#1149670 pgpool2: CVE-2026-92867 CVE-2026-92868 CVE-2026-92869 CVE-2026-92870 CVE-2026-92871 CVE-2026-92872 CVE-2026-92873

Package:
src:pgpool2
Source:
src:pgpool2
Submitter:
Salvatore Bonaccorso
Date:
2026-10-02 09:07:07 UTC
Severity:
normal
Tags:
#1149670#5
Date:
2026-10-02 07:03:12 UTC
From:
To:
Hi,

The following vulnerabilities were published for pgpool2.

CVE-2026-92867[0]:
| An out-of-bounds write vulnerability exists in Pgpool-II , which may
| allow an authenticated attacker to cause abnormal process
| termination or arbitrary code execution.


CVE-2026-92868[1]:
| An improper certificate validation vulnerability exists in Pgpool-
| II, which may allow an unauthenticated attacker to bypass client
| certificate authentication.


CVE-2026-92869[2]:
| An out-of-bounds write vulnerability exists in Pgpool-II, which may
| allow an authenticated attacker to cause abnormal process
| termination.


CVE-2026-92870[3]:
| A stack-based buffer overflow vulnerability exists in Pgpool-II,
| which may allow an unauthenticated attacker to cause abnormal
| process termination.


CVE-2026-92871[4]:
| A NULL pointer dereference vulnerability exists in Pgpool-II, which
| may allow an unauthenticated attacker to cause abnormal termination
| of the watchdog process.


CVE-2026-92872[5]:
| Pgpool-II inserts sensitive information into log file, which may
| allow an authenticated attacker to obtain the cluster information.


CVE-2026-92873[6]:
| Pgpool-II contains an incorrect implementation of an authentication
| algorithm, which may allow an unauthenticated attacker to promote an
| arbitrary watchdog node to the leader node.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-92867
https://www.cve.org/CVERecord?id=CVE-2026-92867
[1] https://security-tracker.debian.org/tracker/CVE-2026-92868
https://www.cve.org/CVERecord?id=CVE-2026-92868
[2] https://security-tracker.debian.org/tracker/CVE-2026-92869
https://www.cve.org/CVERecord?id=CVE-2026-92869
[3] https://security-tracker.debian.org/tracker/CVE-2026-92870
https://www.cve.org/CVERecord?id=CVE-2026-92870
[4] https://security-tracker.debian.org/tracker/CVE-2026-92871
https://www.cve.org/CVERecord?id=CVE-2026-92871
[5] https://security-tracker.debian.org/tracker/CVE-2026-92872
https://www.cve.org/CVERecord?id=CVE-2026-92872
[6] https://security-tracker.debian.org/tracker/CVE-2026-92873
https://www.cve.org/CVERecord?id=CVE-2026-92873
[7] https://pgpool.net/news/2026-09-29/

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1149670#8
Date:
2026-10-02 08:23:54 UTC
From:
To:
Hello,

Bug #1149670 in pgpool2 reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/postgresql/pgpool2/-/commit/ac705df02ce6b70d93cf8310ff7b43aa182d2329
* CVE-2026-92867:
  An out-of-bounds write vulnerability exists in Pgpool-II , which may
  allow an authenticated attacker to cause abnormal process
  termination or arbitrary code execution.
* CVE-2026-92868:
  An improper certificate validation vulnerability exists in Pgpool-
  II, which may allow an unauthenticated attacker to bypass client
  certificate authentication.
* CVE-2026-92869:
  An out-of-bounds write vulnerability exists in Pgpool-II, which may
  allow an authenticated attacker to cause abnormal process
  termination.
* CVE-2026-92870:
  A stack-based buffer overflow vulnerability exists in Pgpool-II,
  which may allow an unauthenticated attacker to cause abnormal
  process termination.
* CVE-2026-92871:
  A NULL pointer dereference vulnerability exists in Pgpool-II, which
  may allow an unauthenticated attacker to cause abnormal termination
  of the watchdog process.
* CVE-2026-92872:
  Pgpool-II inserts sensitive information into log file, which may
  allow an authenticated attacker to obtain the cluster information.
* CVE-2026-92873:
  Pgpool-II contains an incorrect implementation of an authentication
  algorithm, which may allow an unauthenticated attacker to promote an
  arbitrary watchdog node to the leader node.
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1149670

#1149670#15
Date:
2026-10-02 09:05:25 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
pgpool2, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1149670@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Christoph Berg <myon@debian.org> (supplier of updated pgpool2 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Fri, 02 Oct 2026 10:06:02 +0200
Source: pgpool2
Architecture: source
Version: 4.7.3-1
Distribution: unstable
Urgency: medium
Maintainer: Debian PostgreSQL Maintainers <team+postgresql@tracker.debian.org>
Changed-By: Christoph Berg <myon@debian.org>
Closes: 1149670
Changes:
 pgpool2 (4.7.3-1) unstable; urgency=medium
 .
   * New upstream version 4.7.3. (Closes: #1149670)
   * CVE-2026-92867:
     An out-of-bounds write vulnerability exists in Pgpool-II , which may
     allow an authenticated attacker to cause abnormal process
     termination or arbitrary code execution.
   * CVE-2026-92868:
     An improper certificate validation vulnerability exists in Pgpool-
     II, which may allow an unauthenticated attacker to bypass client
     certificate authentication.
   * CVE-2026-92869:
     An out-of-bounds write vulnerability exists in Pgpool-II, which may
     allow an authenticated attacker to cause abnormal process
     termination.
   * CVE-2026-92870:
     A stack-based buffer overflow vulnerability exists in Pgpool-II,
     which may allow an unauthenticated attacker to cause abnormal
     process termination.
   * CVE-2026-92871:
     A NULL pointer dereference vulnerability exists in Pgpool-II, which
     may allow an unauthenticated attacker to cause abnormal termination
     of the watchdog process.
   * CVE-2026-92872:
     Pgpool-II inserts sensitive information into log file, which may
     allow an authenticated attacker to obtain the cluster information.
   * CVE-2026-92873:
     Pgpool-II contains an incorrect implementation of an authentication
     algorithm, which may allow an unauthenticated attacker to promote an
     arbitrary watchdog node to the leader node.
Checksums-Sha1:
 9aff0d18dda574d800a79e64567ddce9ef0819f8 2645 pgpool2_4.7.3-1.dsc
 0e2b51b7e673ce90ba53e47f412bdf332634e6d6 5850112 pgpool2_4.7.3.orig.tar.gz
 fdf38fe5ce1439b584fb50d5421d40622b8667a8 15008 pgpool2_4.7.3-1.debian.tar.xz
Checksums-Sha256:
 787562ba1f7b5ab05d7f491b89d884505e29b6abc8f6c3b8c05796f68e0000bc 2645 pgpool2_4.7.3-1.dsc
 4bf9df3e13feb8e64bee486b4ea54c9076296c2d9406165b0b68d32086fce250 5850112 pgpool2_4.7.3.orig.tar.gz
 219e85b431e4f1bf9e8d9d581facc400e611ea2a3737b82deb36b258895ab4f4 15008 pgpool2_4.7.3-1.debian.tar.xz
Files:
 b09e925887152d1d70abee7451ab8397 2645 database optional pgpool2_4.7.3-1.dsc
 782c956c3d998b9017133cc2fe3b8240 5850112 database optional pgpool2_4.7.3.orig.tar.gz
 59d578aa782ce5314d33ca37b04e4f91 15008 database optional pgpool2_4.7.3-1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEXEj+YVf0kXlZcIfGTFprqxLSp64FAmq/cvIACgkQTFprqxLS
p64Rlw/+K402uiudK1cTCQA+6wx1y0SM6SDRzcQt/xbDubOlmDN5ANFj6e2ZW347
dpFm0iXx0ThiaDQzrlYGhtyDM3EdBzHft7XMmDzWgTLBMi/RqhW8en6EghXzbafV
35+hz9oOKr4JYE7tzSNsWD2Pvq8565P3aj5iRtgKZ00jt5niaf9tdok7tdZ/MgTR
27+tlF7r2+E0h63vLJqO+uanloKsF/rwf6ldSHk0My6t2z4AmpqM1Iw0m18z+jjB
MtSFkpSQhYpArIOmTzp+RxetopQ1PklX2Xd2JdyvMdYWVFtfvvIFPg8riEilqKQJ
VBflgcumgU52jqN2Vj9v8zKJBBxAFTeqyDZLFKNXQXd7T6gEpppqjOsGruVXoKVb
IrGt22XKnLEN4V1qoNLTq9Ef5h+I2xUfOF1cj5Oy+/BLt3KGjA6OXXfs1L3cpaIm
xsC9sngBJ7xrD4wnpv7w8VUCs7Z4WIj0fkrhi6vreP+T8C7UJkc+hG8rN3iSa0oS
RMJAohuOniy0U4n24npIfjUPJQWiGhP+4mj3V7QAUZOouWG/SGuaNDeOSUYey96H
auUi61kNmMy/Yv+dkG1V4+pPBpkYCTvGnqeV5HL/CkVHs0XoK5efYHLUG2Q7617B
kILuOmLU8NGCHKNN6EngtBYfykzvpKqgnOZMUD7d0AXVoEIgcDM=
=avBm
-----END PGP SIGNATURE-----