Skip to content
Debian PostgreSQL DSA-6438

Debian PostgreSQL DSA-6438

Linuxsecurity •LinuxSecurity Advisories • August 13, 2026

Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges ×

The upstream fix to address CVE-2026-6471 requires additional changes to the configuration if some extensions are used. This affects the postgresql-17-wal2json, postgresql-17-squeeze, postgresql-17-pg-rewrite and postgresql-17-decoderbufs extensions included in Debian. Quoting from the changelog: | Restrict logical decoding output plugins to the set specified by | a new server parameter `output_plugin_libraries` (Jacob | Champion) | Previously, a replication user could select any loadable library | | Restrict logical decoding output plugins to the set specified by | a new server parameter `output_plugin_libraries` (Jacob | Champion) | Previously, a replication user could select any loadable library | for logical decoding, allowing exploits of various sorts. To | allow locking this down without breaking setups that worked | before, introduce a whitelist of allowed output plugins. | | By default, only the output plugins shipped as part of | PostgreSQL (`pgoutput` and `test_decoding`) are included in |`ou...

Get the latest Linux and open source security news straight to your inbox.

Extracted Entities

CVEs (1)