Alpine: multiple postgresql17 packages: security update to 17.11-r0

high Tenable Cloud Security Plugin ID 445995

Description

There are packages installed that are affected by multiple vulnerabilities referenced in the following CVEs:

- Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to
inject arbitrary code for restore-time execution as the client operating system account running psql to
restore the dump, via psql \restrict meta-command input expansion. The fix for CVE-2025-8714 introduced
\restrict and \unrestrict to block this attack, but \unrestrict itself was sufficient for an attack.
pg_dumpall is also affected. pg_restore is affected when used to generate a plain-format dump. Non-core
use of \restrict would be affected, but we've not identified non-core use. Versions before PostgreSQL
18.5, 17.11, 16.15, 15.19, and 14.24 are affected. (CVE-2026-18408)

- Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of
data lines as psql commands, via error injection. If the "COPY FROM STDIN" or "\copy FROM STDIN" command
fails before the server indicates that it awaits input rows, psql processes the in-line data rows as psql
commands. "COPY FROM" with a filename is unaffected. The server administrator has no inherent control over
the data rows, so a complete attack requires the attacker to separately acquire control of both the server
and the data rows. Alternatively, an attacker controlling data rows alone might complete an attack through
a coincidental error that they don't control. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and
14.24 are affected. (CVE-2026-6464)

- Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of
dependent statistics objects to the current user. This wrongly allows the table owner to run DROP
STATISTICS and ALTER STATISTICS via this improper ownership. It wrongly denies those commands to the prior
statistics object owner. DROP TABLE remains able to remove statistics objects, so this exploit achieves
nothing in many ownership arrangements. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24
are affected. (CVE-2026-6469)

- Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of service
against ALTER and DROP of the type, via creating a dependency on the type. Many DDL operations did check
the privilege, but assigning a range subtype and referencing the type from an SQL expression did not.
Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected. (CVE-2026-6470)

- Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege
to dlopen any file visible to the operating system account running the server, via the choice of logical
decoding plugin. This in turn runs arbitrary code as that account. Versions before PostgreSQL 18.5, 17.11,
16.15, 15.19, and 14.24 are affected. (CVE-2026-6471)

Solution

Update the postgresql17 library and its related packages to version 17.11-r0 or later.

See Also

https://security.alpinelinux.org/vuln/CVE-2026-14662

https://security.alpinelinux.org/vuln/CVE-2026-14663

https://security.alpinelinux.org/vuln/CVE-2026-14664

https://security.alpinelinux.org/vuln/CVE-2026-14666

https://security.alpinelinux.org/vuln/CVE-2026-14668

https://security.alpinelinux.org/vuln/CVE-2026-14669

https://security.alpinelinux.org/vuln/CVE-2026-14670

https://security.alpinelinux.org/vuln/CVE-2026-14671

https://security.alpinelinux.org/vuln/CVE-2026-14672

https://security.alpinelinux.org/vuln/CVE-2026-14673

https://security.alpinelinux.org/vuln/CVE-2026-14676

https://security.alpinelinux.org/vuln/CVE-2026-14677

https://security.alpinelinux.org/vuln/CVE-2026-14678

https://security.alpinelinux.org/vuln/CVE-2026-14679

https://security.alpinelinux.org/vuln/CVE-2026-14680

https://security.alpinelinux.org/vuln/CVE-2026-14681

https://security.alpinelinux.org/vuln/CVE-2026-15741

https://security.alpinelinux.org/vuln/CVE-2026-15742

https://security.alpinelinux.org/vuln/CVE-2026-16238

https://security.alpinelinux.org/vuln/CVE-2026-16239

https://security.alpinelinux.org/vuln/CVE-2026-16241

https://security.alpinelinux.org/vuln/CVE-2026-18024

https://security.alpinelinux.org/vuln/CVE-2026-18408

https://security.alpinelinux.org/vuln/CVE-2026-19385

https://security.alpinelinux.org/vuln/CVE-2026-6464

https://security.alpinelinux.org/vuln/CVE-2026-6469

https://security.alpinelinux.org/vuln/CVE-2026-6470

https://security.alpinelinux.org/vuln/CVE-2026-6471

Plugin Details

Severity: High

ID: 445995

Version: Revision 1.1

Type: Local

Published: 8/15/2026

Updated: 8/15/2026

Supported Sensors: Agentless Assessment

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.15

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-18408

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.7

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS Score Source: CVE-2026-19385

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 8/13/2026

Reference Information

CVE: CVE-2026-14662, CVE-2026-14663, CVE-2026-14664, CVE-2026-14666, CVE-2026-14668, CVE-2026-14669, CVE-2026-14670, CVE-2026-14671, CVE-2026-14672, CVE-2026-14673, CVE-2026-14676, CVE-2026-14677, CVE-2026-14678, CVE-2026-14679, CVE-2026-14680, CVE-2026-14681, CVE-2026-15741, CVE-2026-15742, CVE-2026-16238, CVE-2026-16239, CVE-2026-16241, CVE-2026-18024, CVE-2026-18408, CVE-2026-19385, CVE-2026-6464, CVE-2026-6469, CVE-2026-6470, CVE-2026-6471