<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE glsa SYSTEM "http://www.gentoo.org/dtd/glsa.dtd">
<glsa id="202608-15">
    <title>PostgreSQL: Multiple Vulnerabilities</title>
    <synopsis>Multiple vulnerabilities have been found in PostgreSQL, the worst of which could result in arbitrary code execution.</synopsis>
    <product type="ebuild">postgresql</product>
    <announced>2026-08-17</announced>
    <revised count="1">2026-08-17</revised>
    <bug>949747</bug>
    <bug>955658</bug>
    <bug>961496</bug>
    <bug>966064</bug>
    <bug>969976</bug>
    <bug>974982</bug>
    <access>local and remote</access>
    <affected>
        <package name="dev-db/postgresql" auto="yes" arch="*">
            <unaffected range="ge" slot="14">14.23-r1</unaffected>
            <unaffected range="ge" slot="15">15.18-r1</unaffected>
            <unaffected range="ge" slot="16">16.14-r1</unaffected>
            <unaffected range="ge" slot="17">17.10</unaffected>
            <unaffected range="ge" slot="18">18.4</unaffected>
            <vulnerable range="lt" slot="14">14.23-r1</vulnerable>
            <vulnerable range="lt" slot="15">15.18-r1</vulnerable>
            <vulnerable range="lt" slot="16">16.14-r1</vulnerable>
            <vulnerable range="lt" slot="17">17.10</vulnerable>
            <vulnerable range="lt" slot="18">18.4</vulnerable>
        </package>
    </affected>
    <background>
        <p>PostgreSQL is an open source object-relational database management system.</p>
    </background>
    <description>
        <p>Multiple vulnerabilities have been discovered in PostgreSQL. Please review the CVE identifiers referenced below for details.</p>
    </description>
    <impact type="high">
        <p>Please review the referenced CVE identifiers for details.</p>
    </impact>
    <workaround>
        <p>There is no known workaround at this time.</p>
    </workaround>
    <resolution>
        <p>All PostgreSQL 14 users should upgrade to the latest version:</p>
        
        <code>
          # emerge --sync
          # emerge --ask --oneshot --verbose ">=dev-db/postgresql-14.23-r1:14"
        </code>
        
        <p>All PostgreSQL 15 users should upgrade to the latest version:</p>
        
        <code>
          # emerge --sync
          # emerge --ask --oneshot --verbose ">=dev-db/postgresql-15.18-r1:15"
        </code>
        
        <p>All PostgreSQL 16 users should upgrade to the latest version:</p>
        
        <code>
          # emerge --sync
          # emerge --ask --oneshot --verbose ">=dev-db/postgresql-16.14-r1:16"
        </code>
        
        <p>All PostgreSQL 17 users should upgrade to the latest version:</p>
        
        <code>
          # emerge --sync
          # emerge --ask --oneshot --verbose ">=dev-db/postgresql-17.10:17"
        </code>
        
        <p>All PostgreSQL 18 users should upgrade to the latest version:</p>
        
        <code>
          # emerge --sync
          # emerge --ask --oneshot --verbose ">=dev-db/postgresql-18.4:18"
        </code>
    </resolution>
    <references>
        <uri link="https://nvd.nist.gov/vuln/detail/CVE-2025-1094">CVE-2025-1094</uri>
        <uri link="https://nvd.nist.gov/vuln/detail/CVE-2025-4207">CVE-2025-4207</uri>
        <uri link="https://nvd.nist.gov/vuln/detail/CVE-2025-8713">CVE-2025-8713</uri>
        <uri link="https://nvd.nist.gov/vuln/detail/CVE-2025-8714">CVE-2025-8714</uri>
        <uri link="https://nvd.nist.gov/vuln/detail/CVE-2025-8715">CVE-2025-8715</uri>
        <uri link="https://nvd.nist.gov/vuln/detail/CVE-2025-12817">CVE-2025-12817</uri>
        <uri link="https://nvd.nist.gov/vuln/detail/CVE-2026-2003">CVE-2026-2003</uri>
        <uri link="https://nvd.nist.gov/vuln/detail/CVE-2026-2004">CVE-2026-2004</uri>
        <uri link="https://nvd.nist.gov/vuln/detail/CVE-2026-2005">CVE-2026-2005</uri>
        <uri link="https://nvd.nist.gov/vuln/detail/CVE-2026-2006">CVE-2026-2006</uri>
        <uri link="https://nvd.nist.gov/vuln/detail/CVE-2026-2007">CVE-2026-2007</uri>
        <uri link="https://nvd.nist.gov/vuln/detail/CVE-2026-6472">CVE-2026-6472</uri>
        <uri link="https://nvd.nist.gov/vuln/detail/CVE-2026-6473">CVE-2026-6473</uri>
        <uri link="https://nvd.nist.gov/vuln/detail/CVE-2026-6474">CVE-2026-6474</uri>
        <uri link="https://nvd.nist.gov/vuln/detail/CVE-2026-6475">CVE-2026-6475</uri>
        <uri link="https://nvd.nist.gov/vuln/detail/CVE-2026-6476">CVE-2026-6476</uri>
        <uri link="https://nvd.nist.gov/vuln/detail/CVE-2026-6477">CVE-2026-6477</uri>
        <uri link="https://nvd.nist.gov/vuln/detail/CVE-2026-6478">CVE-2026-6478</uri>
        <uri link="https://nvd.nist.gov/vuln/detail/CVE-2026-6479">CVE-2026-6479</uri>
        <uri link="https://nvd.nist.gov/vuln/detail/CVE-2026-6575">CVE-2026-6575</uri>
        <uri link="https://nvd.nist.gov/vuln/detail/CVE-2026-6637">CVE-2026-6637</uri>
        <uri link="https://nvd.nist.gov/vuln/detail/CVE-2026-6638">CVE-2026-6638</uri>
    </references>
    <metadata tag="requester" timestamp="2026-08-17T06:40:31.969560Z">sam</metadata>
    <metadata tag="submitter" timestamp="2026-08-17T06:40:31.972402Z">sam</metadata>
</glsa>