Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

Release postgresql-16.15-1.el10_2 ALSA-2026:70186

Chiusa
#3,633 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
5/5
Tempo stimato
Più di una settimana
Idoneità per principianti
20/100
Tipo di issue
Bug
Chiarezza
Specificata chiaramente
Stato di attività
Attiva
Stack tecnologico
postgresql

Direzione di ricerca

This is a security release announcement for PostgreSQL 16.15-1.el10_2, listing multiple CVEs. The work involves patching the PostgreSQL source code for each vulnerability, testing the fixes, and building RPM packages for multiple architectures. Start by examining the upstream PostgreSQL security patches for each CVE, then apply them to the AlmaLinux packaging tree. Verify the build process and run the test suite. 'Done' means all listed packages are built and the security fixes are verified.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

postgresql16 security update
Severity: Important
Description
PostgreSQL is an advanced Object-Relational database management system (DBMS). The base postgresql package contains the client programs that you'll need to access a PostgreSQL DBMS server, as well as HTML documentation for the whole system. These client programs can be located on the same machine as the PostgreSQL server, or on a remote machine that accesses a PostgreSQL server over a network connection. The PostgreSQL server can be found in the postgresql-server sub-package.

Security Fix(es):

  • postgresql: PostgreSQL: Arbitrary code execution via integer wraparound in tsvector and tsquery functions (CVE-2026-14662)
  • postgresql: PostgreSQL: Arbitrary code execution via untrusted data inclusion in pg_dump (CVE-2026-18408)
  • postgresql: PostgreSQL psql: Arbitrary command execution via untrusted data in COPY FROM STDIN (CVE-2026-6464)
  • postgresql: PostgreSQL: Arbitrary code execution via logical decoding plugin (CVE-2026-6471)
  • postgresql: PostgreSQL: Arbitrary code execution via type confusion with "internal" arguments (CVE-2026-14680)
  • postgresql: PostgreSQL: Arbitrary code execution via heap buffer overflow in regexp (CVE-2026-14664)
  • postgresql: pltcl: plperl: PostgreSQL: Arbitrary code execution in 32-bit pltcl and plperl (CVE-2026-14677)
  • postgresql-fuzzystrmatch: PostgreSQL fuzzystrmatch: Arbitrary code execution via integer wraparound (CVE-2026-15742)
  • postgresql: PostgreSQL: Arbitrary code execution via type confusion in cursor lifecycle (CVE-2026-16239)
  • postgresql: PostgreSQL: Arbitrary code execution via long POSIX timezone abbreviation (CVE-2026-14669)
  • postgresql: PostgreSQL: Stack buffer overflow via OUT parameter count manipulation (CVE-2026-14679)
  • postgresql: PostgreSQL: Arbitrary code execution via type confusion in 'refint' module (CVE-2026-14671)
  • postgresql: PostgreSQL: Arbitrary code execution via plperl tied hash heap buffer overflow (CVE-2026-14670)
  • postgresql: PostgreSQL: Information disclosure via type confusion in ctid selectivity estimator (CVE-2026-14668)
  • postgresql: PostgreSQL pg_dump: Arbitrary code execution via crafted transform lists (CVE-2026-19385)
  • postgresql: PostgreSQL: Privilege escalation via SQL injection in EXTRACT() deparse (CVE-2026-15741)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Affected packages:
postgresql-16.15-1.el10_2.x86_64
postgresql-contrib-16.15-1.el10_2.x86_64
postgresql-docs-16.15-1.el10_2.x86_64
postgresql-plperl-16.15-1.el10_2.x86_64
postgresql-plpython3-16.15-1.el10_2.x86_64
postgresql-pltcl-16.15-1.el10_2.x86_64
postgresql-private-devel-16.15-1.el10_2.x86_64
postgresql-private-libs-16.15-1.el10_2.x86_64
postgresql-server-16.15-1.el10_2.x86_64
postgresql-server-devel-16.15-1.el10_2.x86_64
postgresql-static-16.15-1.el10_2.x86_64
postgresql-test-16.15-1.el10_2.x86_64
postgresql-upgrade-16.15-1.el10_2.x86_64
postgresql-upgrade-devel-16.15-1.el10_2.x86_64
postgresql-16.15-1.el10_2.s390x
postgresql-contrib-16.15-1.el10_2.s390x
postgresql-docs-16.15-1.el10_2.s390x
postgresql-plperl-16.15-1.el10_2.s390x
postgresql-plpython3-16.15-1.el10_2.s390x
postgresql-pltcl-16.15-1.el10_2.s390x
postgresql-private-devel-16.15-1.el10_2.s390x
postgresql-private-libs-16.15-1.el10_2.s390x
postgresql-server-16.15-1.el10_2.s390x
postgresql-server-devel-16.15-1.el10_2.s390x
postgresql-static-16.15-1.el10_2.s390x
postgresql-test-16.15-1.el10_2.s390x
postgresql-upgrade-16.15-1.el10_2.s390x
postgresql-upgrade-devel-16.15-1.el10_2.s390x
postgresql-16.15-1.el10_2.ppc64le
postgresql-contrib-16.15-1.el10_2.ppc64le
postgresql-docs-16.15-1.el10_2.ppc64le
postgresql-plperl-16.15-1.el10_2.ppc64le
postgresql-plpython3-16.15-1.el10_2.ppc64le
postgresql-pltcl-16.15-1.el10_2.ppc64le
postgresql-private-devel-16.15-1.el10_2.ppc64le
postgresql-private-libs-16.15-1.el10_2.ppc64le
postgresql-server-16.15-1.el10_2.ppc64le
postgresql-server-devel-16.15-1.el10_2.ppc64le
postgresql-static-16.15-1.el10_2.ppc64le
postgresql-test-16.15-1.el10_2.ppc64le
postgresql-upgrade-16.15-1.el10_2.ppc64le
postgresql-upgrade-devel-16.15-1.el10_2.ppc64le
postgresql-16.15-1.el10_2.aarch64
postgresql-contrib-16.15-1.el10_2.aarch64
postgresql-docs-16.15-1.el10_2.aarch64
postgresql-plperl-16.15-1.el10_2.aarch64
postgresql-plpython3-16.15-1.el10_2.aarch64
postgresql-pltcl-16.15-1.el10_2.aarch64
postgresql-private-devel-16.15-1.el10_2.aarch64
postgresql-private-libs-16.15-1.el10_2.aarch64
postgresql-server-16.15-1.el10_2.aarch64
postgresql-server-devel-16.15-1.el10_2.aarch64
postgresql-static-16.15-1.el10_2.aarch64
postgresql-test-16.15-1.el10_2.aarch64
postgresql-upgrade-16.15-1.el10_2.aarch64
postgresql-upgrade-devel-16.15-1.el10_2.aarch64
postgresql-test-rpm-macros-16.15-1.el10_2.noarch
postgresql-test-rpm-macros-16.15-1.el10_2.noarch
postgresql-test-rpm-macros-16.15-1.el10_2.noarch
postgresql-test-rpm-macros-16.15-1.el10_2.noarch
postgresql-16.15-1.el10_2.x86_64_v2
postgresql-contrib-16.15-1.el10_2.x86_64_v2
postgresql-docs-16.15-1.el10_2.x86_64_v2
postgresql-plperl-16.15-1.el10_2.x86_64_v2
postgresql-plpython3-16.15-1.el10_2.x86_64_v2
postgresql-pltcl-16.15-1.el10_2.x86_64_v2
postgresql-private-devel-16.15-1.el10_2.x86_64_v2
postgresql-private-libs-16.15-1.el10_2.x86_64_v2
postgresql-server-16.15-1.el10_2.x86_64_v2
postgresql-server-devel-16.15-1.el10_2.x86_64_v2
postgresql-static-16.15-1.el10_2.x86_64_v2
postgresql-test-16.15-1.el10_2.x86_64_v2
postgresql-upgrade-16.15-1.el10_2.x86_64_v2
postgresql-upgrade-devel-16.15-1.el10_2.x86_64_v2
postgresql-test-rpm-macros-16.15-1.el10_2.noarch

Lingua principale
Nessun dato sulla lingua
Stelle
2
Fork
0
Metriche di merge delle PR
Nessuna PR unita negli ultimi 30g

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di AlmaLinux/updates

Tutte le issue di AlmaLinux/updates

Issue simili

Altre issue su Databases

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.