Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Critical Security Vulnerabilities in Mageia 9 PostgreSQL15 Remote Code Exec

mageia
Calendar Grey February 17, 2026
Dist Mageia Esm H88
This advisory details security updates for postgresql15 in Mageia addressing multiple vulnerabilities, emphasizing critical fixes.
MGASA-2026-0041 - Updated postgresql15 packages fix security vulnerabilities

Summary

Description: PostgreSQL oidvector discloses a few bytes of memory. (CVE-2026-2003) PostgreSQL intarray missing validation of type of input to selectivity estimator executes arbitrary code. (CVE-2026-2004) PostgreSQL pgcrypto heap buffer overflow executes arbitrary code. (CVE-2026-2005) PostgreSQL missing validation of multibyte character length executes arbitrary code. (CVE-2026-2006) PostgreSQL pg_trgm heap buffer overflow writes pattern onto server memory. (CVE-2026-2007

References

- https://bugs.mageia.org/show_bug.cgi?id=35133

- https://www.postgresql.org/about/news/postgresql-182-178-1612-1516-and-1421-released-3235/

- https://www.cve.org/CVERecord?id=CVE-2026-2003

- https://www.cve.org/CVERecord?id=CVE-2026-2004

- https://www.cve.org/CVERecord?id=CVE-2026-2005

- https://www.cve.org/CVERecord?id=CVE-2026-2006

- https://www.cve.org/CVERecord?id=CVE-2026-2007

Resolution

SRPMS

- 9/core/postgresql15-15.16-1.mga9

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 17 Feb 2026
URL: https://advisories.mageia.org/MGASA-2026-0041.html
Type: security
CVE: CVE-2026-2003, CVE-2026-2004, CVE-2026-2005, CVE-2026-2006, CVE-2026-2007

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here