Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that solves 9 vulnerabilities and has 10 bug fixes can now be installed.. openSUSE security update: security update for postgresql16 ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:21104-1 Rating: important References: * bsc#1263804 * bsc#1265172 * bsc#1265173 * bsc#1265174 * bsc#1265175 * bsc#1265177 * bsc#1265178 * bsc#1265179 * bsc#1265181 * bsc#1265182 Cross-References: * CVE-2026-6472 * CVE-2026-6473 * CVE-2026-6474 * CVE-2026-6475 * CVE-2026-6477 * CVE-2026-6478 * CVE-2026-6479 * CVE-2026-6637 * CVE-2026-6638 CVSS scores: * CVE-2026-6472 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-6473 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6474 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-6475 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-6477 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-6478 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-6479 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6637 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6638 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 9 vulnerabilities and has 10 bug fixes can now be installed. Description: This update for postgresql16 fixes the following issues Security issues: - CVE-2026-6472: ensure the user has CREATE privilege on the schema specified (bsc#1265172). - CVE-2026-6473: integer overflows in memory-allocation calculations (bsc#1265173). - CVE-2026-6474: Guard against malicious time zone names (bsc#1265174). - CVE-2026-6475: Prevent path traversal in pg_basebackup and pg_rewind (bsc#1265175). - CVE-2026-6477: Mark PQfn() as unsafe, and avoid using it within libpq (bsc#1265177). -CVE-2026-6478: Use timing-safe string comparisons in authentication code (bsc#1265178). - CVE-2026-6479: Prevent unbounded recursion while processing startup packets (bsc#1265179). - CVE-2026-6637: Prevent SQL injection and buffer overruns in contrib/spi (bsc#1265181). - CVE-2026-6638: Properly quote object names in logical replication origin checks (bsc#1265182). Non security issue: - Update to version 16.13. - Get rid of update-alternatives for openSUSE/SLE 16.0 and newer to support immutable systems and transactional updates (jsc#PED-14824). Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-969=1 Package List: - openSUSE Leap 16.0: postgresql16-16.14-160000.1.1 postgresql16-contrib-16.14-160000.1.1 postgresql16-devel-16.14-160000.1.1 postgresql16-docs-16.14-160000.1.1 postgresql16-llvmjit-16.14-160000.1.1 postgresql16-llvmjit-devel-16.14-160000.1.1 postgresql16-plperl-16.14-160000.1.1 postgresql16-plpython-16.14-160000.1.1 postgresql16-pltcl-16.14-160000.1.1 postgresql16-server-16.14-160000.1.1 postgresql16-server-devel-16.14-160000.1.1 postgresql16-test-16.14-160000.1.1 References: * https://www.suse.com/security/cve/CVE-2026-6472.html * https://www.suse.com/security/cve/CVE-2026-6473.html * https://www.suse.com/security/cve/CVE-2026-6474.html * https://www.suse.com/security/cve/CVE-2026-6475.html * https://www.suse.com/security/cve/CVE-2026-6477.html * https://www.suse.com/security/cve/CVE-2026-6478.html * https://www.suse.com/security/cve/CVE-2026-6479.html * https://www.suse.com/security/cve/CVE-2026-6637.html * https://www.suse.com/security/cve/CVE-2026-6638.html . Addressing multiple vulnerabilities in postgresql16, this openSUSE update emphasizes critical fixes and enhancements.. postgresql16 update, openSUSEvulnerabilities, SQL injection prevention, path traversal, security update. . Severity: Important. LinuxSecurity.com Team
An update that solves nine vulnerabilities, contains one feature and has one fix can now be installed.. # Security update for postgresql16 Announcement ID: SUSE-SU-2026:22184-1 Release Date: 2026-06-19T17:04:20Z Rating: important References: * bsc#1263804 * bsc#1265172 * bsc#1265173 * bsc#1265174 * bsc#1265175 * bsc#1265177 * bsc#1265178 * bsc#1265179 * bsc#1265181 * bsc#1265182 * jsc#PED-14824 Cross-References: * CVE-2026-6472 * CVE-2026-6473 * CVE-2026-6474 * CVE-2026-6475 * CVE-2026-6477 * CVE-2026-6478 * CVE-2026-6479 * CVE-2026-6637 * CVE-2026-6638 CVSS scores: * CVE-2026-6472 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-6472 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-6473 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6473 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6474 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-6474 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-6475 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-6475 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-6477 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-6477 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-6478 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-6478 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-6479 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6479 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6637 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6637 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6638 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N * CVE-2026-6638 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N * CVE-2026-6638 (NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves nine vulnerabilities, contains one feature and has one fix can now be installed. ## Description: This update for postgresql16 fixes the following issues Security issues: * CVE-2026-6472: ensure the user has CREATE privilege on the schema specified (bsc#1265172). * CVE-2026-6473: integer overflows in memory-allocation calculations (bsc#1265173). * CVE-2026-6474: Guard against malicious time zone names (bsc#1265174). * CVE-2026-6475: Prevent path traversal in pg_basebackup and pg_rewind (bsc#1265175). * CVE-2026-6477: Mark PQfn() as unsafe, and avoid using it within libpq (bsc#1265177). * CVE-2026-6478: Use timing-safe string comparisons in authentication code (bsc#1265178). * CVE-2026-6479: Prevent unbounded recursion while processing startup packets (bsc#1265179). * CVE-2026-6637: Prevent SQL injection and buffer overruns in contrib/spi (bsc#1265181). * CVE-2026-6638: Properly quote object names in logical replication origin checks (bsc#1265182). Non security issue: * Update to version 16.13. * Get rid of update-alternatives for openSUSE/SLE 16.0 and newer to support immutable systems and transactional updates (jsc#PED-14824). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-969=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-969=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * postgresql16-devel-debuginfo-16.14-160000.1.1 * postgresql16-pltcl-16.14-160000.1.1 * postgresql16-contrib-16.14-160000.1.1 * postgresql16-contrib-debuginfo-16.14-160000.1.1 * postgresql16-plperl-16.14-160000.1.1 * postgresql16-server-devel-debuginfo-16.14-160000.1.1 * postgresql16-plpython-16.14-160000.1.1 * postgresql16-debuginfo-16.14-160000.1.1 * postgresql16-pltcl-debuginfo-16.14-160000.1.1 * postgresql16-server-16.14-160000.1.1 * postgresql16-debugsource-16.14-160000.1.1 * postgresql16-16.14-160000.1.1 * postgresql16-server-devel-16.14-160000.1.1 * postgresql16-server-debuginfo-16.14-160000.1.1 * postgresql16-plpython-debuginfo-16.14-160000.1.1 * postgresql16-plperl-debuginfo-16.14-160000.1.1 * postgresql16-devel-16.14-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * postgresql16-docs-16.14-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * postgresql16-devel-debuginfo-16.14-160000.1.1 * postgresql16-pltcl-16.14-160000.1.1 * postgresql16-contrib-16.14-160000.1.1 * postgresql16-contrib-debuginfo-16.14-160000.1.1 * postgresql16-plperl-16.14-160000.1.1 * postgresql16-server-devel-debuginfo-16.14-160000.1.1 * postgresql16-plpython-16.14-160000.1.1 * postgresql16-debuginfo-16.14-160000.1.1 * postgresql16-pltcl-debuginfo-16.14-160000.1.1 * postgresql16-server-16.14-160000.1.1 * postgresql16-debugsource-16.14-160000.1.1 * postgresql16-16.14-160000.1.1 * postgresql16-server-devel-16.14-160000.1.1 * postgresql16-server-debuginfo-16.14-160000.1.1 * postgresql16-plpython-debuginfo-16.14-160000.1.1 * postgresql16-plperl-debuginfo-16.14-160000.1.1 * postgresql16-devel-16.14-160000.1.1 * SUSE Linux Enterprise Server 16.0 (noarch) * postgresql16-docs-16.14-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-6472.html * https://www.suse.com/security/cve/CVE-2026-6473.html * https://www.suse.com/security/cve/CVE-2026-6474.html * https://www.suse.com/security/cve/CVE-2026-6475.html *https://www.suse.com/security/cve/CVE-2026-6477.html * https://www.suse.com/security/cve/CVE-2026-6478.html * https://www.suse.com/security/cve/CVE-2026-6479.html * https://www.suse.com/security/cve/CVE-2026-6637.html * https://www.suse.com/security/cve/CVE-2026-6638.html * https://bugzilla.suse.com/show_bug.cgi?id=1263804 * https://bugzilla.suse.com/show_bug.cgi?id=1265172 * https://bugzilla.suse.com/show_bug.cgi?id=1265173 * https://bugzilla.suse.com/show_bug.cgi?id=1265174 * https://bugzilla.suse.com/show_bug.cgi?id=1265175 * https://bugzilla.suse.com/show_bug.cgi?id=1265177 * https://bugzilla.suse.com/show_bug.cgi?id=1265178 * https://bugzilla.suse.com/show_bug.cgi?id=1265179 * https://bugzilla.suse.com/show_bug.cgi?id=1265181 * https://bugzilla.suse.com/show_bug.cgi?id=1265182 * https://jira.suse.com/browse/PED-14824 . Nine vulnerabilities in postgresql16 addressed with an important security update for SUSE Linux Enterprise Server.. PostgreSQL update,SUSE Linux advisory,security update,SQL injection,buffer overflow. . Severity: Important. LinuxSecurity.com Team
An update that solves 9 vulnerabilities can now be installed.. # postgresql16-16.14-1.1 on GA media Announcement ID: openSUSE-SU-2026:10808-1 Rating: moderate Cross-References: * CVE-2026-6472 * CVE-2026-6473 * CVE-2026-6474 * CVE-2026-6475 * CVE-2026-6477 * CVE-2026-6478 * CVE-2026-6479 * CVE-2026-6637 * CVE-2026-6638 CVSS scores: * CVE-2026-6472 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-6473 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6474 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-6475 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-6477 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-6478 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-6479 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6637 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6638 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N Affected Products: * openSUSE Tumbleweed An update that solves 9 vulnerabilities can now be installed. ## Description: These are all security issues fixed in the postgresql16-16.14-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * postgresql16 16.14-1.1 * postgresql16-contrib 16.14-1.1 * postgresql16-devel 16.14-1.1 * postgresql16-docs 16.14-1.1 * postgresql16-llvmjit 16.14-1.1 * postgresql16-llvmjit-devel 16.14-1.1 * postgresql16-plperl 16.14-1.1 * postgresql16-plpython 16.14-1.1 * postgresql16-pltcl 16.14-1.1 * postgresql16-server 16.14-1.1 * postgresql16-server-devel 16.14-1.1 * postgresql16-test 16.14-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-6472.html * https://www.suse.com/security/cve/CVE-2026-6473.html * https://www.suse.com/security/cve/CVE-2026-6474.html * https://www.suse.com/security/cve/CVE-2026-6475.html *https://www.suse.com/security/cve/CVE-2026-6477.html * https://www.suse.com/security/cve/CVE-2026-6478.html * https://www.suse.com/security/cve/CVE-2026-6479.html * https://www.suse.com/security/cve/CVE-2026-6637.html * https://www.suse.com/security/cve/CVE-2026-6638.html . Nine vulnerabilities in postgresql16 were resolved through this openSUSE update to improve overall security.. openSUSE vulnerabilities update postgresql16. . LinuxSecurity.com Team
An update that solves nine vulnerabilities, contains one feature and has one security fix can now be installed.. # Security update for postgresql16 Announcement ID: SUSE-SU-2026:1942-1 Release Date: 2026-05-18T07:46:20Z Rating: important References: * bsc#1263804 * bsc#1265172 * bsc#1265173 * bsc#1265174 * bsc#1265175 * bsc#1265177 * bsc#1265178 * bsc#1265179 * bsc#1265181 * bsc#1265182 * jsc#PED-14824 Cross-References: * CVE-2026-6472 * CVE-2026-6473 * CVE-2026-6474 * CVE-2026-6475 * CVE-2026-6477 * CVE-2026-6478 * CVE-2026-6479 * CVE-2026-6637 * CVE-2026-6638 CVSS scores: * CVE-2026-6472 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-6472 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-6473 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6473 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6474 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-6474 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-6475 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-6475 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-6477 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-6477 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-6478 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-6478 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-6479 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6479 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6637 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6637 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6638 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N * CVE-2026-6638 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N Affected Products: * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves nine vulnerabilities, contains one feature and has one security fix can now be installed. ## Description: This update for postgresql16 fixes the following issues Update to version 16.13. Security issues: * CVE-2026-6472: ensure the user has CREATE privilege on the schema specified (bsc#1265172). * CVE-2026-6473: integer overflows in memory-allocation calculations (bsc#1265173). * CVE-2026-6474: Guard against malicious time zone names (bsc#1265174). * CVE-2026-6475: Prevent path traversal in pg_basebackup and pg_rewind (bsc#1265175). * CVE-2026-6477: Mark PQfn() as unsafe, and avoid using it within libpq (bsc#1265177). * CVE-2026-6478: Use timing-safe string comparisons in authentication code (bsc#1265178). * CVE-2026-6479: Prevent unbounded recursion while processing startup packets (bsc#1265179). * CVE-2026-6637: Prevent SQL injection and buffer overruns in contrib/spi (bsc#1265181). * CVE-2026-6638: Properly quote object names in logical replication origin checks (bsc#1265182). Non security issue: * Get rid of update-alternatives for openSUSE/SLE 16.0 and newer to support immutable systems and transactional updates (jsc#PED-14824). * /usr/bin/pg_config is missing after migrating away from update-alternatives (bsc#1263804). ## PatchInstructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-1942=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-1942=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-1942=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-1942=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-1942=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-1942=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-1942=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-1942=1 ## Package List: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * postgresql16-devel-debuginfo-16.14-150200.5.44.1 * postgresql16-server-devel-debuginfo-16.14-150200.5.44.1 * postgresql16-pltcl-16.14-150200.5.44.1 * postgresql16-server-16.14-150200.5.44.1 * postgresql16-contrib-16.14-150200.5.44.1 * postgresql16-plperl-debuginfo-16.14-150200.5.44.1 * postgresql16-server-devel-16.14-150200.5.44.1 * postgresql16-16.14-150200.5.44.1 * postgresql16-debuginfo-16.14-150200.5.44.1 * postgresql16-plperl-16.14-150200.5.44.1 * postgresql16-server-debuginfo-16.14-150200.5.44.1 * postgresql16-pltcl-debuginfo-16.14-150200.5.44.1 * postgresql16-plpython-debuginfo-16.14-150200.5.44.1 *postgresql16-debugsource-16.14-150200.5.44.1 * postgresql16-plpython-16.14-150200.5.44.1 * postgresql16-devel-16.14-150200.5.44.1 * postgresql16-contrib-debuginfo-16.14-150200.5.44.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * postgresql16-docs-16.14-150200.5.44.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * postgresql16-devel-debuginfo-16.14-150200.5.44.1 * postgresql16-server-devel-debuginfo-16.14-150200.5.44.1 * postgresql16-pltcl-16.14-150200.5.44.1 * postgresql16-server-16.14-150200.5.44.1 * postgresql16-server-devel-16.14-150200.5.44.1 * postgresql16-contrib-16.14-150200.5.44.1 * postgresql16-16.14-150200.5.44.1 * postgresql16-debuginfo-16.14-150200.5.44.1 * postgresql16-plperl-16.14-150200.5.44.1 * postgresql16-devel-16.14-150200.5.44.1 * postgresql16-server-debuginfo-16.14-150200.5.44.1 * postgresql16-pltcl-debuginfo-16.14-150200.5.44.1 * postgresql16-plpython-debuginfo-16.14-150200.5.44.1 * postgresql16-debugsource-16.14-150200.5.44.1 * postgresql16-plpython-16.14-150200.5.44.1 * postgresql16-plperl-debuginfo-16.14-150200.5.44.1 * postgresql16-contrib-debuginfo-16.14-150200.5.44.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * postgresql16-docs-16.14-150200.5.44.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * postgresql16-devel-debuginfo-16.14-150200.5.44.1 * postgresql16-server-devel-debuginfo-16.14-150200.5.44.1 * postgresql16-pltcl-16.14-150200.5.44.1 * postgresql16-server-16.14-150200.5.44.1 * postgresql16-contrib-16.14-150200.5.44.1 * postgresql16-plperl-debuginfo-16.14-150200.5.44.1 * postgresql16-server-devel-16.14-150200.5.44.1 * postgresql16-16.14-150200.5.44.1 * postgresql16-debuginfo-16.14-150200.5.44.1 * postgresql16-plperl-16.14-150200.5.44.1 * postgresql16-server-debuginfo-16.14-150200.5.44.1 *postgresql16-pltcl-debuginfo-16.14-150200.5.44.1 * postgresql16-plpython-debuginfo-16.14-150200.5.44.1 * postgresql16-debugsource-16.14-150200.5.44.1 * postgresql16-plpython-16.14-150200.5.44.1 * postgresql16-devel-16.14-150200.5.44.1 * postgresql16-contrib-debuginfo-16.14-150200.5.44.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * postgresql16-docs-16.14-150200.5.44.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * postgresql16-devel-debuginfo-16.14-150200.5.44.1 * postgresql16-server-devel-debuginfo-16.14-150200.5.44.1 * postgresql16-pltcl-16.14-150200.5.44.1 * postgresql16-server-16.14-150200.5.44.1 * postgresql16-contrib-16.14-150200.5.44.1 * postgresql16-plperl-debuginfo-16.14-150200.5.44.1 * postgresql16-server-devel-16.14-150200.5.44.1 * postgresql16-16.14-150200.5.44.1 * postgresql16-debuginfo-16.14-150200.5.44.1 * postgresql16-plperl-16.14-150200.5.44.1 * postgresql16-server-debuginfo-16.14-150200.5.44.1 * postgresql16-pltcl-debuginfo-16.14-150200.5.44.1 * postgresql16-plpython-debuginfo-16.14-150200.5.44.1 * postgresql16-debugsource-16.14-150200.5.44.1 * postgresql16-plpython-16.14-150200.5.44.1 * postgresql16-devel-16.14-150200.5.44.1 * postgresql16-contrib-debuginfo-16.14-150200.5.44.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * postgresql16-docs-16.14-150200.5.44.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * postgresql16-devel-debuginfo-16.14-150200.5.44.1 * postgresql16-server-devel-debuginfo-16.14-150200.5.44.1 * postgresql16-pltcl-16.14-150200.5.44.1 * postgresql16-server-16.14-150200.5.44.1 * postgresql16-contrib-16.14-150200.5.44.1 * postgresql16-plperl-debuginfo-16.14-150200.5.44.1 * postgresql16-server-devel-16.14-150200.5.44.1 * postgresql16-16.14-150200.5.44.1 * postgresql16-debuginfo-16.14-150200.5.44.1 * postgresql16-plperl-16.14-150200.5.44.1 *postgresql16-server-debuginfo-16.14-150200.5.44.1 * postgresql16-pltcl-debuginfo-16.14-150200.5.44.1 * postgresql16-plpython-debuginfo-16.14-150200.5.44.1 * postgresql16-debugsource-16.14-150200.5.44.1 * postgresql16-plpython-16.14-150200.5.44.1 * postgresql16-devel-16.14-150200.5.44.1 * postgresql16-contrib-debuginfo-16.14-150200.5.44.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * postgresql16-docs-16.14-150200.5.44.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * postgresql16-devel-debuginfo-16.14-150200.5.44.1 * postgresql16-server-devel-debuginfo-16.14-150200.5.44.1 * postgresql16-pltcl-16.14-150200.5.44.1 * postgresql16-server-16.14-150200.5.44.1 * postgresql16-contrib-16.14-150200.5.44.1 * postgresql16-plperl-debuginfo-16.14-150200.5.44.1 * postgresql16-server-devel-16.14-150200.5.44.1 * postgresql16-16.14-150200.5.44.1 * postgresql16-debuginfo-16.14-150200.5.44.1 * postgresql16-plperl-16.14-150200.5.44.1 * postgresql16-server-debuginfo-16.14-150200.5.44.1 * postgresql16-pltcl-debuginfo-16.14-150200.5.44.1 * postgresql16-plpython-debuginfo-16.14-150200.5.44.1 * postgresql16-debugsource-16.14-150200.5.44.1 * postgresql16-plpython-16.14-150200.5.44.1 * postgresql16-devel-16.14-150200.5.44.1 * postgresql16-contrib-debuginfo-16.14-150200.5.44.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * postgresql16-docs-16.14-150200.5.44.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * postgresql16-server-devel-debuginfo-16.14-150200.5.44.1 * postgresql16-devel-debuginfo-16.14-150200.5.44.1 * postgresql16-server-devel-16.14-150200.5.44.1 * postgresql16-server-16.14-150200.5.44.1 * postgresql16-contrib-16.14-150200.5.44.1 * postgresql16-plperl-debuginfo-16.14-150200.5.44.1 * postgresql16-pltcl-16.14-150200.5.44.1 * postgresql16-16.14-150200.5.44.1 *postgresql16-debuginfo-16.14-150200.5.44.1 * postgresql16-plperl-16.14-150200.5.44.1 * postgresql16-server-debuginfo-16.14-150200.5.44.1 * postgresql16-pltcl-debuginfo-16.14-150200.5.44.1 * postgresql16-plpython-debuginfo-16.14-150200.5.44.1 * postgresql16-debugsource-16.14-150200.5.44.1 * postgresql16-plpython-16.14-150200.5.44.1 * postgresql16-devel-16.14-150200.5.44.1 * postgresql16-contrib-debuginfo-16.14-150200.5.44.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * postgresql16-docs-16.14-150200.5.44.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * postgresql16-devel-debuginfo-16.14-150200.5.44.1 * postgresql16-server-devel-debuginfo-16.14-150200.5.44.1 * postgresql16-pltcl-16.14-150200.5.44.1 * postgresql16-server-16.14-150200.5.44.1 * postgresql16-contrib-16.14-150200.5.44.1 * postgresql16-plperl-debuginfo-16.14-150200.5.44.1 * postgresql16-server-devel-16.14-150200.5.44.1 * postgresql16-16.14-150200.5.44.1 * postgresql16-debuginfo-16.14-150200.5.44.1 * postgresql16-plperl-16.14-150200.5.44.1 * postgresql16-server-debuginfo-16.14-150200.5.44.1 * postgresql16-pltcl-debuginfo-16.14-150200.5.44.1 * postgresql16-plpython-debuginfo-16.14-150200.5.44.1 * postgresql16-debugsource-16.14-150200.5.44.1 * postgresql16-plpython-16.14-150200.5.44.1 * postgresql16-devel-16.14-150200.5.44.1 * postgresql16-contrib-debuginfo-16.14-150200.5.44.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * postgresql16-docs-16.14-150200.5.44.1 ## References: * https://www.suse.com/security/cve/CVE-2026-6472.html * https://www.suse.com/security/cve/CVE-2026-6473.html * https://www.suse.com/security/cve/CVE-2026-6474.html * https://www.suse.com/security/cve/CVE-2026-6475.html * https://www.suse.com/security/cve/CVE-2026-6477.html * https://www.suse.com/security/cve/CVE-2026-6478.html *https://www.suse.com/security/cve/CVE-2026-6479.html * https://www.suse.com/security/cve/CVE-2026-6637.html * https://www.suse.com/security/cve/CVE-2026-6638.html * https://bugzilla.suse.com/show_bug.cgi?id=1263804 * https://bugzilla.suse.com/show_bug.cgi?id=1265172 * https://bugzilla.suse.com/show_bug.cgi?id=1265173 * https://bugzilla.suse.com/show_bug.cgi?id=1265174 * https://bugzilla.suse.com/show_bug.cgi?id=1265175 * https://bugzilla.suse.com/show_bug.cgi?id=1265177 * https://bugzilla.suse.com/show_bug.cgi?id=1265178 * https://bugzilla.suse.com/show_bug.cgi?id=1265179 * https://bugzilla.suse.com/show_bug.cgi?id=1265181 * https://bugzilla.suse.com/show_bug.cgi?id=1265182 * https://jira.suse.com/browse/PED-14824 . SUSE's update resolves nine issues in postgresql16, enhancing security and fixing vulnerabilities. Install now.. SUSE postgresql16 update security patch. . Severity: Important. LinuxSecurity.com Team
An update that solves four vulnerabilities and has one fix can now be installed.. # Security update for postgresql16 Announcement ID: SUSE-SU-2026:20983-1 Release Date: 2026-03-30T14:27:44Z Rating: important References: * bsc#1258008 * bsc#1258009 * bsc#1258010 * bsc#1258011 * bsc#1258754 Cross-References: * CVE-2026-2003 * CVE-2026-2004 * CVE-2026-2005 * CVE-2026-2006 CVSS scores: * CVE-2026-2003 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-2003 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-2004 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-2004 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-2005 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-2005 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-2006 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-2006 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server - BCI 16.0 An update that solves four vulnerabilities and has one fix can now be installed. ## Description: This update for postgresql16 fixes the following issues: * Update to versio 16.13. (bsc#1258754) * CVE-2026-2003: Guard against unexpected dimensions of oidvector/int2vector (bsc#1258008) * CVE-2026-2004: Harden selectivity estimators against being attached to operators that accept unexpected data types. (bsc#1258009) * CVE-2026-2005: Fix buffer overrun in contrib/pgcrypto's PGP decryption functions. (bsc#1258010) * CVE-2026-2006: Fix inadequate validation of multibyte character lengths. (bsc#1258011) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server - BCI 16.0 zypper in -t patchSUSE-SLES-16.0-465=1 ## Package List: * SUSE Linux Enterprise Server - BCI 16.0 (aarch64 ppc64le s390x x86_64) * postgresql16-16.13-160000.1.1 * postgresql16-plperl-16.13-160000.1.1 * postgresql16-server-16.13-160000.1.1 * postgresql16-contrib-debuginfo-16.13-160000.1.1 * postgresql16-server-devel-16.13-160000.1.1 * postgresql16-debugsource-16.13-160000.1.1 * postgresql16-contrib-16.13-160000.1.1 * postgresql16-pltcl-debuginfo-16.13-160000.1.1 * postgresql16-server-debuginfo-16.13-160000.1.1 * postgresql16-devel-debuginfo-16.13-160000.1.1 * postgresql16-plpython-16.13-160000.1.1 * postgresql16-plpython-debuginfo-16.13-160000.1.1 * postgresql16-pltcl-16.13-160000.1.1 * postgresql16-plperl-debuginfo-16.13-160000.1.1 * postgresql16-debuginfo-16.13-160000.1.1 * postgresql16-server-devel-debuginfo-16.13-160000.1.1 * postgresql16-devel-16.13-160000.1.1 * SUSE Linux Enterprise Server - BCI 16.0 (noarch) * postgresql16-docs-16.13-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-2003.html * https://www.suse.com/security/cve/CVE-2026-2004.html * https://www.suse.com/security/cve/CVE-2026-2005.html * https://www.suse.com/security/cve/CVE-2026-2006.html * https://bugzilla.suse.com/show_bug.cgi?id=1258008 * https://bugzilla.suse.com/show_bug.cgi?id=1258009 * https://bugzilla.suse.com/show_bug.cgi?id=1258010 * https://bugzilla.suse.com/show_bug.cgi?id=1258011 * https://bugzilla.suse.com/show_bug.cgi?id=1258754 . Important SUSE security advisory for PostgreSQL 16.13 addressing multiple issues, ensuring data protection and stability.. SUSE PostgreSQL Update, Security Patch SUSE, Postgres Security Release. . Severity: Important. LinuxSecurity.com Team
An update that solves 4 vulnerabilities and has 5 bug fixes can now be installed.. openSUSE security update: security update for postgresql16 ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20447-1 Rating: important References: * bsc#1258008 * bsc#1258009 * bsc#1258010 * bsc#1258011 * bsc#1258754 Cross-References: * CVE-2026-2003 * CVE-2026-2004 * CVE-2026-2005 * CVE-2026-2006 CVSS scores: * CVE-2026-2003 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-2004 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-2005 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-2006 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 4 vulnerabilities and has 5 bug fixes can now be installed. Description: This update for postgresql16 fixes the following issues: - Update to versio 16.13. (bsc#1258754) - CVE-2026-2003: Guard against unexpected dimensions of oidvector/int2vector (bsc#1258008) - CVE-2026-2004: Harden selectivity estimators against being attached to operators that accept unexpected data types. (bsc#1258009) - CVE-2026-2005: Fix buffer overrun in contrib/pgcrypto's PGP decryption functions. (bsc#1258010) - CVE-2026-2006: Fix inadequate validation of multibyte character lengths. (bsc#1258011) Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-465=1 Package List: - openSUSE Leap 16.0: postgresql16-16.13-160000.1.1 postgresql16-contrib-16.13-160000.1.1 postgresql16-devel-16.13-160000.1.1 postgresql16-docs-16.13-160000.1.1 postgresql16-llvmjit-16.13-160000.1.1 postgresql16-llvmjit-devel-16.13-160000.1.1 postgresql16-plperl-16.13-160000.1.1 postgresql16-plpython-16.13-160000.1.1 postgresql16-pltcl-16.13-160000.1.1 postgresql16-server-16.13-160000.1.1 postgresql16-server-devel-16.13-160000.1.1 postgresql16-test-16.13-160000.1.1 References: * https://www.suse.com/security/cve/CVE-2026-2003.html * https://www.suse.com/security/cve/CVE-2026-2004.html * https://www.suse.com/security/cve/CVE-2026-2005.html * https://www.suse.com/security/cve/CVE-2026-2006.html . Four vulnerabilities fixed in postgresql16 update for openSUSE Leap 16.0 along with five bug fixes addressing critical issues.. openSUSE, postgresql16, security update, bug fixes. . Severity: Important. LinuxSecurity.com Team
An update that solves four vulnerabilities and has one security fix can now be installed.. # Security update for postgresql16 Announcement ID: SUSE-SU-2026:0882-1 Release Date: 2026-03-12T10:19:44Z Rating: important References: * bsc#1258008 * bsc#1258009 * bsc#1258010 * bsc#1258011 * bsc#1258754 Cross-References: * CVE-2026-2003 * CVE-2026-2004 * CVE-2026-2005 * CVE-2026-2006 CVSS scores: * CVE-2026-2003 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-2003 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-2004 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-2004 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-2005 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-2005 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-2006 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-2006 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * Legacy Module 15-SP7 * openSUSE Leap 15.6 * Server Applications Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves four vulnerabilities and has one security fix can now be installed. ## Description: This update for postgresql16 fixes the following issues: Update to version 16.13 (bsc#1258754). Security issues fixed: * CVE-2026-2003: improper validation of type "oidvector" may allow disclose a few bytes of server memory (bsc#1258008). * CVE-2026-2004: intarray missing validation of type of input to selectivity estimator could lead to arbitrary code execution (bsc#1258009). *CVE-2026-2005: buffer overrun in contrib/pgcrypto's PGP decryption functions could lead to arbitrary code execution (bsc#1258010). * CVE-2026-2006: inadequate validation of multibyte character lengths could lead to arbitrary code execution (bsc#1258011). Regression fixes: * the substring() function raises an error "invalid byte sequence for encoding" on non-ASCII text values if the source of that value is a database column (caused by CVE-2026-2006 fix). * a standby may halt and return an error "could not access status of transaction". ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-882=1 openSUSE-SLE-15.6-2026-882=1 * Legacy Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Legacy-15-SP7-2026-882=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-882=1 * Server Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2026-882=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-882=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-882=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * postgresql16-test-16.13-150600.16.30.1 * postgresql16-plpython-16.13-150600.16.30.1 * postgresql16-devel-16.13-150600.16.30.1 * postgresql16-16.13-150600.16.30.1 * postgresql16-pltcl-debuginfo-16.13-150600.16.30.1 * postgresql16-llvmjit-16.13-150600.16.30.1 * postgresql16-contrib-debuginfo-16.13-150600.16.30.1 * postgresql16-plpython-debuginfo-16.13-150600.16.30.1 * postgresql16-contrib-16.13-150600.16.30.1 * postgresql16-llvmjit-devel-16.13-150600.16.30.1 *postgresql16-debuginfo-16.13-150600.16.30.1 * postgresql16-llvmjit-debuginfo-16.13-150600.16.30.1 * postgresql16-server-debuginfo-16.13-150600.16.30.1 * postgresql16-debugsource-16.13-150600.16.30.1 * postgresql16-plperl-debuginfo-16.13-150600.16.30.1 * postgresql16-plperl-16.13-150600.16.30.1 * postgresql16-pltcl-16.13-150600.16.30.1 * postgresql16-server-16.13-150600.16.30.1 * postgresql16-devel-debuginfo-16.13-150600.16.30.1 * postgresql16-server-devel-debuginfo-16.13-150600.16.30.1 * postgresql16-server-devel-16.13-150600.16.30.1 * openSUSE Leap 15.6 (noarch) * postgresql16-docs-16.13-150600.16.30.1 * Legacy Module 15-SP7 (aarch64 ppc64le s390x x86_64) * postgresql16-debugsource-16.13-150600.16.30.1 * postgresql16-contrib-debuginfo-16.13-150600.16.30.1 * postgresql16-devel-debuginfo-16.13-150600.16.30.1 * postgresql16-contrib-16.13-150600.16.30.1 * postgresql16-debuginfo-16.13-150600.16.30.1 * postgresql16-devel-16.13-150600.16.30.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * postgresql16-debuginfo-16.13-150600.16.30.1 * postgresql16-test-16.13-150600.16.30.1 * postgresql16-llvmjit-16.13-150600.16.30.1 * postgresql16-debugsource-16.13-150600.16.30.1 * postgresql16-llvmjit-devel-16.13-150600.16.30.1 * postgresql16-llvmjit-debuginfo-16.13-150600.16.30.1 * Server Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * postgresql16-server-16.13-150600.16.30.1 * postgresql16-16.13-150600.16.30.1 * postgresql16-server-debuginfo-16.13-150600.16.30.1 * postgresql16-debugsource-16.13-150600.16.30.1 * postgresql16-debuginfo-16.13-150600.16.30.1 * postgresql16-server-devel-16.13-150600.16.30.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * postgresql16-server-16.13-150600.16.30.1 * postgresql16-16.13-150600.16.30.1 * postgresql16-pltcl-debuginfo-16.13-150600.16.30.1 * postgresql16-server-debuginfo-16.13-150600.16.30.1 *postgresql16-debugsource-16.13-150600.16.30.1 * postgresql16-contrib-debuginfo-16.13-150600.16.30.1 * postgresql16-devel-debuginfo-16.13-150600.16.30.1 * postgresql16-plperl-debuginfo-16.13-150600.16.30.1 * postgresql16-plpython-debuginfo-16.13-150600.16.30.1 * postgresql16-server-devel-debuginfo-16.13-150600.16.30.1 * postgresql16-contrib-16.13-150600.16.30.1 * postgresql16-debuginfo-16.13-150600.16.30.1 * postgresql16-plperl-16.13-150600.16.30.1 * postgresql16-plpython-16.13-150600.16.30.1 * postgresql16-server-devel-16.13-150600.16.30.1 * postgresql16-pltcl-16.13-150600.16.30.1 * postgresql16-devel-16.13-150600.16.30.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * postgresql16-docs-16.13-150600.16.30.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * postgresql16-server-16.13-150600.16.30.1 * postgresql16-16.13-150600.16.30.1 * postgresql16-pltcl-debuginfo-16.13-150600.16.30.1 * postgresql16-server-debuginfo-16.13-150600.16.30.1 * postgresql16-debugsource-16.13-150600.16.30.1 * postgresql16-contrib-debuginfo-16.13-150600.16.30.1 * postgresql16-devel-debuginfo-16.13-150600.16.30.1 * postgresql16-plperl-debuginfo-16.13-150600.16.30.1 * postgresql16-plpython-debuginfo-16.13-150600.16.30.1 * postgresql16-server-devel-debuginfo-16.13-150600.16.30.1 * postgresql16-contrib-16.13-150600.16.30.1 * postgresql16-debuginfo-16.13-150600.16.30.1 * postgresql16-plperl-16.13-150600.16.30.1 * postgresql16-plpython-16.13-150600.16.30.1 * postgresql16-server-devel-16.13-150600.16.30.1 * postgresql16-pltcl-16.13-150600.16.30.1 * postgresql16-devel-16.13-150600.16.30.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * postgresql16-docs-16.13-150600.16.30.1 ## References: * https://www.suse.com/security/cve/CVE-2026-2003.html * https://www.suse.com/security/cve/CVE-2026-2004.html * https://www.suse.com/security/cve/CVE-2026-2005.html *https://www.suse.com/security/cve/CVE-2026-2006.html * https://bugzilla.suse.com/show_bug.cgi?id=1258008 * https://bugzilla.suse.com/show_bug.cgi?id=1258009 * https://bugzilla.suse.com/show_bug.cgi?id=1258010 * https://bugzilla.suse.com/show_bug.cgi?id=1258011 * https://bugzilla.suse.com/show_bug.cgi?id=1258754 . SUSE issue an important security advisory for postgresql16 fixing issues including arbitrary code execution.. SUSE security update, postgresql16 security, security advisory, important software update.. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability and has one security fix can now be installed.. # Security update for postgresql16 Announcement ID: SUSE-SU-2026:0784-1 Release Date: 2026-03-03T13:42:39Z Rating: important References: * bsc#1258011 * bsc#1258754 Cross-References: * CVE-2026-2006 CVSS scores: * CVE-2026-2006 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-2006 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves one vulnerability and has one security fix can now be installed. ## Description: This update for postgresql16 fixes the following issue: Update to version 16.13 (bsc#1258754). Regression fixes: * the substring() function raises an error "invalid byte sequence for encoding" on non-ASCII text values if the source of that value is a database column (caused by CVE-2026-2006 fix). * a standby may halt and return an error "could not access status of transaction". ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-784=1 * SUSELinux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-784=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-784=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-784=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-784=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-784=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-784=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-784=1 ## Package List: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * postgresql16-contrib-debuginfo-16.13-150200.5.41.1 * postgresql16-debugsource-16.13-150200.5.41.1 * postgresql16-contrib-16.13-150200.5.41.1 * postgresql16-plperl-16.13-150200.5.41.1 * postgresql16-plperl-debuginfo-16.13-150200.5.41.1 * postgresql16-16.13-150200.5.41.1 * postgresql16-devel-16.13-150200.5.41.1 * postgresql16-server-debuginfo-16.13-150200.5.41.1 * postgresql16-debuginfo-16.13-150200.5.41.1 * postgresql16-pltcl-16.13-150200.5.41.1 * postgresql16-pltcl-debuginfo-16.13-150200.5.41.1 * postgresql16-server-16.13-150200.5.41.1 * postgresql16-plpython-16.13-150200.5.41.1 * postgresql16-server-devel-debuginfo-16.13-150200.5.41.1 * postgresql16-plpython-debuginfo-16.13-150200.5.41.1 * postgresql16-devel-debuginfo-16.13-150200.5.41.1 * postgresql16-server-devel-16.13-150200.5.41.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * postgresql16-docs-16.13-150200.5.41.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4(aarch64 x86_64) * postgresql16-contrib-debuginfo-16.13-150200.5.41.1 * postgresql16-debugsource-16.13-150200.5.41.1 * postgresql16-contrib-16.13-150200.5.41.1 * postgresql16-plperl-16.13-150200.5.41.1 * postgresql16-plperl-debuginfo-16.13-150200.5.41.1 * postgresql16-16.13-150200.5.41.1 * postgresql16-devel-16.13-150200.5.41.1 * postgresql16-server-debuginfo-16.13-150200.5.41.1 * postgresql16-debuginfo-16.13-150200.5.41.1 * postgresql16-pltcl-16.13-150200.5.41.1 * postgresql16-pltcl-debuginfo-16.13-150200.5.41.1 * postgresql16-server-16.13-150200.5.41.1 * postgresql16-plpython-16.13-150200.5.41.1 * postgresql16-server-devel-debuginfo-16.13-150200.5.41.1 * postgresql16-plpython-debuginfo-16.13-150200.5.41.1 * postgresql16-devel-debuginfo-16.13-150200.5.41.1 * postgresql16-server-devel-16.13-150200.5.41.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * postgresql16-docs-16.13-150200.5.41.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * postgresql16-contrib-debuginfo-16.13-150200.5.41.1 * postgresql16-debugsource-16.13-150200.5.41.1 * postgresql16-contrib-16.13-150200.5.41.1 * postgresql16-plperl-16.13-150200.5.41.1 * postgresql16-plperl-debuginfo-16.13-150200.5.41.1 * postgresql16-16.13-150200.5.41.1 * postgresql16-devel-16.13-150200.5.41.1 * postgresql16-server-debuginfo-16.13-150200.5.41.1 * postgresql16-debuginfo-16.13-150200.5.41.1 * postgresql16-pltcl-16.13-150200.5.41.1 * postgresql16-pltcl-debuginfo-16.13-150200.5.41.1 * postgresql16-server-16.13-150200.5.41.1 * postgresql16-plpython-16.13-150200.5.41.1 * postgresql16-server-devel-debuginfo-16.13-150200.5.41.1 * postgresql16-plpython-debuginfo-16.13-150200.5.41.1 * postgresql16-devel-debuginfo-16.13-150200.5.41.1 * postgresql16-server-devel-16.13-150200.5.41.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) *postgresql16-docs-16.13-150200.5.41.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * postgresql16-contrib-debuginfo-16.13-150200.5.41.1 * postgresql16-debugsource-16.13-150200.5.41.1 * postgresql16-contrib-16.13-150200.5.41.1 * postgresql16-plperl-16.13-150200.5.41.1 * postgresql16-plperl-debuginfo-16.13-150200.5.41.1 * postgresql16-16.13-150200.5.41.1 * postgresql16-devel-16.13-150200.5.41.1 * postgresql16-server-debuginfo-16.13-150200.5.41.1 * postgresql16-debuginfo-16.13-150200.5.41.1 * postgresql16-pltcl-16.13-150200.5.41.1 * postgresql16-pltcl-debuginfo-16.13-150200.5.41.1 * postgresql16-server-16.13-150200.5.41.1 * postgresql16-plpython-16.13-150200.5.41.1 * postgresql16-server-devel-debuginfo-16.13-150200.5.41.1 * postgresql16-plpython-debuginfo-16.13-150200.5.41.1 * postgresql16-devel-debuginfo-16.13-150200.5.41.1 * postgresql16-server-devel-16.13-150200.5.41.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * postgresql16-docs-16.13-150200.5.41.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * postgresql16-contrib-debuginfo-16.13-150200.5.41.1 * postgresql16-debugsource-16.13-150200.5.41.1 * postgresql16-contrib-16.13-150200.5.41.1 * postgresql16-plperl-16.13-150200.5.41.1 * postgresql16-plperl-debuginfo-16.13-150200.5.41.1 * postgresql16-16.13-150200.5.41.1 * postgresql16-devel-16.13-150200.5.41.1 * postgresql16-server-debuginfo-16.13-150200.5.41.1 * postgresql16-debuginfo-16.13-150200.5.41.1 * postgresql16-pltcl-16.13-150200.5.41.1 * postgresql16-pltcl-debuginfo-16.13-150200.5.41.1 * postgresql16-server-16.13-150200.5.41.1 * postgresql16-plpython-16.13-150200.5.41.1 * postgresql16-server-devel-debuginfo-16.13-150200.5.41.1 * postgresql16-plpython-debuginfo-16.13-150200.5.41.1 * postgresql16-devel-debuginfo-16.13-150200.5.41.1 *postgresql16-server-devel-16.13-150200.5.41.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * postgresql16-docs-16.13-150200.5.41.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * postgresql16-contrib-debuginfo-16.13-150200.5.41.1 * postgresql16-debugsource-16.13-150200.5.41.1 * postgresql16-contrib-16.13-150200.5.41.1 * postgresql16-plperl-16.13-150200.5.41.1 * postgresql16-plperl-debuginfo-16.13-150200.5.41.1 * postgresql16-16.13-150200.5.41.1 * postgresql16-devel-16.13-150200.5.41.1 * postgresql16-server-debuginfo-16.13-150200.5.41.1 * postgresql16-debuginfo-16.13-150200.5.41.1 * postgresql16-pltcl-16.13-150200.5.41.1 * postgresql16-pltcl-debuginfo-16.13-150200.5.41.1 * postgresql16-server-16.13-150200.5.41.1 * postgresql16-plpython-16.13-150200.5.41.1 * postgresql16-server-devel-debuginfo-16.13-150200.5.41.1 * postgresql16-plpython-debuginfo-16.13-150200.5.41.1 * postgresql16-devel-debuginfo-16.13-150200.5.41.1 * postgresql16-server-devel-16.13-150200.5.41.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * postgresql16-docs-16.13-150200.5.41.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * postgresql16-contrib-debuginfo-16.13-150200.5.41.1 * postgresql16-debugsource-16.13-150200.5.41.1 * postgresql16-contrib-16.13-150200.5.41.1 * postgresql16-plperl-16.13-150200.5.41.1 * postgresql16-plperl-debuginfo-16.13-150200.5.41.1 * postgresql16-16.13-150200.5.41.1 * postgresql16-devel-16.13-150200.5.41.1 * postgresql16-server-debuginfo-16.13-150200.5.41.1 * postgresql16-debuginfo-16.13-150200.5.41.1 * postgresql16-pltcl-16.13-150200.5.41.1 * postgresql16-pltcl-debuginfo-16.13-150200.5.41.1 * postgresql16-server-16.13-150200.5.41.1 * postgresql16-plpython-16.13-150200.5.41.1 * postgresql16-server-devel-debuginfo-16.13-150200.5.41.1 * postgresql16-plpython-debuginfo-16.13-150200.5.41.1 *postgresql16-devel-debuginfo-16.13-150200.5.41.1 * postgresql16-server-devel-16.13-150200.5.41.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * postgresql16-docs-16.13-150200.5.41.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * postgresql16-contrib-debuginfo-16.13-150200.5.41.1 * postgresql16-debugsource-16.13-150200.5.41.1 * postgresql16-contrib-16.13-150200.5.41.1 * postgresql16-plperl-16.13-150200.5.41.1 * postgresql16-plperl-debuginfo-16.13-150200.5.41.1 * postgresql16-16.13-150200.5.41.1 * postgresql16-devel-16.13-150200.5.41.1 * postgresql16-server-debuginfo-16.13-150200.5.41.1 * postgresql16-debuginfo-16.13-150200.5.41.1 * postgresql16-pltcl-16.13-150200.5.41.1 * postgresql16-pltcl-debuginfo-16.13-150200.5.41.1 * postgresql16-server-16.13-150200.5.41.1 * postgresql16-plpython-16.13-150200.5.41.1 * postgresql16-server-devel-debuginfo-16.13-150200.5.41.1 * postgresql16-plpython-debuginfo-16.13-150200.5.41.1 * postgresql16-devel-debuginfo-16.13-150200.5.41.1 * postgresql16-server-devel-16.13-150200.5.41.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * postgresql16-docs-16.13-150200.5.41.1 ## References: * https://www.suse.com/security/cve/CVE-2026-2006.html * https://bugzilla.suse.com/show_bug.cgi?id=1258011 * https://bugzilla.suse.com/show_bug.cgi?id=1258754 . Critical update for postgresql16 in SUSE to resolve a significant security issue. Immediate action is recommended.. SUSE security, PostgreSQL update, important security fix. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.