PostgreSQL Security Update Advisory

PostgreSQL Security Update Advisory

Overview


A security update addressing several vulnerabilities in PostgreSQL has been released. Users of this product should update to the latest version.

Affected Versions


  • CVE-2026-6472, CVE-2026-6473, CVE-2026-6474, CVE-2026-6475, CVE-2026-6477, CVE-2026-6478, CVE-2026-6479, CVE-2026-6637.
    • PostgreSQL 18 or later, but earlier than 18.4.
    • PostgreSQL 17 or later, but earlier than 17.10.
    • PostgreSQL 16 or later, but earlier than 16.14.
    • PostgreSQL 15 or later, but earlier than 15.18.
    • PostgreSQL 14 or later, but earlier than 14.23.
  • CVE-2026-6476.
    • PostgreSQL 18 or later, but earlier than 18.4.
    • PostgreSQL 17 or later, but earlier than 17.10.
  • CVE-2026-6575.
    • PostgreSQL 18 or later, but earlier than 18.4.
  • CVE-2026-6638.
    • PostgreSQL 18 or later, but earlier than 18.4.
    • PostgreSQL 17 or later, but earlier than 17.10.
    • PostgreSQL 16 or later, but earlier than 16.14.

Resolved Vulnerabilities


  • Insufficient permission validation vulnerability in PostgreSQL’s CREATE TYPE command (CVE-2026-6472).
  • Out-of-bounds write vulnerability caused by integer wrap-around during PostgreSQL server memory allocation (CVE-2026-6473).
  • Information disclosure vulnerability in PostgreSQL’s timeofday() function caused by string processing (CVE-2026-6474).
  • An arbitrary file overwrite vulnerability (CVE-2026-6475) caused by symbolic link handling in PostgreSQL’s pgbasebackup and pgrewind.
  • SQL injection vulnerability in PostgreSQL’s pg_createsubscriber caused by subscriber name handling (CVE-2026-6476).
  • A stack buffer overflow vulnerability in PostgreSQL libpq’s Large Object processing functions (CVE-2026-6477).
  • A vulnerability in PostgreSQL’s MD5-based authentication process that exposes authentication credentials through a timing side channel (CVE-2026-6478).
  • A denial-of-service vulnerability in PostgreSQL’s SSL/GSS negotiation process caused by an infinite recursive call (CVE-2026-6479).
  • A buffer-out-of-bounds read vulnerability in PostgreSQL’s pgrestoreattribute_stats() function (CVE-2026-6575).
  • A stack buffer overflow and SQL injection vulnerability in PostgreSQL’s refint module (CVE-2026-6637).
  • An SQL injection vulnerability (CVE-2026-6638) caused by table name processing in PostgreSQL’s REFRESH PUBLICATION feature.

Mitigation


Vulnerability Patches have been released in the latest updates. Follow the instructions on the reference sites to update to PostgreSQL 18.4, 17.10, 16.14, 15.18, Or 14.23.