Skip to content

CVE-2026-6470 on CTRL-OS 26.05

Aliases: CVE-2026-6470

Packages: postgresql_14, postgresql_15, postgresql_16, postgresql_17, postgresql_18

Status: Plausible

Advisory Information

Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of service against ALTER and DROP of the type, via creating a dependency on the type. Many DDL operations did check the privilege, but assigning a range subtype and referencing the type from an SQL expression did not. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.

Updates

2026-08-14 18:02 CEST

Metadata changes:

  • Status for package postgresql_14: “Plausible
  • Status for package postgresql_15: “Plausible
  • Status for package postgresql_16: “Plausible
  • Status for package postgresql_17: “Plausible
  • Status for package postgresql_18: “Plausible

(Amended on: 2026-08-14 18:03 CEST)

2026-08-14 18:02 CEST

Metadata changes:

  • Status for package postgresql_14: “New
  • Status for package postgresql_15: “New
  • Status for package postgresql_16: “New
  • Status for package postgresql_17: “New
  • Status for package postgresql_18: “New