Skip to content
Ubuntu PostgreSQL Critical Buffer Overflow SQL Injection Vuln 8653

Ubuntu PostgreSQL Critical Buffer Overflow SQL Injection Vuln 8653

Linuxsecurity •LinuxSecurity Advisories • August 20, 2026

Find practical guidance for preventing, investigating, and responding to Linux security problems. Review Linux Privileges ×

Several security issues were fixed in PostgreSQL. Software Description: - postgresql-18: Object-relational SQL database - postgresql-16: Object-relational SQL database - postgresql-14: Object-relational SQL database Details: It was discovered that PostgreSQL incorrectly handled COPY FROM STDIN when an early failure occurred. An authenticated user could possibly use this issue to execute arbitrary SQL commands. (CVE-2026-6464) It was discovered that PostgreSQL incorrectly reset extended statistics ownership during ALTER TABLE ALTER TYPE operations. An attacker could possibly use this issue to obtain sensitive information or gain unintended privileges. (CVE-2026-6469) It was discovered that PostgreSQL failed to check the USAGE privilege on types. An authenticated user could possibly use this issue to obtain sensitive information. (CVE-2026-6470) It was discovered that PostgreSQL logical decoding could load arbitrary shared libraries. An authenticated user could possibly use thi... Read the Full Advisory

Several security issues were fixed in PostgreSQL.

Software Description:

- postgresql-18: Object-relational SQL database

- postgresql-16: Object-relational SQL database

- postgresql-14: Object-relational SQL database

It was discovered that PostgreSQL incorrectly handled COPY FROM STDIN when

an early failure occurred. An authenticated user could possibly use this

issue to execute arbitrary SQL commands. (CVE-2026-6464)

It was discovered that PostgreSQL incorrectly reset extended statistics

ownership during ALTER TABLE ALTER TYPE operations. An attacker could

possibly use this issue to obtain sensitive information or gain unintended

privileges. (CVE-2026-6469)

It was discovered that PostgreSQL failed to check the USAGE privilege on

types. An authenticated user could possibly use this issue to obtain

sensitive information. (CVE-2026-6470)

It was discovered that PostgreSQL logical decoding could load arbitrary

shared libraries. An authenticated user could possibly use thi...

The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS postgresql-18 18.6-0ubuntu0.26.04.1 Ubuntu 24.04 LTS postgresql-16 16.15-0ubuntu0.24.04.1 Ubuntu 22.04 LTS postgresql-14 14.24-0ubuntu0.22.04.1 This update uses a new upstream release, which includes additional bug fixes. After a standard system update you need to restart PostgreSQL to make all the necessary changes.

CVE-2025-8714, CVE-2026-14662, CVE-2026-14663, CVE-2026-14664,

CVE-2026-14666, CVE-2026-14668, CVE-2026-14669, CVE-2026-14670,

CVE-2026-14671, CVE-2026-14672, CVE-2026-14673, CVE-2026-14676,

CVE-2026-14677, CVE-2026-14678, CVE-2026-14679, CVE-2026-14680,

CVE-2026-14681, CVE-2026-15741, CVE-2026-15742, CVE-2026-16238,

CVE-2026-16239, CVE-2026-16241, CVE-2026-18024, CVE-2026-18408,

CVE-2026-19385, CVE-2026-6464, CVE-2026-6469, CVE-2026-6470,

CVE-2026-6471, CVE-2026-6473

Ubuntu Security Notice USN-8653-1

Get the latest Linux and open source security news straight to your inbox.