Back Linuxsecurity SUSE PostgreSQL 15 Key Buffer Overflow and SQL Injection Issues Addressed
Keep your Linux systems secure and up to date with practical patching guidance. Review Linux Patching Best Practices ×
## This update for postgresql15 fixes the following issues: * CVE-2026-6464: `psql` `COPY FROM STDIN` early failure processes data lines as `psql` commands (bsc#1275046). * CVE-2026-6469: `ALTER TABLE ALTER TYPE` resets extended statistics ownership (bsc#1275044). * CVE-2026-6470: failure to check type `USAGE` privilege (bsc#1275043). * CVE-2026-6471: logical decoding can `dlopen` arbitrary file (bsc#1275042). * CVE-2026-14662: `tsvector` and `tsquery` undersize allocations, via integer wraparound (bsc#1275001). * CVE-2026-14663: `pgcrypto`, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext (bsc#1275002). * CVE-2026-14664: `regexp` heap buffer overflow executes arbitrary code (bsc#1275068).
## This update for postgresql15 fixes the following issues: * CVE-2026-6464: `psql` `COPY FROM STDIN` early failure processes data lines as `psql` commands (bsc#1275046). * CVE-2026-6469: `ALTER TABLE ALTER TYPE` resets extended statistics ownership (bsc#1275044). * CVE-2026-6470: failure to check type `USAGE` privilege (bsc#1275043). * CVE-2026-6471: logical decoding can `dlopen` arbitrary file (bsc#1275042). * CVE-2026-14662: `tsvector` and `tsquery` undersize allocations, via integer wraparound (bsc#1275001). * CVE-2026-14663: `pgcrypto`, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext (bsc#1275002). * CVE-2026-14664: `regexp` heap buffer overflow executes arbitrary code (bsc#1275068).
Announcement ID: SUSE-SU-2026:3940-1 Release Date: 2026-09-03T07:32:49Z Rating: important
Get the latest News and Insights
Get the latest Linux and open source security news straight to your inbox.
Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
