An update that solves four vulnerabilities and has one fix can now be installed.. # Security update for postgresql17 Announcement ID: SUSE-SU-2026:20906-1 Release Date: 2026-03-18T15:31:19Z Rating: important References: * bsc#1258008 * bsc#1258009 * bsc#1258010 * bsc#1258011 * bsc#1258754 Cross-References: * CVE-2026-2003 * CVE-2026-2004 * CVE-2026-2005 * CVE-2026-2006 CVSS scores: * CVE-2026-2003 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-2003 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-2004 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-2004 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-2005 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-2005 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-2006 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-2006 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server - BCI 16.0 An update that solves four vulnerabilities and has one fix can now be installed. ## Description: This update for postgresql17 fixes the following issues: * Update to version 17.9. (bsc#1258754) * CVE-2026-2003: Guard against unexpected dimensions of oidvector/int2vector (bsc#1258008) * CVE-2026-2004: Harden selectivity estimators against being attached to operators that accept unexpected data types. (bsc#1258009) * CVE-2026-2005: Fix buffer overrun in contrib/pgcrypto's PGP decryption functions. (bsc#1258010) * CVE-2026-2006: Fix inadequate validation of multibyte character lengths. (bsc#1258011) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server - BCI 16.0 zypper in -t patchSUSE-SLES-16.0-406=1 ## Package List: * SUSE Linux Enterprise Server - BCI 16.0 (aarch64 ppc64le s390x x86_64) * postgresql17-debugsource-17.9-160000.1.1 * postgresql17-plpython-debuginfo-17.9-160000.1.1 * postgresql17-server-debuginfo-17.9-160000.1.1 * postgresql17-plperl-debuginfo-17.9-160000.1.1 * postgresql17-plperl-17.9-160000.1.1 * postgresql17-devel-17.9-160000.1.1 * postgresql17-pltcl-debuginfo-17.9-160000.1.1 * postgresql17-contrib-17.9-160000.1.1 * postgresql17-pltcl-17.9-160000.1.1 * postgresql17-contrib-debuginfo-17.9-160000.1.1 * postgresql17-debuginfo-17.9-160000.1.1 * postgresql17-plpython-17.9-160000.1.1 * postgresql17-server-17.9-160000.1.1 * postgresql17-server-devel-debuginfo-17.9-160000.1.1 * postgresql17-devel-debuginfo-17.9-160000.1.1 * postgresql17-server-devel-17.9-160000.1.1 * postgresql17-17.9-160000.1.1 * SUSE Linux Enterprise Server - BCI 16.0 (noarch) * postgresql17-docs-17.9-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-2003.html * https://www.suse.com/security/cve/CVE-2026-2004.html * https://www.suse.com/security/cve/CVE-2026-2005.html * https://www.suse.com/security/cve/CVE-2026-2006.html * https://bugzilla.suse.com/show_bug.cgi?id=1258008 * https://bugzilla.suse.com/show_bug.cgi?id=1258009 * https://bugzilla.suse.com/show_bug.cgi?id=1258010 * https://bugzilla.suse.com/show_bug.cgi?id=1258011 * https://bugzilla.suse.com/show_bug.cgi?id=1258754 . Update for postgresql17 addresses four issues including buffer overrun and type validation, rated important by SUSE.. SUSE Postgresql17 Important Patch Security Update. . Severity: Important. LinuxSecurity.com Team
PGSQL: Fixed GHSA-hrwm-9436-5mv3 (pgsql extension does not check for errors during escaping). (CVE-2025-1735) SOAP: Fixed GHSA-453j-q27h-5p8x (NULL Pointer Dereference in PHP SOAP . MGASA-2025-0203 - Updated php packages fix security vulnerabilities Publication date: 05 Jul 2025 URL: https://advisories.mageia.org/MGASA-2025-0203.html Type: security Affected Mageia releases: 9 CVE: CVE-2025-1735, CVE-2025-6491, CVE-2025-1220 PGSQL: Fixed GHSA-hrwm-9436-5mv3 (pgsql extension does not check for errors during escaping). (CVE-2025-1735) SOAP: Fixed GHSA-453j-q27h-5p8x (NULL Pointer Dereference in PHP SOAP Extension via Large XML Namespace Prefix). (CVE-2025-6491) Standard: Fixed GHSA-3cr5-j632-f35r (Null byte termination in hostnames). (CVE-2025-1220) References: - https://bugs.mageia.org/show_bug.cgi?id=34418 - https://www.php.net/ChangeLog-8.php#8.2.29 - https://www.cve.org/CVERecord?id=CVE-2025-1735 - https://www.cve.org/CVERecord?id=CVE-2025-6491 - https://www.cve.org/CVERecord?id=CVE-2025-1220 SRPMS: - 9/core/php-8.2.29-1.mga9 . Critical vulnerabilities in Mageia PHP, PGSQL, and SOAP fixed to enhance security against exploitation risks.. Mageia 2025, PHP Security, PGSQL Issues, SOAP Vulnerabilities, Security Updates. . Severity: Critical. LinuxSecurity.com Team
Two security issues were discovered in the pgsql and mysql modules of the InspIRCd IRC daemon, which could result in denial of service. For the stable distribution (buster), these problems have been fixed in . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4764-1
Get the latest Linux and open source security news straight to your inbox.