Information on source package postgresql-15

Available versions

ReleaseVersion
bookworm15.18-0+deb12u1
bookworm (security)15.19-0+deb12u1

Resolved issues

BugDescription
CVE-2026-19385Heap buffer overflow in PostgreSQL pg_dump of long function transform ...
CVE-2026-18408Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious s ...
CVE-2026-18024Buffer over-read in PostgreSQL ascii() SQL function allows a user to d ...
CVE-2026-16241Integer underflow in PostgreSQL ECPG allows a database server administ ...
CVE-2026-16239Type confusion in PostgreSQL "portal"/cursor lifecycle allows a user t ...
CVE-2026-16238Type confusion in PostgreSQL pg_restore_attribute_stats() allows an ob ...
CVE-2026-15742Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct ...
CVE-2026-15741SQL injection in PostgreSQL EXTRACT() deparse allows an object owner t ...
CVE-2026-14681Improper enforcement of message integrity in PostgreSQL GSSAPI support ...
CVE-2026-14680Type confusion with PostgreSQL "internal" data type arguments allows a ...
CVE-2026-14679Stack buffer overflow in PostgreSQL argument name matching allows an o ...
CVE-2026-14678Buffer over-read in PostgreSQL pg_trgm index picksplit function reads ...
CVE-2026-14677Integer wraparound in PostgreSQL 32-bit builds of pltcl and plperl all ...
CVE-2026-14676Heap buffer overflow in PostgreSQL pg_stat_statements allows the query ...
CVE-2026-14673Untrusted search path in PostgreSQL amcheck allows a grantee of amchec ...
CVE-2026-14672Observable response discrepancy in PostgreSQL SCRAM authentication all ...
CVE-2026-14671Type confusion in PostgreSQL module "refint" allows an object creator ...
CVE-2026-14670Heap buffer overflow in PostgreSQL plperl return of a tied hash allows ...
CVE-2026-14669Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the par ...
CVE-2026-14668Type confusion regarding input of PostgreSQL ctid data type selectivit ...
CVE-2026-14666Incomplete tracking in PostgreSQL of changes to role membership, role ...
CVE-2026-14664Heap buffer overflow in PostgreSQL regexp allows the query author to e ...
CVE-2026-14663Cleartext storage in PostgreSQL pgcrypto disabled ciphers allows a use ...
CVE-2026-14662Integer wraparound in PostgreSQL tsvector and tsquery data type functi ...
CVE-2026-6637Stack buffer overflow in PostgreSQL module "refint" allows an unprivil ...
CVE-2026-6479Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an ...
CVE-2026-6478Covert timing channel in comparison of MD5-hashed password in PostgreS ...
CVE-2026-6477Use of inherently dangerous function PQfn(..., result_is_int=0, ...) i ...
CVE-2026-6475Symlink following in PostgreSQL pg_basebackup plain format and in pg_r ...
CVE-2026-6474Externally-controlled format string in PostgreSQL timeofday() function ...
CVE-2026-6473Integer wraparound in multiple PostgreSQL server features allows an un ...
CVE-2026-6472Missing authorization in PostgreSQL CREATE TYPE allows an object creat ...
CVE-2026-6471Missing authorization in PostgreSQL logical decoding allows a non-supe ...
CVE-2026-6470Missing authorization in PostgreSQL DDL commands allows an object crea ...
CVE-2026-6469Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE co ...
CVE-2026-6464Untrusted data inclusion in PostgreSQL psql COPY may allow a server ad ...
CVE-2026-2007Heap buffer overflow in PostgreSQL pg_trgm allows a database user to a ...
CVE-2026-2006Missing validation of multibyte character length in PostgreSQL text ma ...
CVE-2026-2005Heap buffer overflow in PostgreSQL pgcrypto allows a ciphertext provid ...
CVE-2026-2004Missing validation of type of input in PostgreSQL intarray extension s ...
CVE-2026-2003Improper validation of type "oidvector" in PostgreSQL allows a databas ...
CVE-2025-12818Integer wraparound in multiple PostgreSQL libpq client library functio ...
CVE-2025-12817Missing authorization in PostgreSQL CREATE STATISTICS command allows a ...
CVE-2025-8715Improper neutralization of newlines in pg_dump in PostgreSQL allows a ...
CVE-2025-8714Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious s ...
CVE-2025-8713PostgreSQL optimizer statistics allow a user to read sampled data with ...
CVE-2025-4207Buffer over-read in PostgreSQL GB18030 encoding validation allows a da ...
CVE-2025-1094Improper neutralization of quoting syntax in PostgreSQL libpq function ...
CVE-2024-10979Incorrect control of environment variables in PostgreSQL PL/Perl allow ...
CVE-2024-10978Incorrect privilege assignment in PostgreSQL allows a less-privileged ...
CVE-2024-10977Client use of server error message in PostgreSQL allows a server not t ...
CVE-2024-10976Incomplete tracking in PostgreSQL of tables with row security allows a ...
CVE-2024-7348Time-of-check Time-of-use (TOCTOU) race condition in pg_dump in Postgr ...
CVE-2024-4317Missing authorization in PostgreSQL built-in views pg_stats_ext and pg ...
CVE-2024-0985Late privilege drop in REFRESH MATERIALIZED VIEW CONCURRENTLY in Postg ...
CVE-2023-39418A vulnerability was found in PostgreSQL with the use of the MERGE comm ...
CVE-2023-39417IN THE EXTENSION SCRIPT, a SQL Injection vulnerability was found in Po ...
CVE-2023-5870A flaw was found in PostgreSQL involving the pg_cancel_backend role th ...
CVE-2023-5869A flaw was found in PostgreSQL that allows authenticated database user ...
CVE-2023-5868A memory disclosure vulnerability was found in PostgreSQL that allows ...
CVE-2023-2455Row security policies disregard user ID changes after inlining; Postgr ...
CVE-2023-2454schema_element defeats protective search_path changes; It was found th ...
CVE-2022-41862In PostgreSQL, a modified, unauthenticated server can send an untermin ...

Security announcements

DSA / DLADescription
DLA-4740-1postgresql-15 - security update
DSA-6269-1postgresql-15 - security update
DSA-6132-1postgresql-15 - security update
DSA-5812-2postgresql-15 - regression update
DSA-5812-1postgresql-15 - security update
DSA-5745-1postgresql-15 - security update
DSA-5623-1postgresql-15 - security update
DSA-5553-1postgresql-15 - security update

Search for package or bug name: Reporting problems