USN-8653-1: PostgreSQL vulnerabilities
It was discovered that PostgreSQL incorrectly handled COPY FROM STDIN when an early failure occurred. An authenticated user could possibly use this issue to execute arbitrary SQL commands. (CVE-2026-6464) It was discovered that PostgreSQL incorrectly reset extended statistics ownership during ALTER TABLE ALTER TYPE operations. An attacker could possibly use this issue to obtain sensitive information or gain unintended privileges. (CVE-2026-6469) It was discovered that PostgreSQL failed to check the USAGE privilege on types. An authenticated user could possibly use this issue to obtain sensitive information. (CVE-2026-6470) It was discovered that PostgreSQL logical decoding could load arbitrary shared libraries. An authenticated user could possibly use this issue to execute arbitrary code. (CVE-2026-6471) It was discovered that PostgreSQL had integer wraparound issues in tsvector and tsquery allocations. An authenticated user could possibly use this issue to execute arbitrary code. (CVE-2026-14662) It was discovered that PostgreSQL pgcrypto silently used cleartext when OpenSSL-disabled ciphers were requested. An authenticated user could possibly use this issue to obtain sensitive information. (CVE-2026-14663) It was discovered that PostgreSQL had a heap buffer overflow in regular expression processing. An authenticated user could possibly use this issue to execute arbitrary code. (CVE-2026-14664) It was discovered that PostgreSQL row security policies were not properly invalidated when roles were modified. An attacker could possibly use this issue to bypass intended row security restrictions. (CVE-2026-14666) It was discovered that PostgreSQL had a type confusion issue in the selectivity estimator involving ctid. An authenticated user could possibly use this issue to obtain sensitive information. (CVE-2026-14668) It was discovered that PostgreSQL had a heap buffer overflow in the to_char function. An authenticated user could possibly use this issue to execute arbitra
CSIRTS triage
- What
- PostgreSQL contains multiple vulnerabilities including arbitrary SQL execution via COPY FROM STDIN, privilege escalation via ALTER TABLE operations, unguarded USAGE privilege checks, and arbitrary shared library loading via logical decoding.
- Who is affected
- Authenticated users of PostgreSQL installations are able to exploit these vulnerabilities.
- Urgency
- High urgency; multiple high-severity vulnerabilities affecting core database functionality require immediate patching.
- Action
- Update PostgreSQL to a version addressing CVE-2026-6464, CVE-2026-6469, CVE-2026-6470, CVE-2026-6471, and related CVEs.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch PostgreSQL
Get an email when a new PostgreSQL advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://ubuntu.com/security/notices/USN-8653-1
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-64640.49% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 40% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-64690.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-64700.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-64710.51% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 42% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-146620.67% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 49% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-146630.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-146640.61% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 46% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-146660.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 11% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-146680.46% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 39% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-146690.61% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 46% of all EPSS-scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] PostgreSQL: Multiple vulnerabilitiescert-bund
- unknownMultiple vulnerabilities in PostgreSQL (August 14, 2026)cert-fr-avis
- highCVE-2026-6471: Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION…nvd
- mediumCVE-2026-6470: Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of …nvd
- lowCVE-2026-6469: Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership…nvd
- highCVE-2026-6464: Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit exe…nvd
- highCVE-2026-19385: Heap buffer overflow in PostgreSQL pg_dump of long function transform lists allows an object c…nvd
- highCVE-2026-18408: Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin s…nvd
- mediumCVE-2026-18024: Buffer over-read in PostgreSQL ascii() SQL function allows a user to disclose up to 3 bytes af…nvd
- lowCVE-2026-16241: Integer underflow in PostgreSQL ECPG allows a database server administrator to achieve tempora…nvd
- highCVE-2026-16239: Type confusion in PostgreSQL "portal"/cursor lifecycle allows a user to execute arbitrary code…nvd
- highCVE-2026-16238: Type confusion in PostgreSQL pg_restore_attribute_stats() allows an object creator to execute …nvd
More from Ubuntu Security Notices
- unknownUSN-8659-4: Linux kernel (Oracle) vulnerability2026-08-26
- unknownUSN-8666-2: Linux kernel (Azure) vulnerabilities2026-08-25
- unknownUSN-8630-5: Linux kernel (Raspberry Pi) vulnerabilities2026-08-25
- unknownUSN-8658-3: Linux kernel vulnerabilities2026-08-25
- unknownUSN-8643-4: Linux kernel vulnerabilities2026-08-25