- Package:
- src:libpgjava
- Source:
- src:libpgjava
- Submitter:
- Moritz Mühlenhoff
- Date:
- 2026-10-09 09:53:02 UTC
- Severity:
- normal
- Tags:
Hi, The following vulnerabilities were published for libpgjava. CVE-2026-107315[0]: | pgjdbc, the PostgreSQL JDBC Driver, versions 42.7.4 through 42.7.13 | pads a value that is shorter than its declared length with bytes | left in its send buffer instead of zeros, and the server stores | those bytes as part of the value. The bytes are messages the driver | sent earlier on the same connection: SQL text and parameter values | of recent statements, which on a pooled connection can come from | other requests. Each padded value can carry up to 8192 bytes of this | traffic, or 16320 bytes on a connection with GSS encryption. The | padding happens when an application declares a length larger than | the data it supplies, through PreparedStatement.setObject with a | ByteStreamWriter, CopyIn.writeToCopy, PGCopyOutputStream.write, | LargeObject.write, or Blob.setBytes. The driver accepts these calls | without an error. An attacker who can make the application store | such a value and read it back can collect earlier traffic. | Applications whose declared lengths always match their data are not | affected. Versions 42.7.3 and earlier pad with zeros. https://github.com/pgjdbc/pgjdbc/security/advisories/GHSA-f64h-wr5q-3qf3 https://github.com/pgjdbc/pgjdbc/commit/c8998c8e9632a7cdecb128dd7cd122d330b3598a (REL42.7.14) CVE-2026-107314[1]: | pgjdbc, the PostgreSQL JDBC Driver, versions 42.7.11 through 42.7.13 | enforce no restriction when the requireAuth connection property | excludes all six authentication methods the driver knows, for | example requireAuth=!password,!md5,!gss,!sspi,!scram-sha-256,!none. | The driver then accepts any method the server asks for, including | cleartext password authentication. A value without a method in it, | such as requireAuth=, (a single comma), is affected the same way. An | attacker positioned between the application and its server can ask | for cleartext password authentication and receive the database | password. A positive list such as requireAuth=scram-sha-256, and a | partial exclusion such as requireAuth=!password,!md5, are enforced | correctly. The property has no default value, so a deployment that | does not set it is not affected. 42.7.14 fixes the problem: such a | connection is refused with SQLState 08004, and a value without a | method in it is rejected as invalid. https://github.com/pgjdbc/pgjdbc/security/advisories/GHSA-rhp9-mr79-r74h https://github.com/pgjdbc/pgjdbc/commit/a65ef98fe37bf0ecbd1a6331205cdb924985ed75 (REL42.7.14) If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-107315 https://www.cve.org/CVERecord?id=CVE-2026-107315 [1] https://security-tracker.debian.org/tracker/CVE-2026-107314 https://www.cve.org/CVERecord?id=CVE-2026-107314 Please adjust the affected versions in the BTS as needed.
Hello, Bug #1150330 in libpostgresql-jdbc-java reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/java-team/libpostgresql-jdbc-java/-/commit/2a969c513914b30805ec2fe82f78d769250f0f89 + CVE-2026-107315: versions 42.7.4 through 42.7.13 pad a value that is shorter than its declared length with bytes left in its send buffer instead of zeros, and the server stores those bytes as part of the value. The bytes are messages the driver sent earlier on the same connection: SQL text and parameter values of recent statements, which on a pooled connection can come from other requests. Each padded value can carry up to 8192 bytes of this traffic, or 16320 bytes on a connection with GSS encryption. The padding happens when an application declares a length larger than the data it supplies, through PreparedStatement.setObject with a ByteStreamWriter, CopyIn.writeToCopy, PGCopyOutputStream.write, LargeObject.write, or Blob.setBytes. The driver accepts these calls without an error. An attacker who can make the application store such a value and read it back can collect earlier traffic. Applications whose declared lengths always match their data are not affected. Versions 42.7.3 and earlier pad with zeros. + CVE-2026-107314: versions 42.7.11 through 42.7.13 enforce no restriction when the requireAuth connection property excludes all six authentication methods the driver knows, for example requireAuth=!password,!md5,!gss,!sspi,!scram-sha-256,!none. The driver then accepts any method the server asks for, including cleartext password authentication. A value without a method in it, such as requireAuth=, (a single comma), is affected the same way. An attacker positioned between the application and its server can ask for cleartext password authentication and receive the database password. A positive list such as requireAuth=scram-sha-256, and a partial exclusion such as requireAuth=!password,!md5, are enforced correctly. The property has no default value, so a deployment that does not set it is not affected. 42.7.14 fixes the problem: such a connection is refused with SQLState 08004, and a value without a method in it is rejected as invalid. ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1150330
We believe that the bug you reported is fixed in the latest version of
libpgjava, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1150330@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Christoph Berg <myon@debian.org> (supplier of updated libpgjava package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Fri, 09 Oct 2026 11:14:28 +0200
Source: libpgjava
Architecture: source
Version: 42.7.14-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org>
Changed-By: Christoph Berg <myon@debian.org>
Closes: 1150330
Changes:
libpgjava (42.7.14-1) unstable; urgency=medium
.
* New upstream version 42.7.14. (Closes: #1150330)
+ CVE-2026-107315: versions 42.7.4 through 42.7.13 pad a value that is
shorter than its declared length with bytes left in its send buffer
instead of zeros, and the server stores those bytes as part of the
value. The bytes are messages the driver sent earlier on the same
connection: SQL text and parameter values of recent statements, which on
a pooled connection can come from other requests. Each padded value can
carry up to 8192 bytes of this traffic, or 16320 bytes on a connection
with GSS encryption. The padding happens when an application declares a
length larger than the data it supplies, through
PreparedStatement.setObject with a ByteStreamWriter, CopyIn.writeToCopy,
PGCopyOutputStream.write, LargeObject.write, or Blob.setBytes. The
driver accepts these calls without an error. An attacker who can make
the application store such a value and read it back can collect earlier
traffic. Applications whose declared lengths always match their data are
not affected. Versions 42.7.3 and earlier pad with zeros.
+ CVE-2026-107314: versions 42.7.11 through 42.7.13 enforce no restriction
when the requireAuth connection property excludes all six authentication
methods the driver knows, for example
requireAuth=!password,!md5,!gss,!sspi,!scram-sha-256,!none. The driver
then accepts any method the server asks for, including cleartext
password authentication. A value without a method in it, such as
requireAuth=, (a single comma), is affected the same way. An attacker
positioned between the application and its server can ask for cleartext
password authentication and receive the database password. A positive
list such as requireAuth=scram-sha-256, and a partial exclusion such as
requireAuth=!password,!md5, are enforced correctly. The property has no
default value, so a deployment that does not set it is not affected.
42.7.14 fixes the problem: such a connection is refused with SQLState
08004, and a value without a method in it is rejected as invalid.
Checksums-Sha1:
944da05a66bf5092fbe5345307a1aef2801681e9 2426 libpgjava_42.7.14-1.dsc
522aed9be110272187ff0b7b7e5d771acbf6e3a0 1224149 libpgjava_42.7.14.orig.tar.gz
98c9dda4625a12fac5174dce8a8a51037226d9ec 11764 libpgjava_42.7.14-1.debian.tar.xz
Checksums-Sha256:
c14c83a5486cf4da479ddab38f3e3b21ac9cdea8f4d97175e5e8a7cef5b566e8 2426 libpgjava_42.7.14-1.dsc
1f38e5e32f1e9b2200f6c0e7cce02d635d7bc14b35dff803a52e09cd666a16b9 1224149 libpgjava_42.7.14.orig.tar.gz
5a614a21193cf7ffdfdaf334433307d3628cb10beddc02bd292fc3eb76da26ed 11764 libpgjava_42.7.14-1.debian.tar.xz
Files:
086da6a46f697a8f81d33dc933aad648 2426 java optional libpgjava_42.7.14-1.dsc
abe9eb01a66a7a2371e5eb154fd5fc93 1224149 java optional libpgjava_42.7.14.orig.tar.gz
86e1b2fac82844b291ec4f280671fe72 11764 java optional libpgjava_42.7.14-1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEXEj+YVf0kXlZcIfGTFprqxLSp64FAmrItU4ACgkQTFprqxLS
p663kQ//QCwMgWr+nYJT1ZbWlwjtGJKzcj8J0tYimgp2gxKZnpk4eIHP+6RLIqcq
293419kM3DUf1gq1pzhxHgwhO+NZQocYiDlUAojaa/4iJDGWKHKxGgMqCyD/DK57
UXKqx6jkYHC6Go6hzeLe6HEU8DgGHkOXUqyoNTZVxh6uJVlT9zTDHr9M0cPc70bP
76kNw9zhDizk9C8Eo7VAloK3E2vcag/mjE0Ceo7c5IU1YWHTB7PZk5uSyqNtb+B9
/A4E1s8aFO4+p9LrrPYKRE1wa4NPSKMuufHvpXCfnpCoFPVCxwiQLtl6GE9wrsvg
TU9YS+L+AuXdgTLyCyGebJLq5QOk8jyDHgCjqIwmFZrxqcEAFdljWbPMUkfXQ5Fq
KkJPjE9fJtg1MMIrU83jPK9KwRGjN06Xzcqcs8gW+bc2UZop8geuj19cHeZWQUaa
39IoXKo3N/1xE0xQz6I3OerV5ByXTS0VIg+z78LUgdD5YazQCtdU2RcKlxNAT5qD
l9UpphixHyKnZ2LBv6j0lnR8fvu4g7ZIUPR8KgGn88rDe1bCHHokAJaMgENg9eNM
tmcwUVb0rNFOYQRagJbO8WffINCRYv4Ms4LScGZox/CqmsNjd7zveZIiW8RM4hlk
HitTys285CMBtQ8PWHEFX5j3yym85p5Cva1SSIeKnX+guJTaZdo=
=bd+B
-----END PGP SIGNATURE-----