Back Linuxsecurity Debian PostgreSQL DSA-6438
Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges ×
The upstream fix to address CVE-2026-6471 requires additional changes to the configuration if some extensions are used. This affects the postgresql-17-wal2json, postgresql-17-squeeze, postgresql-17-pg-rewrite and postgresql-17-decoderbufs extensions included in Debian. Quoting from the changelog: | Restrict logical decoding output plugins to the set specified by | a new server parameter `output_plugin_libraries` (Jacob | Champion) | Previously, a replication user could select any loadable library | | Restrict logical decoding output plugins to the set specified by | a new server parameter `output_plugin_libraries` (Jacob | Champion) | Previously, a replication user could select any loadable library | for logical decoding, allowing exploits of various sorts. To | allow locking this down without breaking setups that worked | before, introduce a whitelist of allowed output plugins. | | By default, only the output plugins shipped as part of | PostgreSQL (`pgoutput` and `test_decoding`) are included in |`ou...
Get the latest Linux and open source security news straight to your inbox.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
