[CLSA-2026:1787230283] Fix CVE(s): CVE-2023-39417, CVE-2023-5869, CVE-2024-0985
Type:
security
Severity:
Important
Release date:
2026-08-20 12:51:35 UTC
Description:
* SECURITY UPDATE: Reject substituting extension schemas containing quoting-relevant characters, preventing SQL injection via @extschema@ in extension scripts - debian/patches/CVE-2023-39417.patch: Reject substituting extension schemas containing quoting-relevant characters, preventing SQL injection via @extschema@ in extension scripts - CVE-2023-39417 * SECURITY UPDATE: Detect integer overflow while computing new array dimensions in array_set_element(), array_set_element_expanded() and array_set_slice() - debian/patches/CVE-2023-5869.patch: Detect integer overflow while computing new array dimensions in array_set_element(), array_set_element_expanded() and array_set_slice() - CVE-2023-5869 * SECURITY UPDATE: Run REFRESH MATERIALIZED VIEW CONCURRENTLY in the right security context when creating the temporary diff table - debian/patches/CVE-2024-0985.patch: Run REFRESH MATERIALIZED VIEW CONCURRENTLY in the right security context when creating the temporary diff table - CVE-2024-0985
Updated packages:
  • libecpg-compat3-9.6_9.6.24-0+deb10u1+tuxcare.els3_amd64.deb
    sha:dfadf48c275013a8e91be1bdd498de47a3c050b4
  • libecpg-dev-9.6_9.6.24-0+deb10u1+tuxcare.els3_amd64.deb
    sha:3ab3246d63de509b84f17c754259c21b36487b06
  • libecpg6-9.6_9.6.24-0+deb10u1+tuxcare.els3_amd64.deb
    sha:369f079addb94ad1979138c80e1f59edf2b25c97
  • libpgtypes3-9.6_9.6.24-0+deb10u1+tuxcare.els3_amd64.deb
    sha:76131ec08b7ac640f10b6eae9b348075db303054
  • libpq-dev-9.6_9.6.24-0+deb10u1+tuxcare.els3_amd64.deb
    sha:67cd8b5f5be35f92012c7902f2aa0979c8d2b87e
  • libpq5-9.6_9.6.24-0+deb10u1+tuxcare.els3_amd64.deb
    sha:d015cf08078573beb8f5ef0a485f6b21f8580355
  • postgresql-9.6_9.6.24-0+deb10u1+tuxcare.els3_amd64.deb
    sha:a2ae82833db1a0c11448dbeae3ea9d2b62ff59d3
  • postgresql-client-9.6_9.6.24-0+deb10u1+tuxcare.els3_amd64.deb
    sha:2cf1b52da099c1b0d9c90d3117a624068813dc10
  • postgresql-contrib-9.6_9.6.24-0+deb10u1+tuxcare.els3_amd64.deb
    sha:306b84d2e3cdc0e70775a46ae9f1589af458c6ba
  • postgresql-doc-9.6_9.6.24-0+deb10u1+tuxcare.els3_all.deb
    sha:a5ad56dc061a121c057ac1ef786c3ce79e94c0a8
  • postgresql-plperl-9.6_9.6.24-0+deb10u1+tuxcare.els3_amd64.deb
    sha:b0761cd5b69de1928f356a6744ab5b01df39ab8d
  • postgresql-plpython-9.6_9.6.24-0+deb10u1+tuxcare.els3_amd64.deb
    sha:d6e6816676b1c090529d6f1cceeff41ebbec865f
  • postgresql-plpython3-9.6_9.6.24-0+deb10u1+tuxcare.els3_amd64.deb
    sha:2c253bfed9df191498d5df2b3378417f7aa7e7ee
  • postgresql-pltcl-9.6_9.6.24-0+deb10u1+tuxcare.els3_amd64.deb
    sha:b5054d2ea3eaed8d474e9a79571fe633c1044358
  • postgresql-server-dev-9.6_9.6.24-0+deb10u1+tuxcare.els3_amd64.deb
    sha:be1766671b2f8fdbd85aea5368ded08c2fdc611a
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.