/postgresql-9.3","statuses":[{"release_codename":"trusty","status":"deferred","description":"2019-08-23","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"postgresql-9.5","source":"https://ubuntu.com/security/cve?package=postgresql-9.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-9.5","debian":"https://tracker.debian.org/pkg/postgresql-9.5","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":["USN-8294-1"],"notices":[{"id":"USN-8294-1","title":"PostgreSQL vulnerabilities","summary":"Several security issues were fixed in PostgreSQL.","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart PostgreSQL to\nmake all the necessary changes.","references":[],"published":"2026-05-21T20:39:48.706022","description":"It was discovered that PostgreSQL did not correctly enforce authorization\nfor CREATE TYPE. An attacker could possibly use this issue to execute\narbitrary SQL functions. (CVE-2026-6472)\n\nIt was discovered that PostgreSQL incorrectly handled large user input in\nmultiple server features. An attacker could possibly use this issue to\ncause PostgreSQL to crash, resulting in a denial of service, or execute\narbitrary code. (CVE-2026-6473)\n\nIt was discovered that PostgreSQL incorrectly handled format strings in\nthe timeofday() function. An attacker could possibly use this issue to\nobtain sensitive information. (CVE-2026-6474)\n\nIt was discovered that PostgreSQL incorrectly followed symbolic links in\npg_basebackup and pg_rewind. An attacker could possibly use this issue to\noverwrite local files and execute arbitrary code. (CVE-2026-6475)\n\nIt was discovered that PostgreSQL had an SQL injection vulnerability in\npg_createsubscriber. An attacker could possibly use this issue to execute\narbitrary SQL as a superuser. This issue only affected Ubuntu 25.10 and\nUbuntu 26.04 LTS. (CVE-2026-6476)\n\nIt was discovered that PostgreSQL used an unsafe libpq function in large\nobject operations. An attacker could possibly use this issue to overwrite\nclient memory and execute arbitrary code. (CVE-2026-6477)\n\nIt was discovered that PostgreSQL did not compare MD5-hashed passwords in\nconstant time. An attacker could possibly use this issue to obtain\nsensitive information. (CVE-2026-6478)\n\nIt was discovered that PostgreSQL had uncontrolled recursion during SSL and\nGSS negotiation. An attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-6479)\n\nIt was discovered that PostgreSQL incorrectly handled array length\nmismatches in pg_restore_attribute_stats(). An attacker could possibly use\nthis issue to obtain sensitive information. This issue only affected Ubuntu\n26.04 LTS. (CVE-2026-6575)\n\nIt was discovered that PostgreSQL had a stack buffer overflow in the refint\nmodule. An attacker could use this issue to cause PostgreSQL to crash,\nresulting in a denial of service, or possibly execute arbitrary code.\n(CVE-2026-6637)\n\nIt was discovered that PostgreSQL had an SQL injection vulnerability in\nlogical replication REFRESH PUBLICATION. An attacker could possibly use\nthis issue to execute arbitrary SQL. This issue only affected Ubuntu 24.04\nLTS, Ubuntu 25.10, and Ubuntu 26.04 LTS. (CVE-2026-6638)","is_hidden":false,"release_packages":{"jammy":[{"name":"postgresql-14","version":"14.23-0ubuntu0.22.04.1","description":"Object-relational SQL database","is_source":true},{"name":"libecpg-compat3","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"libecpg-dev","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"libecpg6","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"libpgtypes3","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"libpq-dev","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"libpq5","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-client-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-doc-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-plperl-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-plpython3-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-pltcl-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-server-dev-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"}],"noble":[{"name":"postgresql-16","version":"16.14-0ubuntu0.24.04.1","description":"Object-relational SQL database","is_source":true},{"name":"libecpg-compat3","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"libecpg-dev","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"libecpg6","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"libpgtypes3","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"libpq-dev","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"libpq5","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-client-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-doc-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-plperl-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-plpython3-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-pltcl-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-server-dev-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"}],"questing":[{"name":"postgresql-17","version":"17.10-0ubuntu0.25.10.1","description":"Object-relational SQL database","is_source":true},{"name":"libecpg-compat3","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"libecpg-dev","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"libecpg6","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"libpgtypes3","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"libpq-dev","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"libpq5","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-client-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-doc-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-plperl-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-plpython3-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-pltcl-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-server-dev-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"}],"resolute":[{"name":"postgresql-18","version":"18.4-0ubuntu0.26.04.1","description":"Object-relational SQL database","is_source":true},{"name":"libecpg-compat3","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libecpg-dev","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libecpg6","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libpgtypes3","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libpq-dev","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libpq-oauth","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libpq5","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-18-jit","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-client-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-doc-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-plperl-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-plpython3-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-pltcl-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-server-dev-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-6475","CVE-2026-6637","CVE-2026-6575","CVE-2026-6478","CVE-2026-6473","CVE-2026-6477","CVE-2026-6638","CVE-2026-6472","CVE-2026-6476","CVE-2026-6474","CVE-2026-6479"]}]},{"id":"CVE-2026-6477","published":"2026-05-14T14:16:00","updated_at":"2026-05-22T18:08:49.250173+00:00","description":"\nUse of inherently dangerous function PQfn(..., result_is_int=0, ...) in\nPostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64()\nfunctions allows the server superuser to overwrite a client stack buffer\nwith an arbitrarily-large response. Like gets(), PQfn(...,\nresult_is_int=0, ...) stores arbitrary-length, server-determined data into\na buffer of unspecified size. Because both the \\lo_export command in psql\nand pg_dump call lo_read(), the server superuser can overwrite pg_dump or\npsql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18,\nand 14.23 are affected.","ubuntu_description":"","notes":[{"author":"leosilva","note":"PostgreSQL 9.3 is end of life upstream, and no updates are\nare available. Marking as deferred in -esm-main releases."}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-6477","https://www.postgresql.org/about/news/postgresql-184-1710-1614-1518-and-1423-released-3297/","https://www.postgresql.org/support/security/CVE-2026-6477/","https://ubuntu.com/security/notices/USN-8294-1"],"bugs":[""],"patches":{"postgresql-18":[],"postgresql-17":[],"postgresql-16":[],"postgresql-14":[],"postgresql-12":[],"postgresql-10":[],"postgresql-9.5":[],"postgresql-9.3":[]},"tags":{},"packages":[{"name":"postgresql-10","source":"https://ubuntu.com/security/cve?package=postgresql-10","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-10","debian":"https://tracker.debian.org/pkg/postgresql-10","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"postgresql-12","source":"https://ubuntu.com/security/cve?package=postgresql-12","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-12","debian":"https://tracker.debian.org/pkg/postgresql-12","statuses":[{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"postgresql-14","source":"https://ubuntu.com/security/cve?package=postgresql-14","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-14","debian":"https://tracker.debian.org/pkg/postgresql-14","statuses":[{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"14.23-0ubuntu0.22.04.1","component":null,"pocket":"security"}]},{"name":"postgresql-16","source":"https://ubuntu.com/security/cve?package=postgresql-16","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-16","debian":"https://tracker.debian.org/pkg/postgresql-16","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"16.14-0ubuntu0.24.04.1","component":null,"pocket":"security"}]},{"name":"postgresql-17","source":"https://ubuntu.com/security/cve?package=postgresql-17","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-17","debian":"https://tracker.debian.org/pkg/postgresql-17","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"17.10-0ubuntu0.25.10.1","component":null,"pocket":"security"}]},{"name":"postgresql-18","source":"https://ubuntu.com/security/cve?package=postgresql-18","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-18","debian":"https://tracker.debian.org/pkg/postgresql-18","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"18.4-0ubuntu0.26.04.1","component":null,"pocket":"security"}]},{"name":"postgresql-9.3","source":"https://ubuntu.com/security/cve?package=postgresql-9.3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-9.3","debian":"https://tracker.debian.org/pkg/postgresql-9.3","statuses":[{"release_codename":"trusty","status":"deferred","description":"2019-08-23","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"postgresql-9.5","source":"https://ubuntu.com/security/cve?package=postgresql-9.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-9.5","debian":"https://tracker.debian.org/pkg/postgresql-9.5","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":["USN-8294-1"],"notices":[{"id":"USN-8294-1","title":"PostgreSQL vulnerabilities","summary":"Several security issues were fixed in PostgreSQL.","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart PostgreSQL to\nmake all the necessary changes.","references":[],"published":"2026-05-21T20:39:48.706022","description":"It was discovered that PostgreSQL did not correctly enforce authorization\nfor CREATE TYPE. An attacker could possibly use this issue to execute\narbitrary SQL functions. (CVE-2026-6472)\n\nIt was discovered that PostgreSQL incorrectly handled large user input in\nmultiple server features. An attacker could possibly use this issue to\ncause PostgreSQL to crash, resulting in a denial of service, or execute\narbitrary code. (CVE-2026-6473)\n\nIt was discovered that PostgreSQL incorrectly handled format strings in\nthe timeofday() function. An attacker could possibly use this issue to\nobtain sensitive information. (CVE-2026-6474)\n\nIt was discovered that PostgreSQL incorrectly followed symbolic links in\npg_basebackup and pg_rewind. An attacker could possibly use this issue to\noverwrite local files and execute arbitrary code. (CVE-2026-6475)\n\nIt was discovered that PostgreSQL had an SQL injection vulnerability in\npg_createsubscriber. An attacker could possibly use this issue to execute\narbitrary SQL as a superuser. This issue only affected Ubuntu 25.10 and\nUbuntu 26.04 LTS. (CVE-2026-6476)\n\nIt was discovered that PostgreSQL used an unsafe libpq function in large\nobject operations. An attacker could possibly use this issue to overwrite\nclient memory and execute arbitrary code. (CVE-2026-6477)\n\nIt was discovered that PostgreSQL did not compare MD5-hashed passwords in\nconstant time. An attacker could possibly use this issue to obtain\nsensitive information. (CVE-2026-6478)\n\nIt was discovered that PostgreSQL had uncontrolled recursion during SSL and\nGSS negotiation. An attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-6479)\n\nIt was discovered that PostgreSQL incorrectly handled array length\nmismatches in pg_restore_attribute_stats(). An attacker could possibly use\nthis issue to obtain sensitive information. This issue only affected Ubuntu\n26.04 LTS. (CVE-2026-6575)\n\nIt was discovered that PostgreSQL had a stack buffer overflow in the refint\nmodule. An attacker could use this issue to cause PostgreSQL to crash,\nresulting in a denial of service, or possibly execute arbitrary code.\n(CVE-2026-6637)\n\nIt was discovered that PostgreSQL had an SQL injection vulnerability in\nlogical replication REFRESH PUBLICATION. An attacker could possibly use\nthis issue to execute arbitrary SQL. This issue only affected Ubuntu 24.04\nLTS, Ubuntu 25.10, and Ubuntu 26.04 LTS. (CVE-2026-6638)","is_hidden":false,"release_packages":{"jammy":[{"name":"postgresql-14","version":"14.23-0ubuntu0.22.04.1","description":"Object-relational SQL database","is_source":true},{"name":"libecpg-compat3","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"libecpg-dev","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"libecpg6","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"libpgtypes3","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"libpq-dev","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"libpq5","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-client-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-doc-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-plperl-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-plpython3-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-pltcl-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-server-dev-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"}],"noble":[{"name":"postgresql-16","version":"16.14-0ubuntu0.24.04.1","description":"Object-relational SQL database","is_source":true},{"name":"libecpg-compat3","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"libecpg-dev","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"libecpg6","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"libpgtypes3","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"libpq-dev","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"libpq5","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-client-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-doc-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-plperl-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-plpython3-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-pltcl-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-server-dev-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"}],"questing":[{"name":"postgresql-17","version":"17.10-0ubuntu0.25.10.1","description":"Object-relational SQL database","is_source":true},{"name":"libecpg-compat3","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"libecpg-dev","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"libecpg6","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"libpgtypes3","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"libpq-dev","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"libpq5","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-client-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-doc-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-plperl-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-plpython3-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-pltcl-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-server-dev-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"}],"resolute":[{"name":"postgresql-18","version":"18.4-0ubuntu0.26.04.1","description":"Object-relational SQL database","is_source":true},{"name":"libecpg-compat3","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libecpg-dev","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libecpg6","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libpgtypes3","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libpq-dev","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libpq-oauth","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libpq5","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-18-jit","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-client-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-doc-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-plperl-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-plpython3-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-pltcl-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-server-dev-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-6475","CVE-2026-6637","CVE-2026-6575","CVE-2026-6478","CVE-2026-6473","CVE-2026-6477","CVE-2026-6638","CVE-2026-6472","CVE-2026-6476","CVE-2026-6474","CVE-2026-6479"]}]},{"id":"CVE-2026-6476","published":"2026-05-14T14:16:00","updated_at":"2026-05-22T18:08:06.998027+00:00","description":"\nSQL injection in PostgreSQL pg_createsubscriber allows an attacker with\npg_create_subscription rights to execute arbitrary SQL as a superuser. The\nattack takes effect when pg_createsubscriber next runs. Within major\nversions 17 and 18, minor versions before PostgreSQL 18.4 and 17.10 are\naffected. Versions before PostgreSQL 17 are unaffected.","ubuntu_description":"","notes":[{"author":"leosilva","note":"PostgreSQL 9.3 is end of life upstream, and no updates are\nare available. Marking as deferred in -esm-main releases."}],"codename":null,"priority":"medium","cvss3":7.2,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.2,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-6476","https://www.postgresql.org/about/news/postgresql-184-1710-1614-1518-and-1423-released-3297/","https://www.postgresql.org/support/security/CVE-2026-6476/","https://ubuntu.com/security/notices/USN-8294-1"],"bugs":[""],"patches":{"postgresql-18":[],"postgresql-17":[],"postgresql-16":[],"postgresql-14":[],"postgresql-12":[],"postgresql-10":[],"postgresql-9.5":[],"postgresql-9.3":[]},"tags":{},"packages":[{"name":"postgresql-10","source":"https://ubuntu.com/security/cve?package=postgresql-10","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-10","debian":"https://tracker.debian.org/pkg/postgresql-10","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"postgresql-12","source":"https://ubuntu.com/security/cve?package=postgresql-12","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-12","debian":"https://tracker.debian.org/pkg/postgresql-12","statuses":[{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"postgresql-14","source":"https://ubuntu.com/security/cve?package=postgresql-14","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-14","debian":"https://tracker.debian.org/pkg/postgresql-14","statuses":[{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"14.23-0ubuntu0.22.04.1","component":null,"pocket":"security"}]},{"name":"postgresql-16","source":"https://ubuntu.com/security/cve?package=postgresql-16","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-16","debian":"https://tracker.debian.org/pkg/postgresql-16","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"16.14-0ubuntu0.24.04.1","component":null,"pocket":"security"}]},{"name":"postgresql-17","source":"https://ubuntu.com/security/cve?package=postgresql-17","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-17","debian":"https://tracker.debian.org/pkg/postgresql-17","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"17.10-0ubuntu0.25.10.1","component":null,"pocket":"security"}]},{"name":"postgresql-18","source":"https://ubuntu.com/security/cve?package=postgresql-18","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-18","debian":"https://tracker.debian.org/pkg/postgresql-18","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"18.4-0ubuntu0.26.04.1","component":null,"pocket":"security"}]},{"name":"postgresql-9.3","source":"https://ubuntu.com/security/cve?package=postgresql-9.3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-9.3","debian":"https://tracker.debian.org/pkg/postgresql-9.3","statuses":[{"release_codename":"trusty","status":"deferred","description":"2019-08-23","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"postgresql-9.5","source":"https://ubuntu.com/security/cve?package=postgresql-9.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-9.5","debian":"https://tracker.debian.org/pkg/postgresql-9.5","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":["USN-8294-1"],"notices":[{"id":"USN-8294-1","title":"PostgreSQL vulnerabilities","summary":"Several security issues were fixed in PostgreSQL.","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart PostgreSQL to\nmake all the necessary changes.","references":[],"published":"2026-05-21T20:39:48.706022","description":"It was discovered that PostgreSQL did not correctly enforce authorization\nfor CREATE TYPE. An attacker could possibly use this issue to execute\narbitrary SQL functions. (CVE-2026-6472)\n\nIt was discovered that PostgreSQL incorrectly handled large user input in\nmultiple server features. An attacker could possibly use this issue to\ncause PostgreSQL to crash, resulting in a denial of service, or execute\narbitrary code. (CVE-2026-6473)\n\nIt was discovered that PostgreSQL incorrectly handled format strings in\nthe timeofday() function. An attacker could possibly use this issue to\nobtain sensitive information. (CVE-2026-6474)\n\nIt was discovered that PostgreSQL incorrectly followed symbolic links in\npg_basebackup and pg_rewind. An attacker could possibly use this issue to\noverwrite local files and execute arbitrary code. (CVE-2026-6475)\n\nIt was discovered that PostgreSQL had an SQL injection vulnerability in\npg_createsubscriber. An attacker could possibly use this issue to execute\narbitrary SQL as a superuser. This issue only affected Ubuntu 25.10 and\nUbuntu 26.04 LTS. (CVE-2026-6476)\n\nIt was discovered that PostgreSQL used an unsafe libpq function in large\nobject operations. An attacker could possibly use this issue to overwrite\nclient memory and execute arbitrary code. (CVE-2026-6477)\n\nIt was discovered that PostgreSQL did not compare MD5-hashed passwords in\nconstant time. An attacker could possibly use this issue to obtain\nsensitive information. (CVE-2026-6478)\n\nIt was discovered that PostgreSQL had uncontrolled recursion during SSL and\nGSS negotiation. An attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-6479)\n\nIt was discovered that PostgreSQL incorrectly handled array length\nmismatches in pg_restore_attribute_stats(). An attacker could possibly use\nthis issue to obtain sensitive information. This issue only affected Ubuntu\n26.04 LTS. (CVE-2026-6575)\n\nIt was discovered that PostgreSQL had a stack buffer overflow in the refint\nmodule. An attacker could use this issue to cause PostgreSQL to crash,\nresulting in a denial of service, or possibly execute arbitrary code.\n(CVE-2026-6637)\n\nIt was discovered that PostgreSQL had an SQL injection vulnerability in\nlogical replication REFRESH PUBLICATION. An attacker could possibly use\nthis issue to execute arbitrary SQL. This issue only affected Ubuntu 24.04\nLTS, Ubuntu 25.10, and Ubuntu 26.04 LTS. (CVE-2026-6638)","is_hidden":false,"release_packages":{"jammy":[{"name":"postgresql-14","version":"14.23-0ubuntu0.22.04.1","description":"Object-relational SQL database","is_source":true},{"name":"libecpg-compat3","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"libecpg-dev","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"libecpg6","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"libpgtypes3","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"libpq-dev","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"libpq5","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-client-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-doc-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-plperl-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-plpython3-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-pltcl-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-server-dev-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"}],"noble":[{"name":"postgresql-16","version":"16.14-0ubuntu0.24.04.1","description":"Object-relational SQL database","is_source":true},{"name":"libecpg-compat3","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"libecpg-dev","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"libecpg6","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"libpgtypes3","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"libpq-dev","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"libpq5","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-client-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-doc-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-plperl-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-plpython3-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-pltcl-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-server-dev-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"}],"questing":[{"name":"postgresql-17","version":"17.10-0ubuntu0.25.10.1","description":"Object-relational SQL database","is_source":true},{"name":"libecpg-compat3","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"libecpg-dev","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"libecpg6","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"libpgtypes3","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"libpq-dev","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"libpq5","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-client-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-doc-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-plperl-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-plpython3-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-pltcl-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-server-dev-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"}],"resolute":[{"name":"postgresql-18","version":"18.4-0ubuntu0.26.04.1","description":"Object-relational SQL database","is_source":true},{"name":"libecpg-compat3","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libecpg-dev","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libecpg6","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libpgtypes3","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libpq-dev","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libpq-oauth","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libpq5","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-18-jit","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-client-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-doc-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-plperl-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-plpython3-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-pltcl-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-server-dev-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-6475","CVE-2026-6637","CVE-2026-6575","CVE-2026-6478","CVE-2026-6473","CVE-2026-6477","CVE-2026-6638","CVE-2026-6472","CVE-2026-6476","CVE-2026-6474","CVE-2026-6479"]}]},{"id":"CVE-2026-6475","published":"2026-05-14T14:16:00","updated_at":"2026-05-22T18:07:47.423203+00:00","description":"\nSymlink following in PostgreSQL pg_basebackup plain format and in pg_rewind\nallows an origin superuser to overwrite local files, e.g.\n/var/lib/postgres/.bashrc, that hijack the operating system account. It\nwill remain the case that starting the server after these commands\nimplicitly trusts the origin superuser, due to features like\nshared_preload_libraries. Hence, the attack has practical implications\nonly if one takes relevant action between these commands and server start,\nlike moving the files to a different VM or snapshotting the VM. Versions\nbefore PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.","ubuntu_description":"","notes":[{"author":"leosilva","note":"PostgreSQL 9.3 is end of life upstream, and no updates are\nare available. Marking as deferred in -esm-main releases."}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-6475","https://www.postgresql.org/about/news/postgresql-184-1710-1614-1518-and-1423-released-3297/","https://www.postgresql.org/support/security/CVE-2026-6475/","https://ubuntu.com/security/notices/USN-8294-1"],"bugs":[""],"patches":{"postgresql-18":[],"postgresql-17":[],"postgresql-16":[],"postgresql-14":[],"postgresql-12":[],"postgresql-10":[],"postgresql-9.5":[],"postgresql-9.3":[]},"tags":{},"packages":[{"name":"postgresql-10","source":"https://ubuntu.com/security/cve?package=postgresql-10","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-10","debian":"https://tracker.debian.org/pkg/postgresql-10","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"postgresql-12","source":"https://ubuntu.com/security/cve?package=postgresql-12","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-12","debian":"https://tracker.debian.org/pkg/postgresql-12","statuses":[{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"postgresql-14","source":"https://ubuntu.com/security/cve?package=postgresql-14","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-14","debian":"https://tracker.debian.org/pkg/postgresql-14","statuses":[{"release_codename":"jammy","status":"released","description":"14.23-0ubuntu0.22.04.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"postgresql-16","source":"https://ubuntu.com/security/cve?package=postgresql-16","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-16","debian":"https://tracker.debian.org/pkg/postgresql-16","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"16.14-0ubuntu0.24.04.1","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"postgresql-17","source":"https://ubuntu.com/security/cve?package=postgresql-17","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-17","debian":"https://tracker.debian.org/pkg/postgresql-17","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"17.10-0ubuntu0.25.10.1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"postgresql-18","source":"https://ubuntu.com/security/cve?package=postgresql-18","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-18","debian":"https://tracker.debian.org/pkg/postgresql-18","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"18.4-0ubuntu0.26.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"postgresql-9.3","source":"https://ubuntu.com/security/cve?package=postgresql-9.3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-9.3","debian":"https://tracker.debian.org/pkg/postgresql-9.3","statuses":[{"release_codename":"trusty","status":"deferred","description":"2019-08-23","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"postgresql-9.5","source":"https://ubuntu.com/security/cve?package=postgresql-9.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-9.5","debian":"https://tracker.debian.org/pkg/postgresql-9.5","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":["USN-8294-1"],"notices":[{"id":"USN-8294-1","title":"PostgreSQL vulnerabilities","summary":"Several security issues were fixed in PostgreSQL.","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart PostgreSQL to\nmake all the necessary changes.","references":[],"published":"2026-05-21T20:39:48.706022","description":"It was discovered that PostgreSQL did not correctly enforce authorization\nfor CREATE TYPE. An attacker could possibly use this issue to execute\narbitrary SQL functions. (CVE-2026-6472)\n\nIt was discovered that PostgreSQL incorrectly handled large user input in\nmultiple server features. An attacker could possibly use this issue to\ncause PostgreSQL to crash, resulting in a denial of service, or execute\narbitrary code. (CVE-2026-6473)\n\nIt was discovered that PostgreSQL incorrectly handled format strings in\nthe timeofday() function. An attacker could possibly use this issue to\nobtain sensitive information. (CVE-2026-6474)\n\nIt was discovered that PostgreSQL incorrectly followed symbolic links in\npg_basebackup and pg_rewind. An attacker could possibly use this issue to\noverwrite local files and execute arbitrary code. (CVE-2026-6475)\n\nIt was discovered that PostgreSQL had an SQL injection vulnerability in\npg_createsubscriber. An attacker could possibly use this issue to execute\narbitrary SQL as a superuser. This issue only affected Ubuntu 25.10 and\nUbuntu 26.04 LTS. (CVE-2026-6476)\n\nIt was discovered that PostgreSQL used an unsafe libpq function in large\nobject operations. An attacker could possibly use this issue to overwrite\nclient memory and execute arbitrary code. (CVE-2026-6477)\n\nIt was discovered that PostgreSQL did not compare MD5-hashed passwords in\nconstant time. An attacker could possibly use this issue to obtain\nsensitive information. (CVE-2026-6478)\n\nIt was discovered that PostgreSQL had uncontrolled recursion during SSL and\nGSS negotiation. An attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-6479)\n\nIt was discovered that PostgreSQL incorrectly handled array length\nmismatches in pg_restore_attribute_stats(). An attacker could possibly use\nthis issue to obtain sensitive information. This issue only affected Ubuntu\n26.04 LTS. (CVE-2026-6575)\n\nIt was discovered that PostgreSQL had a stack buffer overflow in the refint\nmodule. An attacker could use this issue to cause PostgreSQL to crash,\nresulting in a denial of service, or possibly execute arbitrary code.\n(CVE-2026-6637)\n\nIt was discovered that PostgreSQL had an SQL injection vulnerability in\nlogical replication REFRESH PUBLICATION. An attacker could possibly use\nthis issue to execute arbitrary SQL. This issue only affected Ubuntu 24.04\nLTS, Ubuntu 25.10, and Ubuntu 26.04 LTS. (CVE-2026-6638)","is_hidden":false,"release_packages":{"jammy":[{"name":"postgresql-14","version":"14.23-0ubuntu0.22.04.1","description":"Object-relational SQL database","is_source":true},{"name":"libecpg-compat3","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"libecpg-dev","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"libecpg6","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"libpgtypes3","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"libpq-dev","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"libpq5","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-client-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-doc-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-plperl-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-plpython3-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-pltcl-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-server-dev-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"}],"noble":[{"name":"postgresql-16","version":"16.14-0ubuntu0.24.04.1","description":"Object-relational SQL database","is_source":true},{"name":"libecpg-compat3","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"libecpg-dev","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"libecpg6","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"libpgtypes3","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"libpq-dev","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"libpq5","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-client-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-doc-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-plperl-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-plpython3-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-pltcl-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-server-dev-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"}],"questing":[{"name":"postgresql-17","version":"17.10-0ubuntu0.25.10.1","description":"Object-relational SQL database","is_source":true},{"name":"libecpg-compat3","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"libecpg-dev","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"libecpg6","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"libpgtypes3","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"libpq-dev","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"libpq5","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-client-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-doc-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-plperl-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-plpython3-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-pltcl-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-server-dev-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"}],"resolute":[{"name":"postgresql-18","version":"18.4-0ubuntu0.26.04.1","description":"Object-relational SQL database","is_source":true},{"name":"libecpg-compat3","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libecpg-dev","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libecpg6","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libpgtypes3","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libpq-dev","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libpq-oauth","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libpq5","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-18-jit","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-client-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-doc-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-plperl-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-plpython3-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-pltcl-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-server-dev-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-6475","CVE-2026-6637","CVE-2026-6575","CVE-2026-6478","CVE-2026-6473","CVE-2026-6477","CVE-2026-6638","CVE-2026-6472","CVE-2026-6476","CVE-2026-6474","CVE-2026-6479"]}]},{"id":"CVE-2026-6474","published":"2026-05-14T14:16:00","updated_at":"2026-05-22T18:07:47.423203+00:00","description":"\nExternally-controlled format string in PostgreSQL timeofday() function\nallows an attacker to retrieve portions of server memory, via crafted\ntimezone zones. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and\n14.23 are affected.","ubuntu_description":"","notes":[{"author":"leosilva","note":"PostgreSQL 9.3 is end of life upstream, and no updates are\nare available. Marking as deferred in -esm-main releases."}],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-6474","https://www.postgresql.org/about/news/postgresql-184-1710-1614-1518-and-1423-released-3297/","https://www.postgresql.org/support/security/CVE-2026-6474/","https://ubuntu.com/security/notices/USN-8294-1"],"bugs":[""],"patches":{"postgresql-18":[],"postgresql-17":[],"postgresql-16":[],"postgresql-14":[],"postgresql-12":[],"postgresql-10":[],"postgresql-9.5":[],"postgresql-9.3":[]},"tags":{},"packages":[{"name":"postgresql-10","source":"https://ubuntu.com/security/cve?package=postgresql-10","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-10","debian":"https://tracker.debian.org/pkg/postgresql-10","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"postgresql-12","source":"https://ubuntu.com/security/cve?package=postgresql-12","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-12","debian":"https://tracker.debian.org/pkg/postgresql-12","statuses":[{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"postgresql-14","source":"https://ubuntu.com/security/cve?package=postgresql-14","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-14","debian":"https://tracker.debian.org/pkg/postgresql-14","statuses":[{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"14.23-0ubuntu0.22.04.1","component":null,"pocket":"security"}]},{"name":"postgresql-16","source":"https://ubuntu.com/security/cve?package=postgresql-16","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-16","debian":"https://tracker.debian.org/pkg/postgresql-16","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"16.14-0ubuntu0.24.04.1","component":null,"pocket":"security"}]},{"name":"postgresql-17","source":"https://ubuntu.com/security/cve?package=postgresql-17","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-17","debian":"https://tracker.debian.org/pkg/postgresql-17","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"17.10-0ubuntu0.25.10.1","component":null,"pocket":"security"}]},{"name":"postgresql-18","source":"https://ubuntu.com/security/cve?package=postgresql-18","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-18","debian":"https://tracker.debian.org/pkg/postgresql-18","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"18.4-0ubuntu0.26.04.1","component":null,"pocket":"security"}]},{"name":"postgresql-9.3","source":"https://ubuntu.com/security/cve?package=postgresql-9.3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-9.3","debian":"https://tracker.debian.org/pkg/postgresql-9.3","statuses":[{"release_codename":"trusty","status":"deferred","description":"2019-08-23","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"postgresql-9.5","source":"https://ubuntu.com/security/cve?package=postgresql-9.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-9.5","debian":"https://tracker.debian.org/pkg/postgresql-9.5","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":["USN-8294-1"],"notices":[{"id":"USN-8294-1","title":"PostgreSQL vulnerabilities","summary":"Several security issues were fixed in PostgreSQL.","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart PostgreSQL to\nmake all the necessary changes.","references":[],"published":"2026-05-21T20:39:48.706022","description":"It was discovered that PostgreSQL did not correctly enforce authorization\nfor CREATE TYPE. An attacker could possibly use this issue to execute\narbitrary SQL functions. (CVE-2026-6472)\n\nIt was discovered that PostgreSQL incorrectly handled large user input in\nmultiple server features. An attacker could possibly use this issue to\ncause PostgreSQL to crash, resulting in a denial of service, or execute\narbitrary code. (CVE-2026-6473)\n\nIt was discovered that PostgreSQL incorrectly handled format strings in\nthe timeofday() function. An attacker could possibly use this issue to\nobtain sensitive information. (CVE-2026-6474)\n\nIt was discovered that PostgreSQL incorrectly followed symbolic links in\npg_basebackup and pg_rewind. An attacker could possibly use this issue to\noverwrite local files and execute arbitrary code. (CVE-2026-6475)\n\nIt was discovered that PostgreSQL had an SQL injection vulnerability in\npg_createsubscriber. An attacker could possibly use this issue to execute\narbitrary SQL as a superuser. This issue only affected Ubuntu 25.10 and\nUbuntu 26.04 LTS. (CVE-2026-6476)\n\nIt was discovered that PostgreSQL used an unsafe libpq function in large\nobject operations. An attacker could possibly use this issue to overwrite\nclient memory and execute arbitrary code. (CVE-2026-6477)\n\nIt was discovered that PostgreSQL did not compare MD5-hashed passwords in\nconstant time. An attacker could possibly use this issue to obtain\nsensitive information. (CVE-2026-6478)\n\nIt was discovered that PostgreSQL had uncontrolled recursion during SSL and\nGSS negotiation. An attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-6479)\n\nIt was discovered that PostgreSQL incorrectly handled array length\nmismatches in pg_restore_attribute_stats(). An attacker could possibly use\nthis issue to obtain sensitive information. This issue only affected Ubuntu\n26.04 LTS. (CVE-2026-6575)\n\nIt was discovered that PostgreSQL had a stack buffer overflow in the refint\nmodule. An attacker could use this issue to cause PostgreSQL to crash,\nresulting in a denial of service, or possibly execute arbitrary code.\n(CVE-2026-6637)\n\nIt was discovered that PostgreSQL had an SQL injection vulnerability in\nlogical replication REFRESH PUBLICATION. An attacker could possibly use\nthis issue to execute arbitrary SQL. This issue only affected Ubuntu 24.04\nLTS, Ubuntu 25.10, and Ubuntu 26.04 LTS. (CVE-2026-6638)","is_hidden":false,"release_packages":{"jammy":[{"name":"postgresql-14","version":"14.23-0ubuntu0.22.04.1","description":"Object-relational SQL database","is_source":true},{"name":"libecpg-compat3","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"libecpg-dev","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"libecpg6","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"libpgtypes3","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"libpq-dev","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"libpq5","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-client-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-doc-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-plperl-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-plpython3-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-pltcl-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-server-dev-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"}],"noble":[{"name":"postgresql-16","version":"16.14-0ubuntu0.24.04.1","description":"Object-relational SQL database","is_source":true},{"name":"libecpg-compat3","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"libecpg-dev","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"libecpg6","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"libpgtypes3","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"libpq-dev","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"libpq5","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-client-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-doc-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-plperl-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-plpython3-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-pltcl-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-server-dev-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"}],"questing":[{"name":"postgresql-17","version":"17.10-0ubuntu0.25.10.1","description":"Object-relational SQL database","is_source":true},{"name":"libecpg-compat3","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"libecpg-dev","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"libecpg6","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"libpgtypes3","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"libpq-dev","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"libpq5","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-client-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-doc-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-plperl-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-plpython3-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-pltcl-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-server-dev-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"}],"resolute":[{"name":"postgresql-18","version":"18.4-0ubuntu0.26.04.1","description":"Object-relational SQL database","is_source":true},{"name":"libecpg-compat3","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libecpg-dev","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libecpg6","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libpgtypes3","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libpq-dev","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libpq-oauth","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libpq5","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-18-jit","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-client-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-doc-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-plperl-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-plpython3-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-pltcl-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-server-dev-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-6475","CVE-2026-6637","CVE-2026-6575","CVE-2026-6478","CVE-2026-6473","CVE-2026-6477","CVE-2026-6638","CVE-2026-6472","CVE-2026-6476","CVE-2026-6474","CVE-2026-6479"]}]},{"id":"CVE-2026-6473","published":"2026-05-14T14:16:00","updated_at":"2026-08-25T09:41:48.638498+00:00","description":"\nInteger wraparound in multiple PostgreSQL server features allows an\nunprivileged database user to cause the server to undersize an allocation\nand write out-of-bounds. This may execute arbitrary code as the operating\nsystem user running the database. In applications that pass gigabyte-scale\nuser inputs to the relevant database functions, the application input\nprovider may achieve a segmentation fault. Versions before PostgreSQL\n18.4, 17.10, 16.14, 15.18, and 14.23 are affected.","ubuntu_description":"","notes":[{"author":"leosilva","note":"PostgreSQL 9.3 is end of life upstream, and no updates are\nare available. Marking as deferred in -esm-main releases."}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-6473","https://www.postgresql.org/about/news/postgresql-184-1710-1614-1518-and-1423-released-3297/","https://www.postgresql.org/support/security/CVE-2026-6473/","https://ubuntu.com/security/notices/USN-8294-1","https://ubuntu.com/security/notices/USN-8653-1"],"bugs":[""],"patches":{"postgresql-18":[],"postgresql-17":[],"postgresql-16":[],"postgresql-14":[],"postgresql-12":[],"postgresql-10":[],"postgresql-9.5":[],"postgresql-9.3":[]},"tags":{},"packages":[{"name":"postgresql-10","source":"https://ubuntu.com/security/cve?package=postgresql-10","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-10","debian":"https://tracker.debian.org/pkg/postgresql-10","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"postgresql-12","source":"https://ubuntu.com/security/cve?package=postgresql-12","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-12","debian":"https://tracker.debian.org/pkg/postgresql-12","statuses":[{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"postgresql-14","source":"https://ubuntu.com/security/cve?package=postgresql-14","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-14","debian":"https://tracker.debian.org/pkg/postgresql-14","statuses":[{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"14.23-0ubuntu0.22.04.1","component":null,"pocket":"security"}]},{"name":"postgresql-16","source":"https://ubuntu.com/security/cve?package=postgresql-16","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-16","debian":"https://tracker.debian.org/pkg/postgresql-16","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"16.14-0ubuntu0.24.04.1","component":null,"pocket":"security"}]},{"name":"postgresql-17","source":"https://ubuntu.com/security/cve?package=postgresql-17","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-17","debian":"https://tracker.debian.org/pkg/postgresql-17","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"17.10-0ubuntu0.25.10.1","component":null,"pocket":"security"}]},{"name":"postgresql-18","source":"https://ubuntu.com/security/cve?package=postgresql-18","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-18","debian":"https://tracker.debian.org/pkg/postgresql-18","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"18.4-0ubuntu0.26.04.1","component":null,"pocket":"security"}]},{"name":"postgresql-9.3","source":"https://ubuntu.com/security/cve?package=postgresql-9.3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-9.3","debian":"https://tracker.debian.org/pkg/postgresql-9.3","statuses":[{"release_codename":"trusty","status":"deferred","description":"2019-08-23","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"postgresql-9.5","source":"https://ubuntu.com/security/cve?package=postgresql-9.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-9.5","debian":"https://tracker.debian.org/pkg/postgresql-9.5","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":["USN-8294-1","USN-8653-1"],"notices":[{"id":"USN-8294-1","title":"PostgreSQL vulnerabilities","summary":"Several security issues were fixed in PostgreSQL.","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart PostgreSQL to\nmake all the necessary changes.","references":[],"published":"2026-05-21T20:39:48.706022","description":"It was discovered that PostgreSQL did not correctly enforce authorization\nfor CREATE TYPE. An attacker could possibly use this issue to execute\narbitrary SQL functions. (CVE-2026-6472)\n\nIt was discovered that PostgreSQL incorrectly handled large user input in\nmultiple server features. An attacker could possibly use this issue to\ncause PostgreSQL to crash, resulting in a denial of service, or execute\narbitrary code. (CVE-2026-6473)\n\nIt was discovered that PostgreSQL incorrectly handled format strings in\nthe timeofday() function. An attacker could possibly use this issue to\nobtain sensitive information. (CVE-2026-6474)\n\nIt was discovered that PostgreSQL incorrectly followed symbolic links in\npg_basebackup and pg_rewind. An attacker could possibly use this issue to\noverwrite local files and execute arbitrary code. (CVE-2026-6475)\n\nIt was discovered that PostgreSQL had an SQL injection vulnerability in\npg_createsubscriber. An attacker could possibly use this issue to execute\narbitrary SQL as a superuser. This issue only affected Ubuntu 25.10 and\nUbuntu 26.04 LTS. (CVE-2026-6476)\n\nIt was discovered that PostgreSQL used an unsafe libpq function in large\nobject operations. An attacker could possibly use this issue to overwrite\nclient memory and execute arbitrary code. (CVE-2026-6477)\n\nIt was discovered that PostgreSQL did not compare MD5-hashed passwords in\nconstant time. An attacker could possibly use this issue to obtain\nsensitive information. (CVE-2026-6478)\n\nIt was discovered that PostgreSQL had uncontrolled recursion during SSL and\nGSS negotiation. An attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-6479)\n\nIt was discovered that PostgreSQL incorrectly handled array length\nmismatches in pg_restore_attribute_stats(). An attacker could possibly use\nthis issue to obtain sensitive information. This issue only affected Ubuntu\n26.04 LTS. (CVE-2026-6575)\n\nIt was discovered that PostgreSQL had a stack buffer overflow in the refint\nmodule. An attacker could use this issue to cause PostgreSQL to crash,\nresulting in a denial of service, or possibly execute arbitrary code.\n(CVE-2026-6637)\n\nIt was discovered that PostgreSQL had an SQL injection vulnerability in\nlogical replication REFRESH PUBLICATION. An attacker could possibly use\nthis issue to execute arbitrary SQL. This issue only affected Ubuntu 24.04\nLTS, Ubuntu 25.10, and Ubuntu 26.04 LTS. (CVE-2026-6638)","is_hidden":false,"release_packages":{"jammy":[{"name":"postgresql-14","version":"14.23-0ubuntu0.22.04.1","description":"Object-relational SQL database","is_source":true},{"name":"libecpg-compat3","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"libecpg-dev","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"libecpg6","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"libpgtypes3","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"libpq-dev","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"libpq5","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-client-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-doc-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-plperl-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-plpython3-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-pltcl-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-server-dev-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"}],"noble":[{"name":"postgresql-16","version":"16.14-0ubuntu0.24.04.1","description":"Object-relational SQL database","is_source":true},{"name":"libecpg-compat3","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"libecpg-dev","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"libecpg6","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"libpgtypes3","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"libpq-dev","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"libpq5","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-client-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-doc-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-plperl-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-plpython3-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-pltcl-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-server-dev-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"}],"questing":[{"name":"postgresql-17","version":"17.10-0ubuntu0.25.10.1","description":"Object-relational SQL database","is_source":true},{"name":"libecpg-compat3","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"libecpg-dev","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"libecpg6","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"libpgtypes3","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"libpq-dev","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"libpq5","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-client-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-doc-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-plperl-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-plpython3-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-pltcl-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-server-dev-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"}],"resolute":[{"name":"postgresql-18","version":"18.4-0ubuntu0.26.04.1","description":"Object-relational SQL database","is_source":true},{"name":"libecpg-compat3","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libecpg-dev","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libecpg6","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libpgtypes3","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libpq-dev","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libpq-oauth","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libpq5","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-18-jit","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-client-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-doc-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-plperl-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-plpython3-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-pltcl-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-server-dev-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-6475","CVE-2026-6637","CVE-2026-6575","CVE-2026-6478","CVE-2026-6473","CVE-2026-6477","CVE-2026-6638","CVE-2026-6472","CVE-2026-6476","CVE-2026-6474","CVE-2026-6479"]},{"id":"USN-8653-1","title":"PostgreSQL vulnerabilities","summary":"Several security issues were fixed in PostgreSQL.","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart PostgreSQL to\nmake all the necessary changes.","references":[],"published":"2026-08-20T11:42:58.023934","description":"It was discovered that PostgreSQL incorrectly handled COPY FROM STDIN when\nan early failure occurred. An authenticated user could possibly use this\nissue to execute arbitrary SQL commands. (CVE-2026-6464)\n\nIt was discovered that PostgreSQL incorrectly reset extended statistics\nownership during ALTER TABLE ALTER TYPE operations. An attacker could\npossibly use this issue to obtain sensitive information or gain unintended\nprivileges. (CVE-2026-6469)\n\nIt was discovered that PostgreSQL failed to check the USAGE privilege on\ntypes. An authenticated user could possibly use this issue to obtain\nsensitive information. (CVE-2026-6470)\n\nIt was discovered that PostgreSQL logical decoding could load arbitrary\nshared libraries. An authenticated user could possibly use this issue to\nexecute arbitrary code. (CVE-2026-6471)\n\nIt was discovered that PostgreSQL had integer wraparound issues in tsvector\nand tsquery allocations. An authenticated user could possibly use this\nissue to execute arbitrary code. (CVE-2026-14662)\n\nIt was discovered that PostgreSQL pgcrypto silently used cleartext when\nOpenSSL-disabled ciphers were requested. An authenticated user could\npossibly use this issue to obtain sensitive information. (CVE-2026-14663)\n\nIt was discovered that PostgreSQL had a heap buffer overflow in regular\nexpression processing. An authenticated user could possibly use this issue\nto execute arbitrary code. (CVE-2026-14664)\n\nIt was discovered that PostgreSQL row security policies were not properly\ninvalidated when roles were modified. An attacker could possibly use this\nissue to bypass intended row security restrictions. (CVE-2026-14666)\n\nIt was discovered that PostgreSQL had a type confusion issue in the\nselectivity estimator involving ctid. An authenticated user could possibly\nuse this issue to obtain sensitive information. (CVE-2026-14668)\n\nIt was discovered that PostgreSQL had a heap buffer overflow in the to_char\nfunction. An authenticated user could possibly use this issue to execute\narbitrary code. (CVE-2026-14669)\n\nIt was discovered that PostgreSQL had a heap buffer overflow in the PL/Perl\ntied object handling. An authenticated user could possibly use this issue\nto execute arbitrary code. (CVE-2026-14670)\n\nIt was discovered that PostgreSQL had a type confusion issue in the\nreferential integrity plan cache. An authenticated user could possibly use\nthis issue to execute arbitrary code. (CVE-2026-14671)\n\nIt was discovered that PostgreSQL had an observable response discrepancy\nwhen non-default scram_iterations were used. A remote attacker could\npossibly use this issue to enumerate valid usernames. This issue only\naffected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-14672)\n\nIt was discovered that PostgreSQL amcheck did not clear untrusted search\npaths. An authenticated user could possibly use this issue to execute\narbitrary code. (CVE-2026-14673)\n\nIt was discovered that PostgreSQL had a heap buffer overflow in\npg_stat_statements. An authenticated user could possibly use this issue to\nexecute arbitrary code. This issue only affected Ubuntu 26.04 LTS.\n(CVE-2026-14676)\n\nIt was discovered that PostgreSQL had integer wraparound issues in PL/Tcl\nand PL/Perl allocations on 32-bit systems. An authenticated user could\npossibly use this issue to execute arbitrary code. (CVE-2026-14677)\n\nIt was discovered that PostgreSQL pg_trgm read past the end of a buffer\nduring picksplit operations. An authenticated user could possibly use this\nissue to obtain sensitive information. (CVE-2026-14678)\n\nIt was discovered that PostgreSQL had a stack buffer overflow in argument\nmatching. An authenticated user could possibly use this issue to corrupt\nserver memory. (CVE-2026-14679)\n\nIt was discovered that PostgreSQL had a type confusion issue when functions\nused internal arguments. An authenticated user could possibly use this\nissue to execute arbitrary code. (CVE-2026-14680)\n\nIt was discovered that PostgreSQL did not properly enforce GSSAPI\nencryption when used together with SSL. An attacker could possibly use this\nissue to perform a machine-in-the-middle attack and obtain sensitive\ninformation. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-14681)\n\nIt was discovered that PostgreSQL allowed SQL injection through EXTRACT\narguments during expression deparsing. An authenticated user could possibly\nuse this issue to perform SQL injection attacks. (CVE-2026-15741)\n\nIt was discovered that PostgreSQL fuzzystrmatch had integer wraparound\nissues that could write to arbitrary addresses. An authenticated user could\npossibly use this issue to execute arbitrary code. (CVE-2026-15742)\n\nIt was discovered that PostgreSQL had a type confusion issue in\npg_restore_attribute_stats(). An authenticated user could possibly use this\nissue to execute arbitrary code. This issue only affected Ubuntu 26.04 LTS.\n(CVE-2026-16238)\n\nIt was discovered that PostgreSQL had a type confusion issue when handling\ncursor CLOSE and DECLARE operations. An authenticated user could possibly\nuse this issue to execute arbitrary code. (CVE-2026-16239)\n\nIt was discovered that PostgreSQL had an integer underflow in the ECPG\nclient library. An attacker could possibly use this issue to cause\nPostgreSQL to crash, resulting in a denial of service. (CVE-2026-16241)\n\nIt was discovered that PostgreSQL had an out-of-bounds read in the ascii()\nfunction. An authenticated user could possibly use this issue to obtain\nsensitive information. (CVE-2026-18024)\n\nIt was discovered that the psql \\unrestrict command allowed the superuser\nof a pg_dump origin server to execute arbitrary code in the psql client. An\nattacker could possibly use this issue to execute arbitrary code.\n(CVE-2026-18408)\n\nIt was discovered that PostgreSQL pg_dump had a heap buffer overflow. An\nattacker could possibly use this issue to execute arbitrary code.\n(CVE-2026-19385)","is_hidden":false,"release_packages":{"jammy":[{"name":"postgresql-14","version":"14.24-0ubuntu0.22.04.1","description":"Object-relational SQL database","is_source":true},{"name":"libecpg-compat3","version":"14.24-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.24-0ubuntu0.22.04.1","pocket":"security"},{"name":"libecpg-dev","version":"14.24-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.24-0ubuntu0.22.04.1","pocket":"security"},{"name":"libecpg6","version":"14.24-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.24-0ubuntu0.22.04.1","pocket":"security"},{"name":"libpgtypes3","version":"14.24-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.24-0ubuntu0.22.04.1","pocket":"security"},{"name":"libpq-dev","version":"14.24-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.24-0ubuntu0.22.04.1","pocket":"security"},{"name":"libpq5","version":"14.24-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.24-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-14","version":"14.24-0ubuntu0.22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.24-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-client-14","version":"14.24-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.24-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-doc-14","version":"14.24-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.24-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-plperl-14","version":"14.24-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.24-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-plpython3-14","version":"14.24-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.24-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-pltcl-14","version":"14.24-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.24-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-server-dev-14","version":"14.24-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.24-0ubuntu0.22.04.1","pocket":"security"}],"noble":[{"name":"postgresql-16","version":"16.15-0ubuntu0.24.04.1","description":"Object-relational SQL database","is_source":true},{"name":"libecpg-compat3","version":"16.15-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.15-0ubuntu0.24.04.1","pocket":"security"},{"name":"libecpg-dev","version":"16.15-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.15-0ubuntu0.24.04.1","pocket":"security"},{"name":"libecpg6","version":"16.15-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.15-0ubuntu0.24.04.1","pocket":"security"},{"name":"libpgtypes3","version":"16.15-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.15-0ubuntu0.24.04.1","pocket":"security"},{"name":"libpq-dev","version":"16.15-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.15-0ubuntu0.24.04.1","pocket":"security"},{"name":"libpq5","version":"16.15-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.15-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-16","version":"16.15-0ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.15-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-client-16","version":"16.15-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.15-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-doc-16","version":"16.15-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.15-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-plperl-16","version":"16.15-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.15-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-plpython3-16","version":"16.15-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.15-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-pltcl-16","version":"16.15-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.15-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-server-dev-16","version":"16.15-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.15-0ubuntu0.24.04.1","pocket":"security"}],"resolute":[{"name":"postgresql-18","version":"18.6-0ubuntu0.26.04.1","description":"Object-relational SQL database","is_source":true},{"name":"libecpg-compat3","version":"18.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libecpg-dev","version":"18.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libecpg6","version":"18.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libpgtypes3","version":"18.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libpq-dev","version":"18.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libpq-oauth","version":"18.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"libpq5","version":"18.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-18","version":"18.6-0ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-18-jit","version":"18.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-client-18","version":"18.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-doc-18","version":"18.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-plperl-18","version":"18.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-plpython3-18","version":"18.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-pltcl-18","version":"18.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.6-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-server-dev-18","version":"18.6-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.6-0ubuntu0.26.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2025-8714","CVE-2026-14677","CVE-2026-14676","CVE-2026-15741","CVE-2026-16238","CVE-2026-6470","CVE-2026-14680","CVE-2026-14678","CVE-2026-19385","CVE-2026-6471","CVE-2026-6473","CVE-2026-14671","CVE-2026-14666","CVE-2026-14664","CVE-2026-14663","CVE-2026-14669","CVE-2026-14672","CVE-2026-16241","CVE-2026-6464","CVE-2026-14668","CVE-2026-18408","CVE-2026-16239","CVE-2026-14673","CVE-2026-14662","CVE-2026-14679","CVE-2026-18024","CVE-2026-14681","CVE-2026-6469","CVE-2026-14670","CVE-2026-15742"]}]},{"id":"CVE-2026-6472","published":"2026-05-14T14:16:00","updated_at":"2026-05-22T18:08:06.998027+00:00","description":"\nMissing authorization in PostgreSQL CREATE TYPE allows an object creator to\nhijack other queries that use search_path to find user-defined types,\nincluding extension-defined types. That is to say, the victim will execute\narbitrary SQL functions of the attacker's choice. Versions before\nPostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.","ubuntu_description":"","notes":[{"author":"leosilva","note":"PostgreSQL 9.3 is end of life upstream, and no updates are\nare available. Marking as deferred in -esm-main releases.\nPostgreSQL 9.3 is end of life upstream, and no updates are\nare available. Marking as deferred in -esm-main releases."}],"codename":null,"priority":"medium","cvss3":5.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-6472","https://www.postgresql.org/about/news/postgresql-184-1710-1614-1518-and-1423-released-3297/","https://www.postgresql.org/support/security/CVE-2026-6472/","https://ubuntu.com/security/notices/USN-8294-1"],"bugs":[""],"patches":{"postgresql-18":[],"postgresql-17":[],"postgresql-16":[],"postgresql-14":[],"postgresql-12":[],"postgresql-10":[],"postgresql-9.5":[],"postgresql-9.3":[]},"tags":{},"packages":[{"name":"postgresql-10","source":"https://ubuntu.com/security/cve?package=postgresql-10","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-10","debian":"https://tracker.debian.org/pkg/postgresql-10","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"postgresql-12","source":"https://ubuntu.com/security/cve?package=postgresql-12","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-12","debian":"https://tracker.debian.org/pkg/postgresql-12","statuses":[{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"postgresql-14","source":"https://ubuntu.com/security/cve?package=postgresql-14","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-14","debian":"https://tracker.debian.org/pkg/postgresql-14","statuses":[{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"14.23-0ubuntu0.22.04.1","component":null,"pocket":"security"}]},{"name":"postgresql-16","source":"https://ubuntu.com/security/cve?package=postgresql-16","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-16","debian":"https://tracker.debian.org/pkg/postgresql-16","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"16.14-0ubuntu0.24.04.1","component":null,"pocket":"security"}]},{"name":"postgresql-17","source":"https://ubuntu.com/security/cve?package=postgresql-17","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-17","debian":"https://tracker.debian.org/pkg/postgresql-17","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"17.10-0ubuntu0.25.10.1","component":null,"pocket":"security"}]},{"name":"postgresql-18","source":"https://ubuntu.com/security/cve?package=postgresql-18","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-18","debian":"https://tracker.debian.org/pkg/postgresql-18","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"18.4-0ubuntu0.26.04.1","component":null,"pocket":"security"}]},{"name":"postgresql-9.3","source":"https://ubuntu.com/security/cve?package=postgresql-9.3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-9.3","debian":"https://tracker.debian.org/pkg/postgresql-9.3","statuses":[{"release_codename":"trusty","status":"deferred","description":"2019-08-23","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"postgresql-9.5","source":"https://ubuntu.com/security/cve?package=postgresql-9.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-9.5","debian":"https://tracker.debian.org/pkg/postgresql-9.5","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":["USN-8294-1"],"notices":[{"id":"USN-8294-1","title":"PostgreSQL vulnerabilities","summary":"Several security issues were fixed in PostgreSQL.","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart PostgreSQL to\nmake all the necessary changes.","references":[],"published":"2026-05-21T20:39:48.706022","description":"It was discovered that PostgreSQL did not correctly enforce authorization\nfor CREATE TYPE. An attacker could possibly use this issue to execute\narbitrary SQL functions. (CVE-2026-6472)\n\nIt was discovered that PostgreSQL incorrectly handled large user input in\nmultiple server features. An attacker could possibly use this issue to\ncause PostgreSQL to crash, resulting in a denial of service, or execute\narbitrary code. (CVE-2026-6473)\n\nIt was discovered that PostgreSQL incorrectly handled format strings in\nthe timeofday() function. An attacker could possibly use this issue to\nobtain sensitive information. (CVE-2026-6474)\n\nIt was discovered that PostgreSQL incorrectly followed symbolic links in\npg_basebackup and pg_rewind. An attacker could possibly use this issue to\noverwrite local files and execute arbitrary code. (CVE-2026-6475)\n\nIt was discovered that PostgreSQL had an SQL injection vulnerability in\npg_createsubscriber. An attacker could possibly use this issue to execute\narbitrary SQL as a superuser. This issue only affected Ubuntu 25.10 and\nUbuntu 26.04 LTS. (CVE-2026-6476)\n\nIt was discovered that PostgreSQL used an unsafe libpq function in large\nobject operations. An attacker could possibly use this issue to overwrite\nclient memory and execute arbitrary code. (CVE-2026-6477)\n\nIt was discovered that PostgreSQL did not compare MD5-hashed passwords in\nconstant time. An attacker could possibly use this issue to obtain\nsensitive information. (CVE-2026-6478)\n\nIt was discovered that PostgreSQL had uncontrolled recursion during SSL and\nGSS negotiation. An attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-6479)\n\nIt was discovered that PostgreSQL incorrectly handled array length\nmismatches in pg_restore_attribute_stats(). An attacker could possibly use\nthis issue to obtain sensitive information. This issue only affected Ubuntu\n26.04 LTS. (CVE-2026-6575)\n\nIt was discovered that PostgreSQL had a stack buffer overflow in the refint\nmodule. An attacker could use this issue to cause PostgreSQL to crash,\nresulting in a denial of service, or possibly execute arbitrary code.\n(CVE-2026-6637)\n\nIt was discovered that PostgreSQL had an SQL injection vulnerability in\nlogical replication REFRESH PUBLICATION. An attacker could possibly use\nthis issue to execute arbitrary SQL. This issue only affected Ubuntu 24.04\nLTS, Ubuntu 25.10, and Ubuntu 26.04 LTS. (CVE-2026-6638)","is_hidden":false,"release_packages":{"jammy":[{"name":"postgresql-14","version":"14.23-0ubuntu0.22.04.1","description":"Object-relational SQL database","is_source":true},{"name":"libecpg-compat3","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"libecpg-dev","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"libecpg6","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"libpgtypes3","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"libpq-dev","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"libpq5","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-client-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-doc-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-plperl-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-plpython3-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-pltcl-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-server-dev-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"}],"noble":[{"name":"postgresql-16","version":"16.14-0ubuntu0.24.04.1","description":"Object-relational SQL database","is_source":true},{"name":"libecpg-compat3","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"libecpg-dev","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"libecpg6","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"libpgtypes3","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"libpq-dev","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"libpq5","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-client-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-doc-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-plperl-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-plpython3-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-pltcl-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-server-dev-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"}],"questing":[{"name":"postgresql-17","version":"17.10-0ubuntu0.25.10.1","description":"Object-relational SQL database","is_source":true},{"name":"libecpg-compat3","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"libecpg-dev","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"libecpg6","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"libpgtypes3","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"libpq-dev","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"libpq5","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-client-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-doc-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-plperl-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-plpython3-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-pltcl-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-server-dev-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"}],"resolute":[{"name":"postgresql-18","version":"18.4-0ubuntu0.26.04.1","description":"Object-relational SQL database","is_source":true},{"name":"libecpg-compat3","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libecpg-dev","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libecpg6","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libpgtypes3","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libpq-dev","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libpq-oauth","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libpq5","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-18-jit","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-client-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-doc-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-plperl-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-plpython3-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-pltcl-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-server-dev-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-6475","CVE-2026-6637","CVE-2026-6575","CVE-2026-6478","CVE-2026-6473","CVE-2026-6477","CVE-2026-6638","CVE-2026-6472","CVE-2026-6476","CVE-2026-6474","CVE-2026-6479"]}]},{"id":"CVE-2026-45205","published":"2026-05-14T12:16:00","updated_at":"2026-05-21T11:58:35.836070+00:00","description":"\nUncontrolled Recursion vulnerability in Apache Commons.\nWhen processing an untrusted configuration file, Commons Configuration will\nthrow a StackOverflowError for YAML input with cycles.\nThis issue affects Apache Commons: from 2.2 before 2.15.0.\nUsers are recommended to upgrade to version 2.15.0, which fixes the issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-45205","https://www.openwall.com/lists/oss-security/2026/05/14/5","https://github.com/apache/commons-configuration/pull/634","https://github.com/apache/commons-configuration/commit/b51f6bf26e774f3416fdf782a5e1edf33f32ba82 (commons-configuration-2.15.0-RC1)","https://lists.apache.org/thread/q3q3j10ohcqhs6o0rg1v7kz6kk27vtkk","http://www.openwall.com/lists/oss-security/2026/05/14/5"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1136705"],"patches":{"commons-configuration":[],"commons-configuration2":[]},"tags":{},"packages":[{"name":"commons-configuration","source":"https://ubuntu.com/security/cve?package=commons-configuration","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=commons-configuration","debian":"https://tracker.debian.org/pkg/commons-configuration","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"debian: Vulnerable code not present","component":null,"pocket":"security"}]},{"name":"commons-configuration2","source":"https://ubuntu.com/security/cve?package=commons-configuration2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=commons-configuration2","debian":"https://tracker.debian.org/pkg/commons-configuration2","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-8280","published":"2026-05-14T06:16:00","updated_at":"2026-05-22T22:59:46.506110+00:00","description":"\nGitLab has remediated an issue in GitLab CE/EE affecting all versions from\n8.3 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that\ncould have allowed an authenticated user to cause denial of service through\nexcessive memory consumption due to improper input validation.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"GitLab isn't maintainable as a distro package, and was removed\nfrom Ubuntu because of this. We will not be fixing security\nissues in the gitlab package in Xenial."}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-8280","https://about.gitlab.com/releases/2026/05/13/patch-release-gitlab-18-11-3-released/","https://gitlab.com/gitlab-org/gitlab/-/work_items/579035","https://hackerone.com/reports/3329085"],"bugs":[""],"patches":{"gitlab":[]},"tags":{},"packages":[{"name":"gitlab","source":"https://ubuntu.com/security/cve?package=gitlab","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gitlab","debian":"https://tracker.debian.org/pkg/gitlab","statuses":[{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-8144","published":"2026-05-14T06:16:00","updated_at":"2026-05-22T22:59:46.506110+00:00","description":"\nGitLab has remediated an issue in GitLab CE/EE affecting all versions from\n15.1 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that\ncould have allowed an authenticated user with project membership to\nenumerate private group members due to missing authorization checks.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"GitLab isn't maintainable as a distro package, and was removed\nfrom Ubuntu because of this. We will not be fixing security\nissues in the gitlab package in Xenial."}],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-8144","https://about.gitlab.com/releases/2026/05/13/patch-release-gitlab-18-11-3-released/","https://gitlab.com/gitlab-org/gitlab/-/work_items/591964"],"bugs":[""],"patches":{"gitlab":[]},"tags":{},"packages":[{"name":"gitlab","source":"https://ubuntu.com/security/cve?package=gitlab","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gitlab","debian":"https://tracker.debian.org/pkg/gitlab","statuses":[{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-7481","published":"2026-05-14T06:16:00","updated_at":"2026-05-22T22:59:16.012929+00:00","description":"\nGitLab has remediated an issue in GitLab EE affecting all versions from\n16.4 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that\ncould have allowed an authenticated user with developer-role permissions to\nexecute arbitrary JavaScript in other users' browsers due to improper input\nsanitization.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"GitLab isn't maintainable as a distro package, and was removed\nfrom Ubuntu because of this. We will not be fixing security\nissues in the gitlab package in Xenial."}],"codename":null,"priority":"medium","cvss3":8.7,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":8.7,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-7481","https://about.gitlab.com/releases/2026/05/13/patch-release-gitlab-18-11-3-released/","https://gitlab.com/gitlab-org/gitlab/-/work_items/598646","https://hackerone.com/reports/3697379"],"bugs":[""],"patches":{"gitlab":[]},"tags":{},"packages":[{"name":"gitlab","source":"https://ubuntu.com/security/cve?package=gitlab","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gitlab","debian":"https://tracker.debian.org/pkg/gitlab","statuses":[{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"debian: Only affects Gitlab EE","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-7471","published":"2026-05-14T06:16:00","updated_at":"2026-05-21T14:45:25.073560+00:00","description":"\nGitLab has remediated an issue in GitLab EE affecting all versions from\n18.8 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that\ncould have allowed an authenticated user with control of a virtual registry\nupstream to make requests to internal hosts due to improper validation.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"GitLab isn't maintainable as a distro package, and was removed\nfrom Ubuntu because of this. We will not be fixing security\nissues in the gitlab package in Xenial."}],"codename":null,"priority":"medium","cvss3":3.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":3.5,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-7471","https://about.gitlab.com/releases/2026/05/13/patch-release-gitlab-18-11-3-released/","https://gitlab.com/gitlab-org/gitlab/-/work_items/594196"],"bugs":[""],"patches":{"gitlab":[]},"tags":{},"packages":[{"name":"gitlab","source":"https://ubuntu.com/security/cve?package=gitlab","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gitlab","debian":"https://tracker.debian.org/pkg/gitlab","statuses":[{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"debian: Only affects Gitlab EE","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-7377","published":"2026-05-14T06:16:00","updated_at":"2026-05-22T22:59:16.012929+00:00","description":"\nGitLab has remediated an issue in GitLab EE affecting all versions from\n18.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that, in\ncustomizable analytics dashboards, could have allowed an authenticated user\nto execute arbitrary JavaScript in the context of other users' browsers due\nto improper input sanitization.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"GitLab isn't maintainable as a distro package, and was removed\nfrom Ubuntu because of this. We will not be fixing security\nissues in the gitlab package in Xenial."}],"codename":null,"priority":"medium","cvss3":8.7,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":8.7,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-7377","https://about.gitlab.com/releases/2026/05/13/patch-release-gitlab-18-11-3-released/","https://gitlab.com/gitlab-org/gitlab/-/work_items/598497","https://hackerone.com/reports/3659044"],"bugs":[""],"patches":{"gitlab":[]},"tags":{},"packages":[{"name":"gitlab","source":"https://ubuntu.com/security/cve?package=gitlab","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gitlab","debian":"https://tracker.debian.org/pkg/gitlab","statuses":[{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"debian: Only affects Gitlab EE","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-6883","published":"2026-05-14T06:16:00","updated_at":"2026-05-22T22:58:37.770996+00:00","description":"\nGitLab has remediated an issue in GitLab EE affecting all versions from\n15.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that\ncould have allowed an authenticated user to bypass merge request approval\nrequirements due to improper cleanup of orphaned policy records.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"GitLab isn't maintainable as a distro package, and was removed\nfrom Ubuntu because of this. We will not be fixing security\nissues in the gitlab package in Xenial."}],"codename":null,"priority":"medium","cvss3":2.6,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":2.6,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-6883","https://about.gitlab.com/releases/2026/05/13/patch-release-gitlab-18-11-3-released/","https://gitlab.com/gitlab-org/gitlab/-/work_items/596350"],"bugs":[""],"patches":{"gitlab":[]},"tags":{},"packages":[{"name":"gitlab","source":"https://ubuntu.com/security/cve?package=gitlab","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gitlab","debian":"https://tracker.debian.org/pkg/gitlab","statuses":[{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"debian: Only affects Gitlab EE","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-6335","published":"2026-05-14T06:16:00","updated_at":"2026-05-21T07:33:36.916239+00:00","description":"\nGitLab has remediated an issue in GitLab CE/EE affecting all versions from\n18.11 before 18.11.3 that under certain conditions could have allowed an\nauthenticated user to execute arbitrary code in another user's browser\nsession due to improper sanitization.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"GitLab isn't maintainable as a distro package, and was removed\nfrom Ubuntu because of this. We will not be fixing security\nissues in the gitlab package in Xenial."}],"codename":null,"priority":"medium","cvss3":5.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-6335","https://about.gitlab.com/releases/2026/05/13/patch-release-gitlab-18-11-3-released/","https://gitlab.com/gitlab-org/gitlab/-/work_items/596760","https://hackerone.com/reports/3673647"],"bugs":[""],"patches":{"gitlab":[]},"tags":{},"packages":[{"name":"gitlab","source":"https://ubuntu.com/security/cve?package=gitlab","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gitlab","debian":"https://tracker.debian.org/pkg/gitlab","statuses":[{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"debian: Vulnerable code not present","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-6073","published":"2026-05-14T06:16:00","updated_at":"2026-05-22T22:57:40.664583+00:00","description":"\nGitLab has remediated an issue in GitLab EE affecting all versions from\n18.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that\ncould have allowed an authenticated user to execute arbitrary JavaScript in\nother users' browsers due to improper input sanitization.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"GitLab isn't maintainable as a distro package, and was removed\nfrom Ubuntu because of this. We will not be fixing security\nissues in the gitlab package in Xenial."}],"codename":null,"priority":"medium","cvss3":8.7,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":8.7,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-6073","https://about.gitlab.com/releases/2026/05/13/patch-release-gitlab-18-11-3-released/","https://gitlab.com/gitlab-org/gitlab/-/work_items/596340","https://hackerone.com/reports/3655677"],"bugs":[""],"patches":{"gitlab":[]},"tags":{},"packages":[{"name":"gitlab","source":"https://ubuntu.com/security/cve?package=gitlab","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gitlab","debian":"https://tracker.debian.org/pkg/gitlab","statuses":[{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"debian: Only affects Gitlab EE","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-6063","published":"2026-05-14T06:16:00","updated_at":"2026-05-22T22:58:37.770996+00:00","description":"\nGitLab has remediated an issue in GitLab EE affecting all versions from\n11.10 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that\nunder certain conditions could have allowed an authenticated user with\ndeveloper-role permissions to remove code owner approval rules from merge\nrequests due to improper access control.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"GitLab isn't maintainable as a distro package, and was removed\nfrom Ubuntu because of this. We will not be fixing security\nissues in the gitlab package in Xenial."}],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-6063","https://about.gitlab.com/releases/2026/05/13/patch-release-gitlab-18-11-3-released/","https://gitlab.com/gitlab-org/gitlab/-/work_items/596332","https://hackerone.com/reports/3649087"],"bugs":[""],"patches":{"gitlab":[]},"tags":{},"packages":[{"name":"gitlab","source":"https://ubuntu.com/security/cve?package=gitlab","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gitlab","debian":"https://tracker.debian.org/pkg/gitlab","statuses":[{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"debian: Only affects Gitlab EE","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-4527","published":"2026-05-14T06:16:00","updated_at":"2026-05-22T22:57:59.365981+00:00","description":"\nGitLab has remediated an issue in GitLab CE/EE affecting all versions from\n11.10 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that\ncould have allowed an unauthenticated user to create unauthorized Jira\nsubscriptions for a targeted user's namespace via a specially crafted link\ndue to missing CSRF protection.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"GitLab isn't maintainable as a distro package, and was removed\nfrom Ubuntu because of this. We will not be fixing security\nissues in the gitlab package in Xenial."}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-4527","https://about.gitlab.com/releases/2026/05/13/patch-release-gitlab-18-11-3-released/","https://gitlab.com/gitlab-org/gitlab/-/work_items/594339","https://hackerone.com/reports/3590487"],"bugs":[""],"patches":{"gitlab":[]},"tags":{},"packages":[{"name":"gitlab","source":"https://ubuntu.com/security/cve?package=gitlab","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gitlab","debian":"https://tracker.debian.org/pkg/gitlab","statuses":[{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-4524","published":"2026-05-14T06:16:00","updated_at":"2026-05-22T22:57:40.664583+00:00","description":"\nGitLab has remediated an issue in GitLab CE/EE affecting all versions from\n18.9.1 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that\ncould have allowed an authenticated user to access confidential issue\ncontent in public projects without proper authorization due to improper\nauthorization checks.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"GitLab isn't maintainable as a distro package, and was removed\nfrom Ubuntu because of this. We will not be fixing security\nissues in the gitlab package in Xenial."}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-4524","https://about.gitlab.com/releases/2026/05/13/patch-release-gitlab-18-11-3-released/","https://gitlab.com/gitlab-org/gitlab/-/work_items/594295","https://hackerone.com/reports/3597717"],"bugs":[""],"patches":{"gitlab":[]},"tags":{},"packages":[{"name":"gitlab","source":"https://ubuntu.com/security/cve?package=gitlab","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gitlab","debian":"https://tracker.debian.org/pkg/gitlab","statuses":[{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"debian: Vulnerable code not present","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":11640,"limit":20,"total_results":79316}