Release postgresql-16.15-1.el10_2 ALSA-2026:70186
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 5/5
- Tempo stimato
- Più di una settimana
- Idoneità per principianti
- 20/100
Direzione di ricerca
This is a security release announcement for PostgreSQL 16.15-1.el10_2, listing multiple CVEs. The work involves patching the PostgreSQL source code for each vulnerability, testing the fixes, and building RPM packages for multiple architectures. Start by examining the upstream PostgreSQL security patches for each CVE, then apply them to the AlmaLinux packaging tree. Verify the build process and run the test suite. 'Done' means all listed packages are built and the security fixes are verified.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
postgresql16 security update
Severity: Important
Description
PostgreSQL is an advanced Object-Relational database management system (DBMS). The base postgresql package contains the client programs that you'll need to access a PostgreSQL DBMS server, as well as HTML documentation for the whole system. These client programs can be located on the same machine as the PostgreSQL server, or on a remote machine that accesses a PostgreSQL server over a network connection. The PostgreSQL server can be found in the postgresql-server sub-package.
Security Fix(es):
- postgresql: PostgreSQL: Arbitrary code execution via integer wraparound in tsvector and tsquery functions (CVE-2026-14662)
- postgresql: PostgreSQL: Arbitrary code execution via untrusted data inclusion in pg_dump (CVE-2026-18408)
- postgresql: PostgreSQL psql: Arbitrary command execution via untrusted data in COPY FROM STDIN (CVE-2026-6464)
- postgresql: PostgreSQL: Arbitrary code execution via logical decoding plugin (CVE-2026-6471)
- postgresql: PostgreSQL: Arbitrary code execution via type confusion with "internal" arguments (CVE-2026-14680)
- postgresql: PostgreSQL: Arbitrary code execution via heap buffer overflow in regexp (CVE-2026-14664)
- postgresql: pltcl: plperl: PostgreSQL: Arbitrary code execution in 32-bit pltcl and plperl (CVE-2026-14677)
- postgresql-fuzzystrmatch: PostgreSQL fuzzystrmatch: Arbitrary code execution via integer wraparound (CVE-2026-15742)
- postgresql: PostgreSQL: Arbitrary code execution via type confusion in cursor lifecycle (CVE-2026-16239)
- postgresql: PostgreSQL: Arbitrary code execution via long POSIX timezone abbreviation (CVE-2026-14669)
- postgresql: PostgreSQL: Stack buffer overflow via OUT parameter count manipulation (CVE-2026-14679)
- postgresql: PostgreSQL: Arbitrary code execution via type confusion in 'refint' module (CVE-2026-14671)
- postgresql: PostgreSQL: Arbitrary code execution via plperl tied hash heap buffer overflow (CVE-2026-14670)
- postgresql: PostgreSQL: Information disclosure via type confusion in ctid selectivity estimator (CVE-2026-14668)
- postgresql: PostgreSQL pg_dump: Arbitrary code execution via crafted transform lists (CVE-2026-19385)
- postgresql: PostgreSQL: Privilege escalation via SQL injection in EXTRACT() deparse (CVE-2026-15741)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected packages:
postgresql-16.15-1.el10_2.x86_64
postgresql-contrib-16.15-1.el10_2.x86_64
postgresql-docs-16.15-1.el10_2.x86_64
postgresql-plperl-16.15-1.el10_2.x86_64
postgresql-plpython3-16.15-1.el10_2.x86_64
postgresql-pltcl-16.15-1.el10_2.x86_64
postgresql-private-devel-16.15-1.el10_2.x86_64
postgresql-private-libs-16.15-1.el10_2.x86_64
postgresql-server-16.15-1.el10_2.x86_64
postgresql-server-devel-16.15-1.el10_2.x86_64
postgresql-static-16.15-1.el10_2.x86_64
postgresql-test-16.15-1.el10_2.x86_64
postgresql-upgrade-16.15-1.el10_2.x86_64
postgresql-upgrade-devel-16.15-1.el10_2.x86_64
postgresql-16.15-1.el10_2.s390x
postgresql-contrib-16.15-1.el10_2.s390x
postgresql-docs-16.15-1.el10_2.s390x
postgresql-plperl-16.15-1.el10_2.s390x
postgresql-plpython3-16.15-1.el10_2.s390x
postgresql-pltcl-16.15-1.el10_2.s390x
postgresql-private-devel-16.15-1.el10_2.s390x
postgresql-private-libs-16.15-1.el10_2.s390x
postgresql-server-16.15-1.el10_2.s390x
postgresql-server-devel-16.15-1.el10_2.s390x
postgresql-static-16.15-1.el10_2.s390x
postgresql-test-16.15-1.el10_2.s390x
postgresql-upgrade-16.15-1.el10_2.s390x
postgresql-upgrade-devel-16.15-1.el10_2.s390x
postgresql-16.15-1.el10_2.ppc64le
postgresql-contrib-16.15-1.el10_2.ppc64le
postgresql-docs-16.15-1.el10_2.ppc64le
postgresql-plperl-16.15-1.el10_2.ppc64le
postgresql-plpython3-16.15-1.el10_2.ppc64le
postgresql-pltcl-16.15-1.el10_2.ppc64le
postgresql-private-devel-16.15-1.el10_2.ppc64le
postgresql-private-libs-16.15-1.el10_2.ppc64le
postgresql-server-16.15-1.el10_2.ppc64le
postgresql-server-devel-16.15-1.el10_2.ppc64le
postgresql-static-16.15-1.el10_2.ppc64le
postgresql-test-16.15-1.el10_2.ppc64le
postgresql-upgrade-16.15-1.el10_2.ppc64le
postgresql-upgrade-devel-16.15-1.el10_2.ppc64le
postgresql-16.15-1.el10_2.aarch64
postgresql-contrib-16.15-1.el10_2.aarch64
postgresql-docs-16.15-1.el10_2.aarch64
postgresql-plperl-16.15-1.el10_2.aarch64
postgresql-plpython3-16.15-1.el10_2.aarch64
postgresql-pltcl-16.15-1.el10_2.aarch64
postgresql-private-devel-16.15-1.el10_2.aarch64
postgresql-private-libs-16.15-1.el10_2.aarch64
postgresql-server-16.15-1.el10_2.aarch64
postgresql-server-devel-16.15-1.el10_2.aarch64
postgresql-static-16.15-1.el10_2.aarch64
postgresql-test-16.15-1.el10_2.aarch64
postgresql-upgrade-16.15-1.el10_2.aarch64
postgresql-upgrade-devel-16.15-1.el10_2.aarch64
postgresql-test-rpm-macros-16.15-1.el10_2.noarch
postgresql-test-rpm-macros-16.15-1.el10_2.noarch
postgresql-test-rpm-macros-16.15-1.el10_2.noarch
postgresql-test-rpm-macros-16.15-1.el10_2.noarch
postgresql-16.15-1.el10_2.x86_64_v2
postgresql-contrib-16.15-1.el10_2.x86_64_v2
postgresql-docs-16.15-1.el10_2.x86_64_v2
postgresql-plperl-16.15-1.el10_2.x86_64_v2
postgresql-plpython3-16.15-1.el10_2.x86_64_v2
postgresql-pltcl-16.15-1.el10_2.x86_64_v2
postgresql-private-devel-16.15-1.el10_2.x86_64_v2
postgresql-private-libs-16.15-1.el10_2.x86_64_v2
postgresql-server-16.15-1.el10_2.x86_64_v2
postgresql-server-devel-16.15-1.el10_2.x86_64_v2
postgresql-static-16.15-1.el10_2.x86_64_v2
postgresql-test-16.15-1.el10_2.x86_64_v2
postgresql-upgrade-16.15-1.el10_2.x86_64_v2
postgresql-upgrade-devel-16.15-1.el10_2.x86_64_v2
postgresql-test-rpm-macros-16.15-1.el10_2.noarch
- Lingua principale
- Nessun dato sulla lingua
- Stelle
- 2
- Fork
- 0
- Metriche di merge delle PR
- Nessuna PR unita negli ultimi 30g
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Nessun modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di AlmaLinux/updates
-
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 85/100
-
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 60/100
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 62/100
-
Difficoltà 5/5 Più di una settimana Idoneità per principianti 4/100
-
Difficoltà 5/5 Più di una settimana Idoneità per principianti 5/100
Tutte le issue di AlmaLinux/updates
Issue simili
-
[BUG] LazyStackedTensorDictStore zeroes the last byte of a new key set on the last elementForse già presa @peterdsharpe l’ha presa oggi. Apertabug
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
pytorch/tensordict#2307 ·
I maintainer di solito rispondono entro 1 giorno
-
Add Group doesn't trim the group name, so a spaces-only name creates a blank group and "fossy " bypasses the duplicate checkForse già presa @bhuvan-somisetty l’ha presa oggi. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 90/100
fossology/fossology#3917 · 1 commento ·
I maintainer di solito rispondono entro 2 giorni
-
area:connection bug effort:S priority:P2
Difficoltà 2/5 1-3 ore Idoneità per principianti 70/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
eclipse-score/persistency#493 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 1/5 1-3 ore Idoneità per principianti 85/100
I maintainer di solito rispondono entro 1 giorno