RHSA-2026:69607HighCVSS 8.8

Red Hat Security Advisory: postgresql security update

Published
September 22, 2026
Last Modified
September 29, 2026

🔗 CVE IDs covered (15)

📋 Description

CVE-2026-6464 — postgresql: PostgreSQL psql: Arbitrary command execution via untrusted data in COPY FROM STDIN CVE-2026-6471 — postgresql: PostgreSQL: Arbitrary code execution via logical decoding plugin CVE-2026-14662 — postgresql: PostgreSQL: Arbitrary code execution via integer wraparound in tsvector and tsquery functions CVE-2026-14664 — postgresql: PostgreSQL: Arbitrary code execution via heap buffer overflow in regexp CVE-2026-14668 — postgresql: PostgreSQL: Information disclosure via type confusion in ctid selectivity estimator CVE-2026-14669 — postgresql: PostgreSQL: Arbitrary code execution via long POSIX timezone abbreviation CVE-2026-14670 — postgresql: PostgreSQL: Arbitrary code execution via plperl tied hash heap buffer overflow CVE-2026-14671 — postgresql: PostgreSQL: Arbitrary code execution via type confusion in 'refint' module CVE-2026-14677 — postgresql: pltcl: plperl: PostgreSQL: Arbitrary code execution in 32-bit pltcl and plperl CVE-2026-14679 — postgresql: PostgreSQL: Stack buffer overflow via OUT parameter count manipulation CVE-2026-14680 — postgresql: PostgreSQL: Arbitrary code execution via type confusion with "internal" arguments CVE-2026-15742 — postgresql-fuzzystrmatch: PostgreSQL fuzzystrmatch: Arbitrary code execution via integer wraparound CVE-2026-16239 — postgresql: PostgreSQL: Arbitrary code execution via type confusion in cursor lifecycle CVE-2026-18408 — postgresql: PostgreSQL: Arbitrary code execution via untrusted data inclusion in pg_dump CVE-2026-19385 — postgresql: PostgreSQL pg_dump: Arbitrary code execution via crafted transform lists

🎯 Affected products164

  • Red Hat Enterprise Linux AppStream (v. 9)
  • Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)
  • postgresql-0:13.23-6.el9_8.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • postgresql-0:13.23-6.el9_8.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • postgresql-0:13.23-6.el9_8.s390x as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • postgresql-0:13.23-6.el9_8.src as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • postgresql-0:13.23-6.el9_8.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • postgresql-contrib-0:13.23-6.el9_8.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • postgresql-contrib-0:13.23-6.el9_8.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • postgresql-contrib-0:13.23-6.el9_8.s390x as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • postgresql-contrib-0:13.23-6.el9_8.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • postgresql-contrib-debuginfo-0:13.23-6.el9_8.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • postgresql-contrib-debuginfo-0:13.23-6.el9_8.aarch64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)
  • postgresql-contrib-debuginfo-0:13.23-6.el9_8.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • postgresql-contrib-debuginfo-0:13.23-6.el9_8.ppc64le as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)
  • postgresql-contrib-debuginfo-0:13.23-6.el9_8.s390x as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • postgresql-contrib-debuginfo-0:13.23-6.el9_8.s390x as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)
  • postgresql-contrib-debuginfo-0:13.23-6.el9_8.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • postgresql-contrib-debuginfo-0:13.23-6.el9_8.x86_64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)
  • postgresql-debuginfo-0:13.23-6.el9_8.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • postgresql-debuginfo-0:13.23-6.el9_8.aarch64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)
  • postgresql-debuginfo-0:13.23-6.el9_8.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • postgresql-debuginfo-0:13.23-6.el9_8.ppc64le as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)
  • postgresql-debuginfo-0:13.23-6.el9_8.s390x as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • postgresql-debuginfo-0:13.23-6.el9_8.s390x as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)
  • postgresql-debuginfo-0:13.23-6.el9_8.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • postgresql-debuginfo-0:13.23-6.el9_8.x86_64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)
  • postgresql-debugsource-0:13.23-6.el9_8.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • postgresql-debugsource-0:13.23-6.el9_8.aarch64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)
  • postgresql-debugsource-0:13.23-6.el9_8.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • +134 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this vulnerability, ensure that the REPLICATION privilege is granted only to highly trusted database superusers. Regularly review user privileges to confirm that non-superuser accounts do not possess the REPLICATION privilege unless absolutely necessary and their activities are closely monitored. If logical decoding is not actively used, consider disabling it to further reduce the attack surface, though specific configuration steps for disabling logical decoding are beyond the scope of this mitigation. Workaround: Restrict PostgreSQL to trusted hosts and bind only required interfaces. Do not grant CONNECT to untrusted roles; any session that can run SQL can call regexp_match / regexp_matches / regexp_split_to_*. If those functions are unused, REVOKE EXECUTE on them from PUBLIC. Workaround: To mitigate this vulnerability, administrators should enforce the principle of least privilege by revoking CREATE permissions on all databases from untrusted users. Because exploiting this flaw strictly requires the attacker to be an object creator, removing this privilege effectively neutralizes the threat. Ensure only highly trusted administrative roles can create database objects Workaround: To reduce the risk of exploitation, ensure that only trusted users have privileges to modify timezone settings within the PostgreSQL database. Additionally, restrict network access to the PostgreSQL server to only trusted clients and applications through firewall rules, limiting the attack surface for remote exploitation. Workaround: Disable the plperl procedural language if it is not actively required by executing DROP LANGUAGE plperl; on affected databases. Alternatively, restrict access by revoking USAGE privileges on plperl from untrusted roles. These actions prevent the execution of crafted plperl functions, mitigating the risk(a database restart may be required to clear active sessions). Workaround: To mitigate this vulnerability, administrators should avoid installing the refint module and remove it if it is currently deployed by executing DROP EXTENSION refint; as a database superuser. Additionally, enforcing the principle of least privilege by revoking CREATE permissions on databases from untrusted users prevents them from creating the malicious objects necessary to exploit this flaw. Workaround: To mitigate this issue, disable or remove the `pltcl` and `plperl` extensions if they are not essential for your PostgreSQL deployment, particularly in 32-bit environments. This can be done by revoking `CREATE` privilege on `LANGUAGE pltcl` and `LANGUAGE plperl` from untrusted users. If these extensions are necessary, ensure that only trusted users possess object creation privileges within the database. Workaround: Restrict PostgreSQL to trusted hosts and bind only the required interfaces; use pg_hba.conf so only trusted clients can reach the port. Do not grant CONNECT (or any SQL login) to untrusted roles —any session can trigger this. Workaround: To mitigate this issue, consider disabling the `fuzzystrmatch` extension within PostgreSQL if its functionality is not essential. Alternatively, the `postgresql-fuzzystrmatch` package can be removed. Disabling or removing the extension may affect applications that rely on the `levenshtein()` or `levenshtein_less_equal()` functions. A database service restart may be required for these changes to take effect. Workaround: To mitigate this vulnerability, restrict direct database access strictly to trusted roles and minimize multi-tenant database scenarios where untrusted users can execute arbitrary SQL. Monitor database audit logs for anomalous or high-frequency cursor lifecycle activities involving unexpected CLOSE and DECLARE operations. Workaround: To mitigate this vulnerability, administrators should avoid generating or restoring pg_dump files from untrusted or public origin servers using the psql client. If restoring a plain-format dump from an unverified source is strictly necessary, manually inspect the file for unauthorized \restrict or \unrestrict meta-commands before execution, or isolate the restore process in a sandboxed environment Workaround: Restrict database user privileges, particularly object creation, to trusted administrators only. Ensure that `pg_dump` operations are performed by users with the least necessary operating system privileges to limit the impact of potential code execution.

🔗 References (18)