Bug 2515328 (CVE-2026-19385) - CVE-2026-19385 postgresql: PostgreSQL pg_dump: Arbitrary code execution via crafted transform lists
Summary: CVE-2026-19385 postgresql: PostgreSQL pg_dump: Arbitrary code execution via c...
Keywords:
Status: NEW
Alias: CVE-2026-19385
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2524382 2524383 2524384 2524385
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-13 13:31 UTC by OSIDB Bzimport
Modified: 2026-09-23 07:34 UTC (History)
9 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:67280 0 None None None 2026-09-14 13:31:49 UTC
Red Hat Product Errata RHSA-2026:67491 0 None None None 2026-09-15 08:14:43 UTC
Red Hat Product Errata RHSA-2026:67848 0 None None None 2026-09-16 08:54:17 UTC
Red Hat Product Errata RHSA-2026:69607 0 None None None 2026-09-22 02:39:52 UTC
Red Hat Product Errata RHSA-2026:69698 0 None None None 2026-09-21 22:12:49 UTC
Red Hat Product Errata RHSA-2026:69876 0 None None None 2026-09-22 08:34:57 UTC
Red Hat Product Errata RHSA-2026:69914 0 None None None 2026-09-22 11:39:32 UTC
Red Hat Product Errata RHSA-2026:69923 0 None None None 2026-09-22 10:27:34 UTC
Red Hat Product Errata RHSA-2026:70186 0 None None None 2026-09-22 12:43:08 UTC
Red Hat Product Errata RHSA-2026:70559 0 None None None 2026-09-23 06:29:13 UTC
Red Hat Product Errata RHSA-2026:70602 0 None None None 2026-09-23 07:34:38 UTC

Description OSIDB Bzimport 2026-08-13 13:31:57 UTC
Heap buffer overflow in PostgreSQL pg_dump of long function transform lists allows an object creator to execute arbitrary code as the operating system user running pg_dump, via a crafted transform list.  Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.

Comment 2 Jon Orris 2026-09-14 13:31:47 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:67280 https://access.redhat.com/errata/RHSA-2026:67280

Comment 3 Jon Orris 2026-09-15 08:14:42 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:67491 https://access.redhat.com/errata/RHSA-2026:67491

Comment 4 Jon Orris 2026-09-16 08:54:16 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:67848 https://access.redhat.com/errata/RHSA-2026:67848

Comment 6 Jon Orris 2026-09-21 22:12:48 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:69698 https://access.redhat.com/errata/RHSA-2026:69698

Comment 7 Jon Orris 2026-09-22 02:39:51 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:69607 https://access.redhat.com/errata/RHSA-2026:69607

Comment 8 Jon Orris 2026-09-22 08:34:56 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:69876 https://access.redhat.com/errata/RHSA-2026:69876

Comment 9 Jon Orris 2026-09-22 10:27:33 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:69923 https://access.redhat.com/errata/RHSA-2026:69923

Comment 10 Jon Orris 2026-09-22 11:39:31 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:69914 https://access.redhat.com/errata/RHSA-2026:69914

Comment 11 Jon Orris 2026-09-22 12:43:07 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:70186 https://access.redhat.com/errata/RHSA-2026:70186

Comment 12 Jon Orris 2026-09-23 06:29:12 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:70559 https://access.redhat.com/errata/RHSA-2026:70559

Comment 13 Jon Orris 2026-09-23 07:34:36 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2026:70602 https://access.redhat.com/errata/RHSA-2026:70602


Note You need to log in before you can comment on or make changes to this bug.