IBM SECURITY ADVISORY First Issued: Tue Oct 6 01:00:55 CDT 2026 The most recent version of this document is available here: https://aix.software.ibm.com/aix/efixes/security/postgres_advisory2.asc Security Bulletin: Multiple vulnerabilities in PostgreSQL affect PowerVM VIOS =============================================================================== SUMMARY: Vulnerabilities in PostgreSQL could allow Memory Corruption/Arbitrary Code Execution (CVE-2026-14662, CVE-2026-14664, CVE-2026-14669, CVE-2026-14670, CVE-2026-14671, CVE-2026-14677, CVE-2026-14679, CVE-2026-14680, CVE-2026-15742, CVE-2026-16239, CVE-2026-19385), Information Disclosure (CVE-2026-14663, CVE-2026-14668, CVE-2026-14678, CVE-2026-18024), SQL Injection (CVE-2026-15741), Privilege Escalation / Authorization Issues (CVE-2026-14673, CVE-2026-6469, CVE-2026-6470, CVE-2026-6471), Command Injection / Untrusted Data Inclusion( CVE-2026-18408, CVE-2026-6464 ), Security Policy Bypass(CVE-2026-14666). Denial of service (CVE-2026-16241). PowerVM VIOS uses PostgreSQL as part of Shared Storage Pools (SSP) and for internal administration purposes. =============================================================================== VULNERABILITY DETAILS: CVEID: CVE-2026-14662 https://www.cve.org/CVERecord?id=CVE-2026-14662 DESCRIPTION: Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database user to cause out-of-bounds writes and execute arbitrary code via crafted large inputs. Affects PostgreSQL before 18.6, 17.11, 16.15, 15.19, and 14.24. CVSS Base Score: 8.8 CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-14663 https://www.cve.org/CVERecord?id=CVE-2026-14663 DESCRIPTION: Cleartext storage issue in PostgreSQL pgcrypto disabled ciphers may allow recovery of plaintext from faulty ciphertext and weaken protection provided by the Modification Detection Code (MDC). Affects PostgreSQL before 18.6, 17.11, 16.15, 15.19, and 14.24. CVSS Base Score: 6.5 CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N) CVEID: CVE-2026-14664 https://www.cve.org/CVERecord?id=CVE-2026-14664 DESCRIPTION: Heap buffer overflow in PostgreSQL regexp processing may allow query authors to execute arbitrary code through specially crafted text that bypasses encoding validation. Affects PostgreSQL before 18.6, 17.11, 16.15, 15.19, and 14.24. CVSS Base Score: 8.8 CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-14666 https://www.cve.org/CVERecord?id=CVE-2026-14666 DESCRIPTION: Incomplete tracking of role membership, role attributes, and database ownership changes may allow cached row-level security policies to remain active after privileges are revoked. Affects PostgreSQL before 18.6, 17.11, 16.15, 15.19, and 14.24. CVSS Base Score: 4.2 CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N) CVEID: CVE-2026-14668 https://www.cve.org/CVERecord?id=CVE-2026-14668 DESCRIPTION: Type confusion in the PostgreSQL ctid selectivity estimator may allow disclosure of memory-derived values through specially crafted non-ctid inputs. Affects PostgreSQL before 18.6, 17.11, 16.15, 15.19, and 14.24. CVSS Base Score: 8.1 CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H) CVEID: CVE-2026-14669 https://www.cve.org/CVERecord?id=CVE-2026-14669 DESCRIPTION: Heap buffer overflow in PostgreSQL to_char(timestamptz) may allow arbitrary code execution through a crafted long POSIX timezone abbreviation. Affects PostgreSQL before 18.6, 17.11, 16.15, 15.19, and 14.24. CVSS Base Score: 8.8 CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-14670 https://www.cve.org/CVERecord?id=CVE-2026-14670 DESCRIPTION: Heap buffer overflow in PostgreSQL plperl handling of tied hash returns may allow function owners to execute arbitrary code via crafted function bodies. Affects PostgreSQL before 18.6, 17.11, 16.15, 15.19, and 14.24. CVSS Base Score: 8.8 CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-14671 https://www.cve.org/CVERecord?id=CVE-2026-14671 DESCRIPTION: Type confusion in the PostgreSQL refint module may allow object creators to execute arbitrary code as the database operating system user. Affects PostgreSQL before 18.6, 17.11, 16.15, 15.19, and 14.24. CVSS Base Score: 8.8 CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-14673 https://www.cve.org/CVERecord?id=CVE-2026-14673 DESCRIPTION: Untrusted search path handling in PostgreSQL amcheck may allow users with EXECUTE privilege to invoke arbitrary functions through a hostile search path. PostgreSQL 17 is unaffected. CVSS Base Score: 3.8 CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N) CVEID: CVE-2026-14677 https://www.cve.org/CVERecord?id=CVE-2026-14677 DESCRIPTION: Integer wraparound in 32-bit PostgreSQL pltcl and plperl builds may cause out-of-bounds writes and arbitrary code execution through crafted function bodies. Affects PostgreSQL before 18.6, 17.11, 16.15, 15.19, and 14.24. CVSS Base Score: 8.8 CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-14678 https://www.cve.org/CVERecord?id=CVE-2026-14678 DESCRIPTION: Buffer over-read in the PostgreSQL pg_trgm index picksplit function may allow limited disclosure of memory values through index split behavior. Affects PostgreSQL before 18.6, 17.11, 16.15, 15.19, and 14.24. CVSS Base Score: 4.3 CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N) CVEID: CVE-2026-14679 https://www.cve.org/CVERecord?id=CVE-2026-14679 DESCRIPTION: Stack buffer overflow in PostgreSQL argument name matching may allow object creators to cause denial of service or limited integrity impacts through crafted OUT parameter counts. Affects PostgreSQL before 18.6, 17.11, 16.15, 15.19, and 14.24. CVSS Base Score: 8.2 CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H) CVEID: CVE-2026-14680 https://www.cve.org/CVERecord?id=CVE-2026-14680 DESCRIPTION: Type confusion involving PostgreSQL internal data type arguments may allow arbitrary code execution through calls to functions using the internal type. Affects PostgreSQL before 18.6, 17.11, 16.15, 15.19, and 14.24. CVSS Base Score: 8.8 CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-15741 https://www.cve.org/CVERecord?id=CVE-2026-15741 DESCRIPTION: SQL injection in PostgreSQL EXTRACT() deparse may allow object owners to execute arbitrary SQL as a superuser through malicious object definitions. Affects PostgreSQL before 18.6, 17.11, 16.15, 15.19, and 14.24. CVSS Base Score: 8.8 CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) CVEID: CVE-2026-15742 https://www.cve.org/CVERecord?id=CVE-2026-15742 DESCRIPTION: Integer wraparound in PostgreSQL fuzzystrmatch may allow arbitrary code execution through crafted inputs to levenshtein() and levenshtein_less_equal() functions. Affects PostgreSQL before 18.6, 17.11, 16.15, 15.19, and 14.24. CVSS Base Score: 8.8 CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-16239 https://www.cve.org/CVERecord?id=CVE-2026-16239 DESCRIPTION: Type confusion in PostgreSQL portal and cursor lifecycle handling may allow arbitrary code execution through recreation of cursors with differing types. Affects PostgreSQL before 18.6, 17.11, 16.15, 15.19, and 14.24. CVSS Base Score: 8.8 CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-16241 https://www.cve.org/CVERecord?id=CVE-2026-16241 DESCRIPTION: Integer underflow in PostgreSQL ECPG may allow a database server administrator to cause temporary denial of service against ECPG clients through malformed bytea values. Affects PostgreSQL before 18.6, 17.11, 16.15, 15.19, and 14.24. CVSS Base Score: 3.8 CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L) CVEID: CVE-2026-18024 https://www.cve.org/CVERecord?id=CVE-2026-18024 DESCRIPTION: Buffer over-read in PostgreSQL ascii() may allow disclosure of up to three bytes beyond an allocation boundary through crafted text values. Affects PostgreSQL before 18.6, 17.11, 16.15, 15.19, and 14.24. CVSS Base Score: 4.3 CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N) CVEID: CVE-2026-18408 https://www.cve.org/CVERecord?id=CVE-2026-18408 DESCRIPTION: Untrusted data inclusion in PostgreSQL pg_dump may allow arbitrary code execution during restore operations through psql meta-command expansion. Affects PostgreSQL before 18.6, 17.11, 16.15, 15.19, and 14.24. CVSS Base Score: 8.8 CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) CVEID: CVE-2026-19385 https://www.cve.org/CVERecord?id=CVE-2026-19385 DESCRIPTION: Heap buffer overflow in PostgreSQL pg_dump processing of long function transform lists may allow arbitrary code execution through crafted transform lists. Affects PostgreSQL before 18.6, 17.11, 16.15, 15.19, and 14.24. CVSS Base Score: 8.8 CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-6464 https://www.cve.org/CVERecord?id=CVE-2026-6464 DESCRIPTION: Untrusted data inclusion in PostgreSQL psql COPY may allow execution of data lines as psql commands through error injection under specific failure conditions. Affects PostgreSQL before 18.6, 17.11, 16.15, 15.19, and 14.24. CVSS Base Score: 8.1 CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-6469 https://www.cve.org/CVERecord?id=CVE-2026-6469 DESCRIPTION: Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE may improperly transfer ownership of statistics objects, enabling unauthorized statistics management operations. Affects PostgreSQL before 18.6, 17.11, 16.15, 15.19, and 14.24. CVSS Base Score: 3.8 CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L) CVEID: CVE-2026-6470 https://www.cve.org/CVERecord?id=CVE-2026-6470 DESCRIPTION: Missing authorization checks in PostgreSQL DDL commands may allow object creators to prevent ALTER or DROP operations by creating unauthorized dependencies. Affects PostgreSQL before 18.6, 17.11, 16.15, 15.19, and 14.24. CVSS Base Score: 4.3 CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L) CVEID: CVE-2026-6471 https://www.cve.org/CVERecord?id=CVE-2026-6471 DESCRIPTION: Missing authorization in PostgreSQL logical decoding may allow users with REPLICATION privilege to load arbitrary files and execute code as the database operating system user. Affects PostgreSQL before 18.6, 17.11, 16.15, 15.19, and 14.24. CVSS Base Score: 7.2 CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H) AFFECTED PRODUCTS AND VERSIONS: VIOS 4.1 The vulnerability is being addressed in the following fileset levels: key_fileset = aix Fileset Lower Level Upper Level KEY --------------------------------------------------------- ios.database.rte 7.3.3.0 7.3.3.2 key_w_fs ios.viodb15.rte 7.3.4.0 7.3.4.3 key_w_fs Note: A. Postgres 13 is out of support. Considering long term support, it is advised to upgrade to Postgres 15. To find out whether the affected filesets are installed on your systems, refer to the lssw command found in VIOS user's guide. Example: lssw | grep -i ios REMEDIATION: FIXES IBM strongly recommends addressing the vulnerability now. The VIOS fixes can be downloaded via https from: https://aix.software.ibm.com/aix/efixes/security/postgres_fix2.tar The link above is to a tar file containing this signed advisory, install packages, and OpenSSL signatures for each package. The fixes below include prerequisite checking. This will enforce the correct mapping between the fixes and VIOS levels. AIX Level Fix KEY --------------------------------------------------------------- 4.1.0.x pg13_cleanup_final.sh key_w_fs 4.1.0.x vdb15_1of2.260831.epkg.Z key_w_fs 4.1.0.x vdb15_2of2.260831.epkg.Z key_w_fs 4.1.1.x ios.viodb15 key_w_fs 4.1.2.x ios.viodb15 key_w_fs NOTE: To help with enabling the fix, two README files are provided in the tar file. One is for 4.1.0 and another is for 4.1.1/4.1.2. Once the provided version of ios.viodb15.rte is successfully installed, the vulnerabilities reported in this bulletin have been addressed. To extract the fixes from the tar file: tar xvf postgres_fix2.tar cd postgres_fix2 IMPORTANT: If possible, it is recommended that a mksysb backup of the system be created. Verify it is both bootable and readable before proceeding. To preview the fix installation: oem_setup_env installp -apYd . ios To install the fix package: oem_setup_env installp -aXYd . ios Verify you have retrieved the fixes intact: The checksums below were generated using the "openssl dgst -sha256 [file]" command as the following: openssl dgst -sha256 filename KEY ----------------------------------------------------------------------------------------------------- 57b01a3fd4e42f48134d10ed04a6d479cf8f50183a6955938925238f8b292836 ios.viodb15 key_w_csum b8cab10f06a8b9e1525526ce8d847560c7e1d2e7bc00dd6fbd68022453bc2616 vdb15_1of2.260831.epkg.Z key_w_csum 709cef7a1d0bac12f669af4fb95b685ffc79b9ccde4918a7a83c593e89e038b8 vdb15_2of2.260831.epkg.Z key_w_csum 2d5706a63c5c57e703398b646d2f0803cb16179cde20bfe606bb6dee94f5e0b8 pg13_cleanup_final.sh key_w_csum openssl dgst -sha512 filename KEY -------------------------------------------------------------------------------------------------------------------------------------------------------------------------- 13bdd0a207da595b5da22799f6c030cca5a574d67628b7dd9e3cdb3f99ef7f390daa6825e9ae8729fd5947d73b17a1fc658ad3581583aa8cc1cef091bc445284 ios.viodb15 key_4K_w_csum 5b052b6defc3a1255ce27b9dd3e3e06c89d23e1118d72b9ffcbe675aa7a54f856b484bfb04705e7596fb0eab8183a6d0b458131bf44ace825963c8c2b463d71a vdb15_1of2.260831.epkg.Z key_4K_w_csum 4eb74ce9acae161db90879c20cc29af3dd9705a97149127dc38b1202dc558e57ac918c776e1d0d6e9bcebcec16d9cf581611eefa0348ee8f1d2ee1b17293a951 vdb15_1of2.260831.epkg.Z key_4K_w_csum 42e417147ce938503669074398a046ced5127cc1aaba31fcf80e91e967b94cef12227b54847716eba0ca98d80a95131f9a341cdfcf9d55c65d31e62e8f048fe3 pg13_cleanup_final.sh key_4K_w_csum These sums should match exactly. The OpenSSL signatures in the tar file and on this advisory can also be used to verify the integrity of the fixes. If the sums or signatures cannot be confirmed, contact IBM Support at http://ibm.com/support/ and describe the discrepancy. openssl dgst -sha256 -verify [pubkey_file] -signature [advisory_file].sig [advisory_file] openssl dgst -sha256 -verify [pubkey_file] -signature [ifix_file].sig [ifix_file] Published advisory OpenSSL signature file location: https://aix.software.ibm.com/aix/efixes/security/postgres_advisory2.asc.sig WORKAROUNDS AND MITIGATIONS: None. =============================================================================== CONTACT US: Note: Keywords labeled as KEY in this document are used for parsing purposes. If you would like to receive AIX Security Advisories via email, please visit "My Notifications": http://www.ibm.com/support/mynotifications Contact IBM Support for questions related to this announcement: https://ibm.com/support/ For information on how to securely verify AIX security bulletins and fixes: https://www.ibm.com/support/pages/node/6985269 To obtain the OpenSSL public key that can be used to verify the signed advisories and ifixes: Download the key from our web page: https://aix.software.ibm.com/aix/efixes/security/systems_p_os_aix_security_pubkey.txt To verify the AIX/VIOS security bulletin: Published advisory OpenSSL signature file location: https://aix.software.ibm.com/aix/efixes/security/postgres_advisory2.asc.sig openssl dgst -sha256 -verify [pubkey_file] -signature [advisory_file].sig [advisory_file] Please contact your local IBM AIX support center for any assistance. REFERENCES: Complete CVSS v3 Guide: http://www.first.org/cvss/user-guide On-line Calculator v3: http://www.first.org/cvss/calculator/3.0 RELATED INFORMATION: IBM Secure Engineering Web Portal http://www.ibm.com/security/secure-engineering/bulletins.html IBM Product Security Incident Response Blog https://www.ibm.com/blogs/psirt/ Security Bulletin: Multiple vulnerabilities in PostgreSQL affect PowerVM VIOS https://www.ibm.com/support/pages/node/7291332 ACKNOWLEDGEMENTS: None. CHANGE HISTORY: First Issued: Tue Oct 6 01:00:55 CDT 2026 =============================================================================== *The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin. Disclaimer According to the Forum of Incident Response and Security Teams (FIRST), the Common Vulnerability Scoring System (CVSS) is an "industry open standard designed to convey vulnerability severity and help to determine urgency and priority of response." IBM PROVIDES THE CVSS SCORES "AS IS" WITHOUT WARRANTY OF ANY KIND, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. CUSTOMERS ARE RESPONSIBLE FOR ASSESSING THE IMPACT OF ANY ACTUAL OR POTENTIAL SECURITY VULNERABILITY.