[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index] [SECURITY] [DSA 6270-1] postgresql-17 security update To: debian-security-announce@lists.debian.org Subject: [SECURITY] [DSA 6270-1] postgresql-17 security update From: Moritz Muehlenhoff <jmm@debian.org> Date: Thu, 14 May 2026 14:26:16 +0000 Message-id: <[🔎] agXbiN-m_jY_P7xF@seger.debian.org> Reply-to: debian-security-announce-request@lists.debian.org -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-6270-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff May 14, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : postgresql-17 CVE ID : CVE-2026-6472 CVE-2026-6473 CVE-2026-6474 CVE-2026-6475 CVE-2026-6476 CVE-2026-6477 CVE-2026-6478 CVE-2026-6479 CVE-2026-6637 CVE-2026-6638 Multiple security issues were discovered in PostgreSQL, which may result in authorisation bypass, execution of arbitrary code, information disclosure, privilege escalation, SQL injection or denial of service. For the stable distribution (trixie), these problems have been fixed in version 17.10-0+deb13u1. We recommend that you upgrade your postgresql-17 packages. For the detailed security status of postgresql-17 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/postgresql-17 Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmoF2pkACgkQEMKTtsN8 TjZ0sQ/9E+7icXhRTsGvL0N7lQQIzWOXrwIBmu9Yr37AxDJ6Syyg/axDB1jNSjyT zVa64OBWR0BCU8PkYr3eFv61oRkBxNhtUrJjiUxdi/Mw2w6G/bue7y1XeTHn5qpM 9ukzFk0Zupw9A5hEQrvad/qWBLxs7h43lNBLK1Qcwpq81BXqRRv87ElJuWTRAwYa AmvAhuuWwFU7fwmcn2ShONzJROwyslkk2X3HNiLdDygUkBPFZpgV/263tdWKTRq5 slq8yyC69WROhfmHWhmwhnT9whxF3r92Lcr9TcGzpgW9El71vFuaW1fRttnOk/pz qA9kmgb5W1vgLMTlMYyR//rAagEF5NBgcrd9ICIG9/ShR3O64YZB7upVXvrDN0bS gucP6UixzNVnSOvoEopDxFDE/yBmSoYgcCtXa8R9mtTjSEDDKIFKhy3KNgXN4UGd T/2k4XTuj3WPReziLx3NCKOJ1oSIG1Ap1Xxxc/kKDJ2ROMbJF6j5Nyu5AwKhQ5NL c3FNLV7DsVddvAxsh3XIfOkTxsxNpoB1iuVutWjWVaoJRHZcKiEQMMBDtqvBurS4 d6ZZCpEE6pNRjrFSLKkK/AJ9nqODAkcO1K0HEG82H+57noLAsLxaS1JYFToLC8/q 2BWvlE42lKQ4jiqUnG2v0S/7YjLUo4im2PQKY76H6TMnuza9qFs= =a8a4 -----END PGP SIGNATURE----- Reply to: debian-security-announce@lists.debian.org Moritz Muehlenhoff (on-list) Moritz Muehlenhoff (off-list) Prev by Date: [SECURITY] [DSA 6269-1] postgresql-15 security update Next by Date: [SECURITY] [DSA 6271-1] gsasl security update Previous by thread: [SECURITY] [DSA 6269-1] postgresql-15 security update Next by thread: [SECURITY] [DSA 6271-1] gsasl security update Index(es): Date Thread
Multiple security vulnerabilities in PostgreSQL, including CVE-2026-6473 (CVSS 8.8 HIGH), may lead to authorization bypass, arbitrary code execution, information disclosure, privilege escalation, SQL injection, or denial of service. The Debian Security Advisory DSA-6270-1 addresses these issues for the `postgresql-17` package in the stable distribution, requiring an upgrade to version 17.10-0+deb13u1.