<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 19:20:12 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:19009 — Important: postgresql18 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:19009</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: postgresql18, AlmaLinux:10: postgresql18-contrib, AlmaLinux:10: postgresql18-docs, AlmaLinux:10: postgresql18-plperl, AlmaLinux:10: postgresql18-plpython3, AlmaLinux:10: postgresql18-private-devel, AlmaLinux:10: postgresql18-private-libs, AlmaLinux:10: postgresql18-server, AlmaLinux:10: postgresql18-server-devel, AlmaLinux:10: postgresql18-static and 4 more&lt;/p&gt;
&lt;p&gt;PostgreSQL is an advanced Object-Relational database management system (DBMS). The base postgresql package contains the client programs that you&amp;#39;ll need to access a PostgreSQL DBMS server, as well as HTML documentation for the whole system. These client programs can be located on the same machine as the PostgreSQL server, or on a remote machine that accesses a PostgreSQL server over a network connection. The PostgreSQL server can be found in the postgresql-server sub-package.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* postgresql: PostgreSQL pg_trgm heap buffer overflow writes pattern onto server memory (CVE-2026-2007)
  * postgresql: PostgreSQL oidvector discloses a few bytes of memory (CVE-2026-2003)
  * postgresql: PostgreSQL missing validation of multibyte character length executes arbitrary code (CVE-2026-2006)
  * postgresql: PostgreSQL intarray missing validation of type of input to selectivity estimator executes arbitrary code (CVE-2026-2004)
  * postgresql: PostgreSQL pgcrypto heap buffer overflow executes arbitrary code (CVE-2026-2005)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: postgresql18, AlmaLinux:10: postgresql18-contrib, AlmaLinux:10: postgresql18-docs, AlmaLinux:10: postgresql18-plperl, AlmaLinux:10: postgresql18-plpython3, AlmaLinux:10: postgresql18-private-devel, AlmaLinux:10: postgresql18-private-libs, AlmaLinux:10: postgresql18-server, AlmaLinux:10: postgresql18-server-devel, AlmaLinux:10: postgresql18-static and 4 more&lt;/p&gt;
&lt;p&gt;PostgreSQL is an advanced Object-Relational database management system (DBMS). The base postgresql package contains the client programs that you&amp;#39;ll need to access a PostgreSQL DBMS server, as well as HTML documentation for the whole system. These client programs can be located on the same machine as the PostgreSQL server, or on a remote machine that accesses a PostgreSQL server over a network connection. The PostgreSQL server can be found in the postgresql-server sub-package.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* postgresql: PostgreSQL pg_trgm heap buffer overflow writes pattern onto server memory (CVE-2026-2007)
  * postgresql: PostgreSQL oidvector discloses a few bytes of memory (CVE-2026-2003)
  * postgresql: PostgreSQL missing validation of multibyte character length executes arbitrary code (CVE-2026-2006)
  * postgresql: PostgreSQL intarray missing validation of type of input to selectivity estimator executes arbitrary code (CVE-2026-2004)
  * postgresql: PostgreSQL pgcrypto heap buffer overflow executes arbitrary code (CVE-2026-2005)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:19009</guid>
    </item>
    <item>
      <title>bdu:2026-01724</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-01724</link>
      <description>bdu:2026-01724</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-01724</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-2007</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-2007</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: postgresql15, Alpaquita:25: postgresql17, Alpaquita:stream: postgresql18&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: postgresql15, Alpaquita:25: postgresql17, Alpaquita:stream: postgresql18&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-2007</guid>
    </item>
    <item>
      <title>BIT-postgresql-2026-2007 — PostgreSQL pg_trgm heap buffer overflow writes pattern onto server memory</title>
      <link>https://cve.radiocsirt.org/vuln/bit-postgresql-2026-2007</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: postgresql&lt;/p&gt;
&lt;p&gt;Heap buffer overflow in PostgreSQL pg_trgm allows a database user to achieve unknown impacts via a crafted input string.  The attacker has limited control over the byte patterns to be written, but we have not ruled out the viability of attacks that lead to privilege escalation.  PostgreSQL 18.1 and 18.0 are affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: postgresql&lt;/p&gt;
&lt;p&gt;Heap buffer overflow in PostgreSQL pg_trgm allows a database user to achieve unknown impacts via a crafted input string.  The attacker has limited control over the byte patterns to be written, but we have not ruled out the viability of attacks that lead to privilege escalation.  PostgreSQL 18.1 and 18.0 are affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-postgresql-2026-2007</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0164 — De multiples vulnérabilités ont été découvertes dans PostgreSQL. Elles permettent à un attaquant de provoquer une exécu…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0164</link>
      <description>certfr-2026-avi-0164</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0164</guid>
    </item>
    <item>
      <title>EUVD-2026-337521</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-337521</link>
      <description>EUVD-2026-337521</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-337521</guid>
    </item>
    <item>
      <title>fkie_cve-2026-2007</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-2007</link>
      <description>&lt;p&gt;Heap buffer overflow in PostgreSQL pg_trgm allows a database user to achieve unknown impacts via a crafted input string.  The attacker has limited control over the byte patterns to be written, but we have not ruled out the viability of attacks that lead to privilege escalation.  PostgreSQL 18.1 and 18.0 are affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Heap buffer overflow in PostgreSQL pg_trgm allows a database user to achieve unknown impacts via a crafted input string.  The attacker has limited control over the byte patterns to be written, but we have not ruled out the viability of attacks that lead to privilege escalation.  PostgreSQL 18.1 and 18.0 are affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-2007</guid>
    </item>
    <item>
      <title>GHSA-5pr9-9395-q5gq</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-5pr9-9395-q5gq</link>
      <description>&lt;p&gt;Heap buffer overflow in PostgreSQL pg_trgm allows a database user to achieve unknown impacts via a crafted input string.  The attacker has limited control over the byte patterns to be written, but we have not ruled out the viability of attacks that lead to privilege escalation.  PostgreSQL 18.1 and 18.0 are affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Heap buffer overflow in PostgreSQL pg_trgm allows a database user to achieve unknown impacts via a crafted input string.  The attacker has limited control over the byte patterns to be written, but we have not ruled out the viability of attacks that lead to privilege escalation.  PostgreSQL 18.1 and 18.0 are affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-5pr9-9395-q5gq</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10197-1 — libecpg6-18.2-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10197-1</link>
      <description>&lt;p&gt;libecpg6-18.2-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libecpg6-18.2-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10197-1</guid>
    </item>
    <item>
      <title>RHSA-2026:8756 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:8756</link>
      <description>&lt;p&gt;postgresql: improper privilege check during certain RESET ALL operations postgresql: CREATE STATISTICS does not check for schema CREATE privilege postgresql: libpq: libpq undersizes allocations, via integer wraparound postgresql: PostgreSQL oidvector discloses a few bytes of memory postgresql: PostgreSQL intarray missing validation of type of input to selectivity estimator executes arbitrary code postgresql: PostgreSQL pgcrypto heap buffer overflow executes arbitrary code postgresql: PostgreSQL missing validation of multibyte character length executes arbitrary code postgresql: PostgreSQL pg_trgm heap buffer overflow writes pattern onto server memory&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;postgresql: improper privilege check during certain RESET ALL operations postgresql: CREATE STATISTICS does not check for schema CREATE privilege postgresql: libpq: libpq undersizes allocations, via integer wraparound postgresql: PostgreSQL oidvector discloses a few bytes of memory postgresql: PostgreSQL intarray missing validation of type of input to selectivity estimator executes arbitrary code postgresql: PostgreSQL pgcrypto heap buffer overflow executes arbitrary code postgresql: PostgreSQL missing validation of multibyte character length executes arbitrary code postgresql: PostgreSQL pg_trgm heap buffer overflow writes pattern onto server memory&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:8756</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:0585-1 — Security update for postgresql18</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:0585-1</link>
      <description>&lt;p&gt;Security update for postgresql18&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for postgresql18&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:0585-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-2007</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-2007</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: postgresql-9.3&lt;/p&gt;
&lt;p&gt;Heap buffer overflow in PostgreSQL pg_trgm allows a database user to achieve unknown impacts via a crafted input string.  The attacker has limited control over the byte patterns to be written, but we have not ruled out the viability of attacks that lead to privilege escalation.  PostgreSQL 18.1 and 18.0 are affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: postgresql-9.3&lt;/p&gt;
&lt;p&gt;Heap buffer overflow in PostgreSQL pg_trgm allows a database user to achieve unknown impacts via a crafted input string.  The attacker has limited control over the byte patterns to be written, but we have not ruled out the viability of attacks that lead to privilege escalation.  PostgreSQL 18.1 and 18.0 are affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-2007</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0409 — PostgreSQL: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0409</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter oder anonymer Angreifer kann mehrere Schwachstellen in PostgreSQL ausnutzen, um Informationen offenzulegen, beliebigen Code auszuführen und nicht näher bezeichnete Angriffe durchzuführen, was möglicherweise zu einer Ausweitung der Berechtigungen führen kann.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter oder anonymer Angreifer kann mehrere Schwachstellen in PostgreSQL ausnutzen, um Informationen offenzulegen, beliebigen Code auszuführen und nicht näher bezeichnete Angriffe durchzuführen, was möglicherweise zu einer Ausweitung der Berechtigungen führen kann.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0409</guid>
    </item>
  </channel>
</rss>
