gpp_maybe Security update for postgresql17
SUSE-SLE-Module-Basesystem-15-SP7-2026-883


This update for postgresql17 fixes the following issues: Update to version 17.9 (bsc#1258754). Security issues fixed: - CVE-2026-2003: improper validation of type "oidvector" may allow disclose a few bytes of server memory (bsc#1258008). - CVE-2026-2004: intarray missing validation of type of input to selectivity estimator could lead to arbitrary code execution (bsc#1258009). - CVE-2026-2005: buffer overrun in contrib/pgcrypto's PGP decryption functions could lead to arbitrary code execution (bsc#1258010). - CVE-2026-2006: inadequate validation of multibyte character lengths could lead to arbitrary code execution (bsc#1258011). Regression fixes: - the substring() function raises an error "invalid byte sequence for encoding" on non-ASCII text values if the source of that value is a database column (caused by CVE-2026-2006 fix). - a standby may halt and return an error "could not access status of transaction".


cloud_download Downloads

Basesystem Module 15.7 aarch64
  • Packages
    postgresql17
    Basic Clients and Utilities for PostgreSQL
    17.9-150600.13.24.1 lock rpm lock src
Basesystem Module 15.7 ppc64le
  • Packages
    postgresql17
    Basic Clients and Utilities for PostgreSQL
    17.9-150600.13.24.1 lock rpm lock src
Basesystem Module 15.7 s390x
  • Packages
    postgresql17
    Basic Clients and Utilities for PostgreSQL
    17.9-150600.13.24.1 lock rpm lock src
Basesystem Module 15.7 x86_64
  • Packages
    postgresql17
    Basic Clients and Utilities for PostgreSQL
    17.9-150600.13.24.1 lock rpm lock src