SUSE SLES12: postgresql16 / postgresql16-contrib / postgresql16-devel / etc (SUSE-SU-2026:3794-1)

high Nessus Plugin ID 341035

Synopsis

The remote SUSE host is missing one or more security updates.

Description

The remote SUSE Linux SLES12 host has packages installed that are affected by multiple vulnerabilities as referenced in the SUSE-SU-2026:3794-1 advisory.

- CVE-2026-6464: `psql` `COPY FROM STDIN` early failure processes data lines as `psql` commands (bsc#1275046).
- CVE-2026-6469: `ALTER TABLE ALTER TYPE` resets extended statistics ownership (bsc#1275044).
- CVE-2026-6470: failure to check type `USAGE` privilege (bsc#1275043).
- CVE-2026-6471: logical decoding can `dlopen` arbitrary file (bsc#1275042).
- CVE-2026-14662: `tsvector` and `tsquery` undersize allocations, via integer wraparound (bsc#1275001).
- CVE-2026-14663: `pgcrypto`, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext (bsc#1275002).
- CVE-2026-14664: `regexp` heap buffer overflow executes arbitrary code (bsc#1275068).
- CVE-2026-14666: row security caching disregards role modifications (bsc#1275067).
- CVE-2026-14668: `ctid` type confusion in selectivity estimator discloses derivative of arbitrary read (bsc#1275066).
- CVE-2026-14669: `to_char` heap buffer overflow executes arbitrary code (bsc#1275065).
- CVE-2026-14670: `plperl` tied object heap buffer overflow executes arbitrary code (bsc#1275064).
- CVE-2026-14671: `refint` plan cache type confusion executes arbitrary code (bsc#1275063).
- CVE-2026-14672: observable response discrepancy with non-default `scram_iterations` provides user existence oracle (bsc#1275062).
- CVE-2026-14673: `amcheck` does not clear untrusted search path (bsc#1275061).
- CVE-2026-14677: 32-bit `pltcl` and `plperl` undersize allocations, via integer wraparound (bsc#1275059).
- CVE-2026-14678: `pg_trgm` `picksplit` reads past end of buffer (bsc#1275058).
- CVE-2026-14679: stack buffer overflow in argument match writes `0x0` and `0x1` to server memory (bsc#1275057).
- CVE-2026-14680: type confusion via 'internal' arguments (bsc#1275056).
- CVE-2026-15741: expression deparse allows SQL injection via `EXTRACT` argument (bsc#1275054).
- CVE-2026-15742: `fuzzystrmatch` writes effectively-arbitrary addresses, via integer wraparound (bsc#1275053).
- CVE-2026-16239: type confusion in cursor `CLOSE + DECLARE` executes arbitrary code (bsc#1275051).
- CVE-2026-16241: ECPG integer underflow can crash the client (bsc#1275050).
- CVE-2026-18024: `ascii()` function reads past end of buffer (bsc#1275049).
- CVE-2026-18408: `psql` `\unrestrict` lets superuser of `pg_dump` origin server execute arbitrary code in `psql` client (bsc#1275048).
- CVE-2026-19385: `pg_dump` heap buffer overflow executes arbitrary code (bsc#1275047).

Changes for postgresql16:

- Let `llvmjit-devel` require the `llc` and `clang` binaries to fix build of extensions on SLE-16 and newer.
- Use LLVM 15 on SLE-15 up to SP5 and LLVM 17 on SP6 and SP7.
- Update to version 16.15:
* https://www.postgresql.org/docs/16/release-16-15.html
* https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://bugzilla.suse.com/1275001

https://bugzilla.suse.com/1275002

https://bugzilla.suse.com/1275042

https://bugzilla.suse.com/1275043

https://bugzilla.suse.com/1275044

https://bugzilla.suse.com/1275046

https://bugzilla.suse.com/1275047

https://bugzilla.suse.com/1275048

https://bugzilla.suse.com/1275049

https://bugzilla.suse.com/1275050

https://bugzilla.suse.com/1275051

https://bugzilla.suse.com/1275053

https://bugzilla.suse.com/1275054

https://bugzilla.suse.com/1275056

https://bugzilla.suse.com/1275057

https://bugzilla.suse.com/1275058

https://bugzilla.suse.com/1275059

https://bugzilla.suse.com/1275061

https://bugzilla.suse.com/1275062

https://bugzilla.suse.com/1275063

https://bugzilla.suse.com/1275064

https://bugzilla.suse.com/1275065

https://bugzilla.suse.com/1275066

https://bugzilla.suse.com/1275067

https://bugzilla.suse.com/1275068

https://www.suse.com/security/cve/CVE-2026-14662

https://www.suse.com/security/cve/CVE-2026-14663

https://www.suse.com/security/cve/CVE-2026-14664

https://www.suse.com/security/cve/CVE-2026-14666

https://www.suse.com/security/cve/CVE-2026-14668

https://www.suse.com/security/cve/CVE-2026-14669

https://www.suse.com/security/cve/CVE-2026-14670

https://www.suse.com/security/cve/CVE-2026-14671

https://www.suse.com/security/cve/CVE-2026-14672

https://www.suse.com/security/cve/CVE-2026-14673

https://www.suse.com/security/cve/CVE-2026-14677

https://www.suse.com/security/cve/CVE-2026-14678

https://www.suse.com/security/cve/CVE-2026-14679

https://www.suse.com/security/cve/CVE-2026-14680

https://www.suse.com/security/cve/CVE-2026-15741

https://www.suse.com/security/cve/CVE-2026-15742

https://www.suse.com/security/cve/CVE-2026-16239

https://www.suse.com/security/cve/CVE-2026-16241

https://www.suse.com/security/cve/CVE-2026-18024

https://www.suse.com/security/cve/CVE-2026-18408

https://www.suse.com/security/cve/CVE-2026-19385

https://www.suse.com/security/cve/CVE-2026-6464

https://www.suse.com/security/cve/CVE-2026-6469

https://www.suse.com/security/cve/CVE-2026-6470

https://www.suse.com/security/cve/CVE-2026-6471

http://www.nessus.org/u?4fac00c3

Plugin Details

Severity: High

ID: 341035

File Name: suse_SU-2026-3794-1.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 8/27/2026

Updated: 8/27/2026

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.17

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-18408

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.9

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS Score Source: CVE-2026-19385

Vulnerability Information

CPE: cpe:/o:novell:suse_linux:12, p-cpe:/a:novell:suse_linux:postgresql16-contrib, p-cpe:/a:novell:suse_linux:postgresql16-devel, p-cpe:/a:novell:suse_linux:postgresql16-docs, p-cpe:/a:novell:suse_linux:postgresql16-plperl, p-cpe:/a:novell:suse_linux:postgresql16-plpython, p-cpe:/a:novell:suse_linux:postgresql16-pltcl, p-cpe:/a:novell:suse_linux:postgresql16-server-devel, p-cpe:/a:novell:suse_linux:postgresql16-server, p-cpe:/a:novell:suse_linux:postgresql16

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 8/25/2026

Vulnerability Publication Date: 8/13/2026

Reference Information

CVE: CVE-2026-14662, CVE-2026-14663, CVE-2026-14664, CVE-2026-14666, CVE-2026-14668, CVE-2026-14669, CVE-2026-14670, CVE-2026-14671, CVE-2026-14672, CVE-2026-14673, CVE-2026-14677, CVE-2026-14678, CVE-2026-14679, CVE-2026-14680, CVE-2026-15741, CVE-2026-15742, CVE-2026-16239, CVE-2026-16241, CVE-2026-18024, CVE-2026-18408, CVE-2026-19385, CVE-2026-6464, CVE-2026-6469, CVE-2026-6470, CVE-2026-6471

IAVB: 2026-B-0238

SuSE: SUSE-SU-2026:3794-1