Ubuntu security alert
Canonical released fixes for 30 PostgreSQL vulnerabilities across three Ubuntu LTS versions.
Published 20 August 2026 · Canonical USN-8653-1
The notice covers SQL injection, information exposure, privilege problems, memory-safety bugs and possible code execution.
Impact differs by vulnerability and Ubuntu release.
Affected Ubuntu LTS releases
Canonical supplied corrected packages for each supported release.
Serious outcomes
Other issues could enable SQL injection, leak information or bypass intended row-security restrictions.
These are possible outcomes—not proof that every server has been attacked.
Important context
Canonical describes many issues as requiring an authenticated user. That still matters on shared, exposed or poorly restricted systems.
Check your exposure
Review who can connect, restrict port 5432, remove unnecessary accounts and confirm least-privilege permissions.
Network controls reduce exposure but do not replace the update.
What administrators should do
The takeaway
Ubuntu 22.04, 24.04 and 26.04 administrators should apply the corrected PostgreSQL packages and verify their services.
Primary source: Canonical USN-8653-1