Information on source package postgresql-17

Available versions

ReleaseVersion
trixie17.10-0+deb13u1
trixie (security)17.11-0+deb13u1

Resolved issues

BugDescription
CVE-2026-19385Heap buffer overflow in PostgreSQL pg_dump of long function transform ...
CVE-2026-18408Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious s ...
CVE-2026-18024Buffer over-read in PostgreSQL ascii() SQL function allows a user to d ...
CVE-2026-16241Integer underflow in PostgreSQL ECPG allows a database server administ ...
CVE-2026-16239Type confusion in PostgreSQL "portal"/cursor lifecycle allows a user t ...
CVE-2026-16238Type confusion in PostgreSQL pg_restore_attribute_stats() allows an ob ...
CVE-2026-15742Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct ...
CVE-2026-15741SQL injection in PostgreSQL EXTRACT() deparse allows an object owner t ...
CVE-2026-14681Improper enforcement of message integrity in PostgreSQL GSSAPI support ...
CVE-2026-14680Type confusion with PostgreSQL "internal" data type arguments allows a ...
CVE-2026-14679Stack buffer overflow in PostgreSQL argument name matching allows an o ...
CVE-2026-14678Buffer over-read in PostgreSQL pg_trgm index picksplit function reads ...
CVE-2026-14677Integer wraparound in PostgreSQL 32-bit builds of pltcl and plperl all ...
CVE-2026-14676Heap buffer overflow in PostgreSQL pg_stat_statements allows the query ...
CVE-2026-14673Untrusted search path in PostgreSQL amcheck allows a grantee of amchec ...
CVE-2026-14672Observable response discrepancy in PostgreSQL SCRAM authentication all ...
CVE-2026-14671Type confusion in PostgreSQL module "refint" allows an object creator ...
CVE-2026-14670Heap buffer overflow in PostgreSQL plperl return of a tied hash allows ...
CVE-2026-14669Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the par ...
CVE-2026-14668Type confusion regarding input of PostgreSQL ctid data type selectivit ...
CVE-2026-14666Incomplete tracking in PostgreSQL of changes to role membership, role ...
CVE-2026-14664Heap buffer overflow in PostgreSQL regexp allows the query author to e ...
CVE-2026-14663Cleartext storage in PostgreSQL pgcrypto disabled ciphers allows a use ...
CVE-2026-14662Integer wraparound in PostgreSQL tsvector and tsquery data type functi ...
CVE-2026-6638SQL injection in PostgreSQL logical replication ALTER SUBSCRIPTION ... ...
CVE-2026-6637Stack buffer overflow in PostgreSQL module "refint" allows an unprivil ...
CVE-2026-6479Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an ...
CVE-2026-6478Covert timing channel in comparison of MD5-hashed password in PostgreS ...
CVE-2026-6477Use of inherently dangerous function PQfn(..., result_is_int=0, ...) i ...
CVE-2026-6476SQL injection in PostgreSQL pg_createsubscriber allows an attacker wit ...
CVE-2026-6475Symlink following in PostgreSQL pg_basebackup plain format and in pg_r ...
CVE-2026-6474Externally-controlled format string in PostgreSQL timeofday() function ...
CVE-2026-6473Integer wraparound in multiple PostgreSQL server features allows an un ...
CVE-2026-6472Missing authorization in PostgreSQL CREATE TYPE allows an object creat ...
CVE-2026-6471Missing authorization in PostgreSQL logical decoding allows a non-supe ...
CVE-2026-6470Missing authorization in PostgreSQL DDL commands allows an object crea ...
CVE-2026-6469Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE co ...
CVE-2026-6464Untrusted data inclusion in PostgreSQL psql COPY may allow a server ad ...
CVE-2026-2007Heap buffer overflow in PostgreSQL pg_trgm allows a database user to a ...
CVE-2026-2006Missing validation of multibyte character length in PostgreSQL text ma ...
CVE-2026-2005Heap buffer overflow in PostgreSQL pgcrypto allows a ciphertext provid ...
CVE-2026-2004Missing validation of type of input in PostgreSQL intarray extension s ...
CVE-2026-2003Improper validation of type "oidvector" in PostgreSQL allows a databas ...
CVE-2025-12818Integer wraparound in multiple PostgreSQL libpq client library functio ...
CVE-2025-12817Missing authorization in PostgreSQL CREATE STATISTICS command allows a ...
CVE-2025-8715Improper neutralization of newlines in pg_dump in PostgreSQL allows a ...
CVE-2025-8714Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious s ...
CVE-2025-8713PostgreSQL optimizer statistics allow a user to read sampled data with ...
CVE-2025-4207Buffer over-read in PostgreSQL GB18030 encoding validation allows a da ...
CVE-2025-1094Improper neutralization of quoting syntax in PostgreSQL libpq function ...
CVE-2024-10979Incorrect control of environment variables in PostgreSQL PL/Perl allow ...
CVE-2024-10978Incorrect privilege assignment in PostgreSQL allows a less-privileged ...
CVE-2024-10977Client use of server error message in PostgreSQL allows a server not t ...
CVE-2024-10976Incomplete tracking in PostgreSQL of tables with row security allows a ...

Security announcements

DSA / DLADescription
DSA-6438-1postgresql-17 - security update
DSA-6270-1postgresql-17 - security update
DSA-6133-1postgresql-17 - security update

Search for package or bug name: Reporting problems