CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

USN-8653-1: PostgreSQL vulnerabilities

unknownpublic exploitCVE-2026-6464CVE-2026-6469CVE-2026-6470CVE-2026-6471CVE-2026-14662CVE-2026-14663
It was discovered that PostgreSQL incorrectly handled COPY FROM STDIN when an early failure occurred. An authenticated user could possibly use this issue to execute arbitrary SQL commands. (CVE-2026-6464) It was discovered that PostgreSQL incorrectly reset extended statistics ownership during ALTER TABLE ALTER TYPE operations. An attacker could possibly use this issue to obtain sensitive information or gain unintended privileges. (CVE-2026-6469) It was discovered that PostgreSQL failed to check the USAGE privilege on types. An authenticated user could possibly use this issue to obtain sensitive information. (CVE-2026-6470) It was discovered that PostgreSQL logical decoding could load arbitrary shared libraries. An authenticated user could possibly use this issue to execute arbitrary code. (CVE-2026-6471) It was discovered that PostgreSQL had integer wraparound issues in tsvector and tsquery allocations. An authenticated user could possibly use this issue to execute arbitrary code. (CVE-2026-14662) It was discovered that PostgreSQL pgcrypto silently used cleartext when OpenSSL-disabled ciphers were requested. An authenticated user could possibly use this issue to obtain sensitive information. (CVE-2026-14663) It was discovered that PostgreSQL had a heap buffer overflow in regular expression processing. An authenticated user could possibly use this issue to execute arbitrary code. (CVE-2026-14664) It was discovered that PostgreSQL row security policies were not properly invalidated when roles were modified. An attacker could possibly use this issue to bypass intended row security restrictions. (CVE-2026-14666) It was discovered that PostgreSQL had a type confusion issue in the selectivity estimator involving ctid. An authenticated user could possibly use this issue to obtain sensitive information. (CVE-2026-14668) It was discovered that PostgreSQL had a heap buffer overflow in the to_char function. An authenticated user could possibly use this issue to execute arbitra

CSIRTS triage

What
PostgreSQL contains multiple vulnerabilities including arbitrary SQL execution via COPY FROM STDIN, privilege escalation via ALTER TABLE operations, unguarded USAGE privilege checks, and arbitrary shared library loading via logical decoding.
Who is affected
Authenticated users of PostgreSQL installations are able to exploit these vulnerabilities.
Urgency
High urgency; multiple high-severity vulnerabilities affecting core database functionality require immediate patching.
Action
Update PostgreSQL to a version addressing CVE-2026-6464, CVE-2026-6469, CVE-2026-6470, CVE-2026-6471, and related CVEs.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch PostgreSQL

Get an email when a new PostgreSQL advisory drops — max one per day, one-click unsubscribe.

Details

Source
Ubuntu Security Notices (INTL · vendor-psirt · site)
Severity
unknown
Published
2026-08-20
Exploitation
Not in CISA KEV at last sync

Original advisory: https://ubuntu.com/security/notices/USN-8653-1

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-6464coverage & exploitation statusNVD · CVE.org
CVE-2026-6469coverage & exploitation statusNVD · CVE.org
CVE-2026-6470coverage & exploitation statusNVD · CVE.org
CVE-2026-6471coverage & exploitation statusNVD · CVE.org
CVE-2026-14662coverage & exploitation statusNVD · CVE.org
CVE-2026-14663coverage & exploitation statusNVD · CVE.org
CVE-2026-14664coverage & exploitation statusNVD · CVE.org
CVE-2026-14666coverage & exploitation statusNVD · CVE.org
CVE-2026-14668coverage & exploitation statusNVD · CVE.org
CVE-2026-14669coverage & exploitation statusNVD · CVE.org
CVE-2026-14670coverage & exploitation statusNVD · CVE.org
CVE-2026-14671coverage & exploitation statusNVD · CVE.org
CVE-2026-14672coverage & exploitation statusNVD · CVE.org
CVE-2026-14673coverage & exploitation statusNVD · CVE.org
CVE-2026-14676coverage & exploitation statusNVD · CVE.org
CVE-2026-14677coverage & exploitation statusNVD · CVE.org
CVE-2026-14678coverage & exploitation statusNVD · CVE.org
CVE-2026-14679coverage & exploitation statusNVD · CVE.org
CVE-2026-14680coverage & exploitation statusNVD · CVE.org
CVE-2026-14681coverage & exploitation statusNVD · CVE.org
CVE-2026-15741coverage & exploitation statusNVD · CVE.org
CVE-2026-15742coverage & exploitation statusNVD · CVE.org
CVE-2026-16238coverage & exploitation statusNVD · CVE.org
CVE-2026-16239coverage & exploitation statusNVD · CVE.org
CVE-2026-16241coverage & exploitation statusNVD · CVE.org
CVE-2026-18024coverage & exploitation statusNVD · CVE.org
CVE-2026-18408coverage & exploitation statusNVD · CVE.org
CVE-2026-19385coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from Ubuntu Security Notices