Important: postgresql:16 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:4063", "synopsis": "Important: postgresql:16 security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for pg_repack, pgaudit, module.postgres-decoderbufs, module.pgaudit, postgresql, module.pg_repack, postgres-decoderbufs, module.postgresql.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "PostgreSQL is an advanced object-relational database management system (DBMS).\n\nSecurity Fix(es):\n\n* postgresql: PostgreSQL missing validation of multibyte character length executes arbitrary code (CVE-2026-2006)\n\n* postgresql: PostgreSQL intarray missing validation of type of input to selectivity estimator executes arbitrary code (CVE-2026-2004)\n\n* postgresql: PostgreSQL pgcrypto heap buffer overflow executes arbitrary code (CVE-2026-2005)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2439324", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2439324", "description": ""}, {"ticket": "2439325", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2439325", "description": ""}, {"ticket": "2439326", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2439326", "description": ""}], "cves": [{"name": "CVE-2026-2004", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2026-2004", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "cvss3BaseScore": "8.8", "cwe": "CWE-1287"}, {"name": "CVE-2026-2005", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2026-2005","cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "cvss3BaseScore": "8.8", "cwe": "CWE-120"}, {"name": "CVE-2026-2006", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2026-2006", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "cvss3BaseScore": "8.8", "cwe": "CWE-1285"}], "references": [], "publishedAt": "2026-03-10T00:01:18.383307Z", "rpms": {"Rocky Linux 8": {"nvras": ["pgaudit-0:16.0-1.module+el8.10.0+1622+bd25b19c.aarch64.rpm", "pgaudit-0:16.0-1.module+el8.10.0+1858+fcc46a79.aarch64.rpm", "pgaudit-0:16.0-1.module+el8.10.0+40057+c37a0e3d.aarch64.rpm", "pgaudit-0:16.0-1.module+el8.10.0+40057+c37a0e3d.src.rpm", "pgaudit-0:16.0-1.module+el8.10.0+1622+bd25b19c.src.rpm", "pgaudit-0:16.0-1.module+el8.10.0+1858+fcc46a79.src.rpm", "pgaudit-0:16.0-1.module+el8.10.0+1622+bd25b19c.x86_64.rpm", "pgaudit-0:16.0-1.module+el8.10.0+1858+fcc46a79.x86_64.rpm", "pgaudit-0:16.0-1.module+el8.10.0+40057+c37a0e3d.x86_64.rpm", "pgaudit-debuginfo-0:16.0-1.module+el8.10.0+40057+c37a0e3d.aarch64.rpm", "pgaudit-debuginfo-0:16.0-1.module+el8.10.0+1858+fcc46a79.aarch64.rpm", "pgaudit-debuginfo-0:16.0-1.module+el8.10.0+1622+bd25b19c.aarch64.rpm", "pgaudit-debuginfo-0:16.0-1.module+el8.10.0+1858+fcc46a79.x86_64.rpm", "pgaudit-debuginfo-0:16.0-1.module+el8.10.0+1622+bd25b19c.x86_64.rpm", "pgaudit-debuginfo-0:16.0-1.module+el8.10.0+40057+c37a0e3d.x86_64.rpm", "pgaudit-debugsource-0:16.0-1.module+el8.10.0+40057+c37a0e3d.aarch64.rpm", "pgaudit-debugsource-0:16.0-1.module+el8.10.0+1622+bd25b19c.aarch64.rpm", "pgaudit-debugsource-0:16.0-1.module+el8.10.0+1858+fcc46a79.aarch64.rpm", "pgaudit-debugsource-0:16.0-1.module+el8.10.0+1622+bd25b19c.x86_64.rpm", "pgaudit-debugsource-0:16.0-1.module+el8.10.0+1858+fcc46a79.x86_64.rpm", "pgaudit-debugsource-0:16.0-1.module+el8.10.0+40057+c37a0e3d.x86_64.rpm", "pg_repack-0:1.5.1-1.module+el8.10.0+1900+d7340343.aarch64.rpm", "pg_repack-0:1.5.1-1.module+el8.10.0+40057+c37a0e3d.aarch64.rpm","pg_repack-0:1.5.1-1.module+el8.10.0+1900+d7340343.src.rpm", "pg_repack-0:1.5.1-1.module+el8.10.0+40057+c37a0e3d.src.rpm", "pg_repack-0:1.5.1-1.module+el8.10.0+40057+c37a0e3d.x86_64.rpm", "pg_repack-0:1.5.1-1.module+el8.10.0+1900+d7340343.x86_64.rpm", "pg_repack-debuginfo-0:1.5.1-1.module+el8.10.0+1900+d7340343.aarch64.rpm", "pg_repack-debuginfo-0:1.5.1-1.module+el8.10.0+40057+c37a0e3d.aarch64.rpm", "pg_repack-debuginfo-0:1.5.1-1.module+el8.10.0+40057+c37a0e3d.x86_64.rpm", "pg_repack-debuginfo-0:1.5.1-1.module+el8.10.0+1900+d7340343.x86_64.rpm", "pg_repack-debugsource-0:1.5.1-1.module+el8.10.0+1900+d7340343.aarch64.rpm", "pg_repack-debugsource-0:1.5.1-1.module+el8.10.0+40057+c37a0e3d.aarch64.rpm", "pg_repack-debugsource-0:1.5.1-1.module+el8.10.0+40057+c37a0e3d.x86_64.rpm", "pg_repack-debugsource-0:1.5.1-1.module+el8.10.0+1900+d7340343.x86_64.rpm", "postgres-decoderbufs-0:2.4.0-1.Final.module+el8.10.0+1622+bd25b19c.aarch64.rpm", "postgres-decoderbufs-0:2.4.0-1.Final.module+el8.10.0+1858+fcc46a79.aarch64.rpm", "postgres-decoderbufs-0:2.4.0-1.Final.module+el8.10.0+40057+c37a0e3d.aarch64.rpm", "postgres-decoderbufs-0:2.4.0-1.Final.module+el8.10.0+1622+bd25b19c.src.rpm", "postgres-decoderbufs-0:2.4.0-1.Final.module+el8.10.0+1858+fcc46a79.src.rpm", "postgres-decoderbufs-0:2.4.0-1.Final.module+el8.10.0+40057+c37a0e3d.src.rpm", "postgres-decoderbufs-0:2.4.0-1.Final.module+el8.10.0+1858+fcc46a79.x86_64.rpm", "postgres-decoderbufs-0:2.4.0-1.Final.module+el8.10.0+40057+c37a0e3d.x86_64.rpm", "postgres-decoderbufs-0:2.4.0-1.Final.module+el8.10.0+1622+bd25b19c.x86_64.rpm", "postgres-decoderbufs-debuginfo-0:2.4.0-1.Final.module+el8.10.0+1858+fcc46a79.aarch64.rpm", "postgres-decoderbufs-debuginfo-0:2.4.0-1.Final.module+el8.10.0+1622+bd25b19c.aarch64.rpm", "postgres-decoderbufs-debuginfo-0:2.4.0-1.Final.module+el8.10.0+40057+c37a0e3d.aarch64.rpm", "postgres-decoderbufs-debuginfo-0:2.4.0-1.Final.module+el8.10.0+1858+fcc46a79.x86_64.rpm", "postgres-decoderbufs-debuginfo-0:2.4.0-1.Final.module+el8.10.0+1622+bd25b19c.x86_64.rpm","postgres-decoderbufs-debuginfo-0:2.4.0-1.Final.module+el8.10.0+40057+c37a0e3d.x86_64.rpm", "postgres-decoderbufs-debugsource-0:2.4.0-1.Final.module+el8.10.0+1622+bd25b19c.aarch64.rpm", "postgres-decoderbufs-debugsource-0:2.4.0-1.Final.module+el8.10.0+1858+fcc46a79.aarch64.rpm", "postgres-decoderbufs-debugsource-0:2.4.0-1.Final.module+el8.10.0+40057+c37a0e3d.aarch64.rpm", "postgres-decoderbufs-debugsource-0:2.4.0-1.Final.module+el8.10.0+40057+c37a0e3d.x86_64.rpm", "postgres-decoderbufs-debugsource-0:2.4.0-1.Final.module+el8.10.0+1622+bd25b19c.x86_64.rpm", "postgres-decoderbufs-debugsource-0:2.4.0-1.Final.module+el8.10.0+1858+fcc46a79.x86_64.rpm", "postgresql-0:16.13-1.module+el8.10.0+40101+1be82829.aarch64.rpm", "postgresql-0:16.13-1.module+el8.10.0+40101+1be82829.src.rpm", "postgresql-0:16.13-1.module+el8.10.0+40101+1be82829.x86_64.rpm", "postgresql-contrib-0:16.13-1.module+el8.10.0+40101+1be82829.aarch64.rpm", "postgresql-contrib-0:16.13-1.module+el8.10.0+40101+1be82829.x86_64.rpm", "postgresql-contrib-debuginfo-0:16.13-1.module+el8.10.0+40101+1be82829.aarch64.rpm", "postgresql-contrib-debuginfo-0:16.13-1.module+el8.10.0+40101+1be82829.x86_64.rpm", "postgresql-debuginfo-0:16.13-1.module+el8.10.0+40101+1be82829.aarch64.rpm", "postgresql-debuginfo-0:16.13-1.module+el8.10.0+40101+1be82829.x86_64.rpm", "postgresql-debugsource-0:16.13-1.module+el8.10.0+40101+1be82829.aarch64.rpm", "postgresql-debugsource-0:16.13-1.module+el8.10.0+40101+1be82829.x86_64.rpm", "postgresql-docs-0:16.13-1.module+el8.10.0+40101+1be82829.aarch64.rpm", "postgresql-docs-0:16.13-1.module+el8.10.0+40101+1be82829.x86_64.rpm", "postgresql-docs-debuginfo-0:16.13-1.module+el8.10.0+40101+1be82829.aarch64.rpm", "postgresql-docs-debuginfo-0:16.13-1.module+el8.10.0+40101+1be82829.x86_64.rpm", "postgresql-plperl-0:16.13-1.module+el8.10.0+40101+1be82829.aarch64.rpm", "postgresql-plperl-0:16.13-1.module+el8.10.0+40101+1be82829.x86_64.rpm", "postgresql-plperl-debuginfo-0:16.13-1.module+el8.10.0+40101+1be82829.aarch64.rpm","postgresql-plperl-debuginfo-0:16.13-1.module+el8.10.0+40101+1be82829.x86_64.rpm", "postgresql-plpython3-0:16.13-1.module+el8.10.0+40101+1be82829.aarch64.rpm", "postgresql-plpython3-0:16.13-1.module+el8.10.0+40101+1be82829.x86_64.rpm", "postgresql-plpython3-debuginfo-0:16.13-1.module+el8.10.0+40101+1be82829.aarch64.rpm", "postgresql-plpython3-debuginfo-0:16.13-1.module+el8.10.0+40101+1be82829.x86_64.rpm", "postgresql-pltcl-0:16.13-1.module+el8.10.0+40101+1be82829.aarch64.rpm", "postgresql-pltcl-0:16.13-1.module+el8.10.0+40101+1be82829.x86_64.rpm", "postgresql-pltcl-debuginfo-0:16.13-1.module+el8.10.0+40101+1be82829.aarch64.rpm", "postgresql-pltcl-debuginfo-0:16.13-1.module+el8.10.0+40101+1be82829.x86_64.rpm", "postgresql-private-devel-0:16.13-1.module+el8.10.0+40101+1be82829.aarch64.rpm", "postgresql-private-devel-0:16.13-1.module+el8.10.0+40101+1be82829.x86_64.rpm", "postgresql-private-libs-0:16.13-1.module+el8.10.0+40101+1be82829.aarch64.rpm", "postgresql-private-libs-0:16.13-1.module+el8.10.0+40101+1be82829.x86_64.rpm", "postgresql-private-libs-debuginfo-0:16.13-1.module+el8.10.0+40101+1be82829.aarch64.rpm", "postgresql-private-libs-debuginfo-0:16.13-1.module+el8.10.0+40101+1be82829.x86_64.rpm", "postgresql-server-0:16.13-1.module+el8.10.0+40101+1be82829.aarch64.rpm", "postgresql-server-0:16.13-1.module+el8.10.0+40101+1be82829.x86_64.rpm", "postgresql-server-debuginfo-0:16.13-1.module+el8.10.0+40101+1be82829.aarch64.rpm", "postgresql-server-debuginfo-0:16.13-1.module+el8.10.0+40101+1be82829.x86_64.rpm", "postgresql-server-devel-0:16.13-1.module+el8.10.0+40101+1be82829.aarch64.rpm", "postgresql-server-devel-0:16.13-1.module+el8.10.0+40101+1be82829.x86_64.rpm", "postgresql-server-devel-debuginfo-0:16.13-1.module+el8.10.0+40101+1be82829.aarch64.rpm", "postgresql-server-devel-debuginfo-0:16.13-1.module+el8.10.0+40101+1be82829.x86_64.rpm", "postgresql-static-0:16.13-1.module+el8.10.0+40101+1be82829.aarch64.rpm", "postgresql-static-0:16.13-1.module+el8.10.0+40101+1be82829.x86_64.rpm","postgresql-test-0:16.13-1.module+el8.10.0+40101+1be82829.aarch64.rpm", "postgresql-test-0:16.13-1.module+el8.10.0+40101+1be82829.x86_64.rpm", "postgresql-test-debuginfo-0:16.13-1.module+el8.10.0+40101+1be82829.aarch64.rpm", "postgresql-test-debuginfo-0:16.13-1.module+el8.10.0+40101+1be82829.x86_64.rpm", "postgresql-test-rpm-macros-0:16.13-1.module+el8.10.0+40101+1be82829.noarch.rpm", "postgresql-upgrade-0:16.13-1.module+el8.10.0+40101+1be82829.aarch64.rpm", "postgresql-upgrade-0:16.13-1.module+el8.10.0+40101+1be82829.x86_64.rpm", "postgresql-upgrade-debuginfo-0:16.13-1.module+el8.10.0+40101+1be82829.aarch64.rpm", "postgresql-upgrade-debuginfo-0:16.13-1.module+el8.10.0+40101+1be82829.x86_64.rpm", "postgresql-upgrade-devel-0:16.13-1.module+el8.10.0+40101+1be82829.aarch64.rpm", "postgresql-upgrade-devel-0:16.13-1.module+el8.10.0+40101+1be82829.x86_64.rpm", "postgresql-upgrade-devel-debuginfo-0:16.13-1.module+el8.10.0+40101+1be82829.aarch64.rpm", "postgresql-upgrade-devel-debuginfo-0:16.13-1.module+el8.10.0+40101+1be82829.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Important PostgreSQL update for Rocky Linux 8 fixes critical security issues affecting data integrity and execution.. PostgreSQL Security Update, Rocky Linux Security Advisory, Code Execution Risks. . Severity: Important. LinuxSecurity.com Team
Xpdf and Poppler are vulnerable to a heap overflow that may be exploited to execute arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200602-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Xpdf, Poppler: Heap overflow Date: February 12, 2006 Bugs: #120985 ID: 200602-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Xpdf and Poppler are vulnerable to a heap overflow that may be exploited to execute arbitrary code. Background ========= Xpdf is a PDF file viewer that runs under the X Window System. Poppler is a PDF rendering library based on the Xpdf 3.0 code base. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 app-text/xpdf < 3.01-r7 > = 3.01-r7 2 app-text/poppler < 0.5.0-r4 > = 0.5.0-r4 ------------------------------------------------------------------- 2 affected packages on all of their supported architectures. ------------------------------------------------------------------- Description ========== Dirk Mueller has reported a vulnerability in Xpdf. It is caused by a missing boundary check in the splash rasterizer engine when handling PDF splash images with overly large dimensions. Impact ===== By sending a specially crafted PDF file to a victim, an attacker could cause an overflow, potentially resulting in the execution of arbitrary code with the privileges of the user running the application. Workaround ========= There is no known workaround at thistime. Resolution ========= All Xpdf users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =app-text/xpdf-3.01-r7" All Poppler users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =app-text/poppler-0.5.0-r4" References ========= [ 1 ] CVE-2006-0301 https://www.cve.org/CVERecord?id=CVE-2006-0301 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200602-04 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to
"infamous41md" and Chris Evans discovered several heap based buffer overflows in xpdf, the Portable Document Format (PDF) suite, which is also present in tetex-bin, the binary files of teTeX, and which can lead to a denial of service by crashing the application or possibly to the execution of arbitrary code.. - --------------------------------------------------------------------------Debian Security Advisory DSA 937-1
Get the latest Linux and open source security news straight to your inbox.