{"cve": "CVE-2026-2006", "updated": 1785084335, "url": "https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0346/", "affected": [{"ecosystem": "Debian:12", "package": "postgresql-15", "affected": null, "fixed": "15.16-0+deb12u1", "status": "fixed", "ref": "https://osv.dev/vulnerability/DEBIAN-CVE-2026-2006"}, {"ecosystem": "Debian:12", "package": "postgresql-15", "affected": null, "fixed": "15.16-0+deb12u1", "status": "fixed", "ref": "https://osv.dev/vulnerability/DSA-6132-1"}, {"ecosystem": "Ubuntu:24.04:LTS", "package": "postgresql-16", "affected": null, "fixed": "16.13-0ubuntu0.24.04.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/UBUNTU-CVE-2026-2006"}, {"ecosystem": "SUSE:Linux Enterprise Server 12 SP5-LTSS", "package": "postgresql15", "affected": null, "fixed": "15.16-3.50.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2026:0615-1"}, {"ecosystem": "SUSE:Linux Enterprise Server LTSS Extended Security 12 SP5", "package": "postgresql15", "affected": null, "fixed": "15.16-3.50.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2026:0615-1"}, {"ecosystem": "SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS", "package": "postgresql15", "affected": null, "fixed": "15.17-150200.5.54.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2026:0770-1"}, {"ecosystem": "SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS", "package": "postgresql15", "affected": null, "fixed": "15.17-150200.5.54.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2026:0770-1"}, {"ecosystem": "SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS", "package": "postgresql15", "affected": null, "fixed": "15.17-150200.5.54.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2026:0770-1"}, {"ecosystem": "SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS", "package": "postgresql15", "affected": null, "fixed": "15.17-150200.5.54.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2026:0770-1"}, {"ecosystem": "SUSE:Linux Enterprise Server 15 SP4-LTSS", "package": "postgresql15", "affected": null, "fixed": "15.17-150200.5.54.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2026:0770-1"}, {"ecosystem": "SUSE:Linux Enterprise Server 15 SP5-LTSS", "package": "postgresql15", "affected": null, "fixed": "15.17-150200.5.54.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2026:0770-1"}, {"ecosystem": "SUSE:Linux Enterprise Server for SAP Applications 15 SP4", "package": "postgresql15", "affected": null, "fixed": "15.17-150200.5.54.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2026:0770-1"}, {"ecosystem": "SUSE:Linux Enterprise Server for SAP Applications 15 SP5", "package": "postgresql15", "affected": null, "fixed": "15.17-150200.5.54.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2026:0770-1"}, {"ecosystem": "SUSE:Linux Enterprise Module for Legacy 15 SP7", "package": "postgresql15", "affected": null, "fixed": "15.17-150600.16.28.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2026:0771-1"}, {"ecosystem": "SUSE:Linux Enterprise Server 15 SP6-LTSS", "package": "postgresql15", "affected": null, "fixed": "15.17-150600.16.28.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2026:0771-1"}, {"ecosystem": "SUSE:Linux Enterprise Server for SAP Applications 15 SP6", "package": "postgresql15", "affected": null, "fixed": "15.17-150600.16.28.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2026:0771-1"}, {"ecosystem": "openSUSE:Leap 15.6", "package": "postgresql15", "affected": null, "fixed": "15.17-150600.16.28.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2026:0771-1"}, {"ecosystem": "SUSE:Linux Enterprise Server 16.0", "package": "postgresql15", "affected": null, "fixed": "15.16-160000.1.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2026:20588-1"}, {"ecosystem": "SUSE:Linux Enterprise Server for SAP applications 16.0", "package": "postgresql15", "affected": null, "fixed": "15.16-160000.1.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2026:20588-1"}, {"ecosystem": "SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS", "package": "postgresql16", "affected": null, "fixed": "16.12-150200.5.38.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2026:0588-1"}, {"ecosystem": "SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS", "package": "postgresql16", "affected": null, "fixed": "16.12-150200.5.38.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2026:0588-1"}, {"ecosystem": "SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS", "package": "postgresql16", "affected": null, "fixed": "16.12-150200.5.38.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2026:0588-1"}, {"ecosystem": "SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS", "package": "postgresql16", "affected": null, "fixed": "16.12-150200.5.38.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2026:0588-1"}, {"ecosystem": "SUSE:Linux Enterprise Server 15 SP4-LTSS", "package": "postgresql16", "affected": null, "fixed": "16.12-150200.5.38.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2026:0588-1"}, {"ecosystem": "SUSE:Linux Enterprise Server 15 SP5-LTSS", "package": "postgresql16", "affected": null, "fixed": "16.12-150200.5.38.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2026:0588-1"}, {"ecosystem": "SUSE:Linux Enterprise Server for SAP Applications 15 SP4", "package": "postgresql16", "affected": null, "fixed": "16.12-150200.5.38.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2026:0588-1"}, {"ecosystem": "SUSE:Linux Enterprise Server for SAP Applications 15 SP5", "package": "postgresql16", "affected": null, "fixed": "16.12-150200.5.38.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2026:0588-1"}, {"ecosystem": "SUSE:Linux Enterprise Server 12 SP5-LTSS", "package": "postgresql16", "affected": null, "fixed": "16.12-3.38.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2026:0614-1"}, {"ecosystem": "SUSE:Linux Enterprise Server LTSS Extended Security 12 SP5", "package": "postgresql16", "affected": null, "fixed": "16.12-3.38.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2026:0614-1"}, {"ecosystem": "SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS", "package": "postgresql16", "affected": null, "fixed": "16.13-150200.5.41.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2026:0784-1"}, {"ecosystem": "SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS", "package": "postgresql16", "affected": null, "fixed": "16.13-150200.5.41.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2026:0784-1"}, {"ecosystem": "SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS", "package": "postgresql16", "affected": null, "fixed": "16.13-150200.5.41.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2026:0784-1"}, {"ecosystem": "SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS", "package": "postgresql16", "affected": null, "fixed": "16.13-150200.5.41.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2026:0784-1"}, {"ecosystem": "SUSE:Linux Enterprise Server 15 SP4-LTSS", "package": "postgresql16", "affected": null, "fixed": "16.13-150200.5.41.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2026:0784-1"}, {"ecosystem": "SUSE:Linux Enterprise Server 15 SP5-LTSS", "package": "postgresql16", "affected": null, "fixed": "16.13-150200.5.41.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2026:0784-1"}, {"ecosystem": "SUSE:Linux Enterprise Server for SAP Applications 15 SP4", "package": "postgresql16", "affected": null, "fixed": "16.13-150200.5.41.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2026:0784-1"}, {"ecosystem": "SUSE:Linux Enterprise Server for SAP Applications 15 SP5", "package": "postgresql16", "affected": null, "fixed": "16.13-150200.5.41.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2026:0784-1"}, {"ecosystem": "SUSE:Linux Enterprise Module for Legacy 15 SP7", "package": "postgresql16", "affected": null, "fixed": "16.13-150600.16.30.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2026:0882-1"}, {"ecosystem": "SUSE:Linux Enterprise Module for Package Hub 15 SP7", "package": "postgresql16", "affected": null, "fixed": "16.13-150600.16.30.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2026:0882-1"}, {"ecosystem": "SUSE:Linux Enterprise Module for Server Applications 15 SP7", "package": "postgresql16", "affected": null, "fixed": "16.13-150600.16.30.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2026:0882-1"}, {"ecosystem": "SUSE:Linux Enterprise Server 15 SP6-LTSS", "package": "postgresql16", "affected": null, "fixed": "16.13-150600.16.30.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2026:0882-1"}, {"ecosystem": "SUSE:Linux Enterprise Server for SAP Applications 15 SP6", "package": "postgresql16", "affected": null, "fixed": "16.13-150600.16.30.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2026:0882-1"}, {"ecosystem": "openSUSE:Leap 15.6", "package": "postgresql16", "affected": null, "fixed": "16.13-150600.16.30.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2026:0882-1"}, {"ecosystem": "SUSE:Linux Enterprise Server 16.0", "package": "postgresql16", "affected": null, "fixed": "16.13-160000.1.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2026:20983-1"}, {"ecosystem": "SUSE:Linux Enterprise Server for SAP applications 16.0", "package": "postgresql16", "affected": null, "fixed": "16.13-160000.1.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2026:20983-1"}, {"ecosystem": "openSUSE:Tumbleweed", "package": "postgresql15", "affected": null, "fixed": "15.16-1.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/openSUSE-SU-2026:10191-1"}, {"ecosystem": "openSUSE:Leap 16.0", "package": "postgresql15", "affected": null, "fixed": "15.16-160000.1.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/openSUSE-SU-2026:20266-1"}, {"ecosystem": "openSUSE:Tumbleweed", "package": "postgresql16", "affected": null, "fixed": "16.12-1.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/openSUSE-SU-2026:10192-1"}, {"ecosystem": "openSUSE:Leap 16.0", "package": "postgresql16", "affected": null, "fixed": "16.13-160000.1.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/openSUSE-SU-2026:20447-1"}, {"ecosystem": "Red Hat:enterprise_linux:10.2", "package": "postgresql", "affected": null, "fixed": "0:16.13-1.el10_2", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:19010"}, {"ecosystem": "Red Hat:enterprise_linux:9::appstream", "package": "postgresql", "affected": null, "fixed": "0:13.23-2.el9_7", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:3730"}, {"ecosystem": "Red Hat:enterprise_linux:10.1", "package": "postgresql", "affected": null, "fixed": "0:16.13-1.el10_1", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:3887"}, {"ecosystem": "Red Hat:enterprise_linux:9::appstream", "package": "postgresql", "affected": null, "fixed": "0:15.17-1.module+el9.7.0+24029+ef6a2953", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:3896"}, {"ecosystem": "Red Hat:enterprise_linux:8::appstream", "package": "postgresql", "affected": null, "fixed": "0:13.23-2.module+el8.10.0+24039+b49622e4", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:4024"}, {"ecosystem": "Red Hat:enterprise_linux:8::appstream", "package": "postgresql", "affected": null, "fixed": "0:15.17-1.module+el8.10.0+24043+d28c3b3f", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:4059"}, {"ecosystem": "Red Hat:enterprise_linux:8::appstream", "package": "postgresql", "affected": null, "fixed": "0:16.13-1.module+el8.10.0+24044+3710dd58", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:4063"}, {"ecosystem": "Red Hat:enterprise_linux:8::appstream", "package": "postgresql", "affected": null, "fixed": "0:12.22-6.module+el8.10.0+24045+2b30545f", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:4064"}, {"ecosystem": "Red Hat:rhel_e4s:8.8::appstream", "package": "postgresql", "affected": null, "fixed": "0:13.23-1.module+el8.8.0+24046+5b274db5.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:4074"}, {"ecosystem": "Red Hat:rhel_tus:8.8::appstream", "package": "postgresql", "affected": null, "fixed": "0:13.23-1.module+el8.8.0+24046+5b274db5.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:4074"}, {"ecosystem": "Red Hat:rhel_e4s:8.8::appstream", "package": "postgresql", "affected": null, "fixed": "0:12.22-1.module+el8.8.0+24047+e7ffc146.3", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:4075"}, {"ecosystem": "Red Hat:rhel_tus:8.8::appstream", "package": "postgresql", "affected": null, "fixed": "0:12.22-1.module+el8.8.0+24047+e7ffc146.3", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:4075"}, {"ecosystem": "Red Hat:enterprise_linux:9::appstream", "package": "postgresql", "affected": null, "fixed": "0:16.13-1.module+el9.7.0+24031+188c384c", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:4110"}, {"ecosystem": "Red Hat:rhel_e4s:9.2::appstream", "package": "postgresql", "affected": null, "fixed": "0:15.17-1.module+el9.2.0+24076+9f04ec7d", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:4254"}, {"ecosystem": "Red Hat:enterprise_linux_eus:10.0", "package": "postgresql", "affected": null, "fixed": "0:16.13-1.el10_0", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:4441"}, {"ecosystem": "Red Hat:rhel_e4s:9.2::appstream", "package": "postgresql", "affected": null, "fixed": "0:13.23-1.el9_2.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:4475"}, {"ecosystem": "Red Hat:rhel_aus:8.4::appstream", "package": "postgresql", "affected": null, "fixed": "0:13.23-1.module+el8.4.0+24060+20ac1283.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:4504"}, {"ecosystem": "Red Hat:rhel_eus_long_life:8.4::appstream", "package": "postgresql", "affected": null, "fixed": "0:13.23-1.module+el8.4.0+24060+20ac1283.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:4504"}, {"ecosystem": "Red Hat:rhel_aus:8.6::appstream", "package": "postgresql", "affected": null, "fixed": "0:12.22-1.module+el8.6.0+24068+6365202e.3", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:4505"}, {"ecosystem": "Red Hat:rhel_e4s:8.6::appstream", "package": "postgresql", "affected": null, "fixed": "0:12.22-1.module+el8.6.0+24068+6365202e.3", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:4505"}, {"ecosystem": "Red Hat:rhel_tus:8.6::appstream", "package": "postgresql", "affected": null, "fixed": "0:12.22-1.module+el8.6.0+24068+6365202e.3", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:4505"}, {"ecosystem": "Red Hat:rhel_aus:8.2::appstream", "package": "postgresql", "affected": null, "fixed": "0:12.22-1.module+el8.2.0+24074+a7f2beb9.3", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:4506"}, {"ecosystem": "Red Hat:rhel_aus:8.4::appstream", "package": "postgresql", "affected": null, "fixed": "0:12.22-1.module+el8.4.0+24066+665c8b71.3", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:4509"}, {"ecosystem": "Red Hat:rhel_eus_long_life:8.4::appstream", "package": "postgresql", "affected": null, "fixed": "0:12.22-1.module+el8.4.0+24066+665c8b71.3", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:4509"}, {"ecosystem": "Red Hat:rhel_e4s:8.8::appstream", "package": "postgresql", "affected": null, "fixed": "0:15.17-1.module+el8.8.0+24064+070714b8", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:4515"}, {"ecosystem": "Red Hat:rhel_aus:8.6::appstream", "package": "postgresql", "affected": null, "fixed": "0:13.23-1.module+el8.6.0+24072+5a7aa9c7.2", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:4516"}, {"ecosystem": "Red Hat:rhel_e4s:8.6::appstream", "package": "postgresql", "affected": null, "fixed": "0:13.23-1.module+el8.6.0+24072+5a7aa9c7.2", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:4516"}, {"ecosystem": "Red Hat:rhel_tus:8.6::appstream", "package": "postgresql", "affected": null, "fixed": "0:13.23-1.module+el8.6.0+24072+5a7aa9c7.2", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:4516"}, {"ecosystem": "Red Hat:rhel_e4s:9.0::appstream", "package": "postgresql", "affected": null, "fixed": "0:13.23-1.el9_0.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:4518"}, {"ecosystem": "Red Hat:rhel_eus:9.4::appstream", "package": "postgresql", "affected": null, "fixed": "0:13.23-1.el9_4.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:4524"}, {"ecosystem": "Red Hat:rhel_eus:9.6::appstream", "package": "postgresql", "affected": null, "fixed": "0:13.23-1.el9_6.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:4528"}, {"ecosystem": "Red Hat:rhel_eus:9.4::appstream", "package": "postgresql", "affected": null, "fixed": "0:16.13-1.module+el9.4.0+24065+759b8157", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:4544"}, {"ecosystem": "Red Hat:rhel_eus:9.6::appstream", "package": "postgresql", "affected": null, "fixed": "0:15.17-1.module+el9.6.0+24075+d1e73d59", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:4546"}, {"ecosystem": "Red Hat:rhel_eus:9.6::appstream", "package": "postgresql", "affected": null, "fixed": "0:16.13-1.module+el9.6.0+24061+f3d71053", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:4547"}, {"ecosystem": "Red Hat:rhel_eus:9.4::appstream", "package": "postgresql", "affected": null, "fixed": "0:15.17-1.module+el9.4.0+24062+0e16bfab", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:4548"}, {"ecosystem": "Red Hat:enterprise_linux:10.2", "package": "postgresql16", "affected": null, "fixed": "0:16.13-1.el10_2", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:19010"}, {"ecosystem": "Red Hat:enterprise_linux:10.1", "package": "postgresql16", "affected": null, "fixed": "0:16.13-1.el10_1", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:3887"}, {"ecosystem": "Red Hat:enterprise_linux_eus:10.0", "package": "postgresql16", "affected": null, "fixed": "0:16.13-1.el10_0", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:4441"}]}