Back Linuxsecurity Ubuntu PostgreSQL Critical Buffer Overflow SQL Injection Vuln 8653
Find practical guidance for preventing, investigating, and responding to Linux security problems. Review Linux Privileges ×
Several security issues were fixed in PostgreSQL. Software Description: - postgresql-18: Object-relational SQL database - postgresql-16: Object-relational SQL database - postgresql-14: Object-relational SQL database Details: It was discovered that PostgreSQL incorrectly handled COPY FROM STDIN when an early failure occurred. An authenticated user could possibly use this issue to execute arbitrary SQL commands. (CVE-2026-6464) It was discovered that PostgreSQL incorrectly reset extended statistics ownership during ALTER TABLE ALTER TYPE operations. An attacker could possibly use this issue to obtain sensitive information or gain unintended privileges. (CVE-2026-6469) It was discovered that PostgreSQL failed to check the USAGE privilege on types. An authenticated user could possibly use this issue to obtain sensitive information. (CVE-2026-6470) It was discovered that PostgreSQL logical decoding could load arbitrary shared libraries. An authenticated user could possibly use thi... Read the Full Advisory
Several security issues were fixed in PostgreSQL.
Software Description:
- postgresql-18: Object-relational SQL database
- postgresql-16: Object-relational SQL database
- postgresql-14: Object-relational SQL database
It was discovered that PostgreSQL incorrectly handled COPY FROM STDIN when
an early failure occurred. An authenticated user could possibly use this
issue to execute arbitrary SQL commands. (CVE-2026-6464)
It was discovered that PostgreSQL incorrectly reset extended statistics
ownership during ALTER TABLE ALTER TYPE operations. An attacker could
possibly use this issue to obtain sensitive information or gain unintended
privileges. (CVE-2026-6469)
It was discovered that PostgreSQL failed to check the USAGE privilege on
types. An authenticated user could possibly use this issue to obtain
sensitive information. (CVE-2026-6470)
It was discovered that PostgreSQL logical decoding could load arbitrary
shared libraries. An authenticated user could possibly use thi...
The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS postgresql-18 18.6-0ubuntu0.26.04.1 Ubuntu 24.04 LTS postgresql-16 16.15-0ubuntu0.24.04.1 Ubuntu 22.04 LTS postgresql-14 14.24-0ubuntu0.22.04.1 This update uses a new upstream release, which includes additional bug fixes. After a standard system update you need to restart PostgreSQL to make all the necessary changes.
CVE-2025-8714, CVE-2026-14662, CVE-2026-14663, CVE-2026-14664,
CVE-2026-14666, CVE-2026-14668, CVE-2026-14669, CVE-2026-14670,
CVE-2026-14671, CVE-2026-14672, CVE-2026-14673, CVE-2026-14676,
CVE-2026-14677, CVE-2026-14678, CVE-2026-14679, CVE-2026-14680,
CVE-2026-14681, CVE-2026-15741, CVE-2026-15742, CVE-2026-16238,
CVE-2026-16239, CVE-2026-16241, CVE-2026-18024, CVE-2026-18408,
CVE-2026-19385, CVE-2026-6464, CVE-2026-6469, CVE-2026-6470,
Ubuntu Security Notice USN-8653-1
Get the latest Linux and open source security news straight to your inbox.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
