public inbox for [email protected]
help / color / mirror / Atom feedFrom: apt.postgresql.org Repository Update <[email protected]>
To: PostgreSQL on Debian and Ubuntu <[email protected]>
Subject: libpgjava updated to version 42.7.11-1.pgdg+1
Date: Wed, 29 Apr 2026 13:17:45 +0000
Message-ID: <[email protected]> (raw)
The package libpgjava was updated on apt.postgresql.org.
apt-listchanges: Changelogs
---------------------------
libpgjava (42.7.11-1.pgdg+1) sid-pgdg; urgency=medium
* Rebuild for sid-pgdg.
* No source changes.
-- PostgreSQL on Debian and Ubuntu <[email protected]> Wed, 29 Apr 2026 11:08:43 +0200
libpgjava (42.7.11-1) unstable; urgency=medium
* New upstream version 42.7.11.
* Limit SCRAM PBKDF2 iterations accepted from the server.
pgjdbc was vulnerable to a client-side denial of service in SCRAM-SHA-256
authentication, where a malicious or compromised PostgreSQL server could
specify an extremely large PBKDF2 iteration count, causing the client to
consume unbounded CPU and potentially exhaust connection pools. The fix
introduces a new scramMaxIterations connection property (defaulting to
100,000) to cap iteration counts before computation begins.
(CVE-2026-42198)
-- Christoph Berg <[email protected]> Wed, 29 Apr 2026 11:08:43 +0200
New version 42.7.11-1.pgdg+1:
libpgjava | 42.7.11-1.pgdg+1 | sid-pgdg | source
libpgjava | 42.7.10-1.pgdg+1 | sid-pgdg | source
libpgjava | 42.7.11-1.pgdg14+1 | forky-pgdg | source
libpgjava | 42.7.10-1.pgdg14+1 | forky-pgdg | source
libpgjava | 42.7.11-1.pgdg13+1 | trixie-pgdg | source
libpgjava | 42.7.10-1.pgdg13+1 | trixie-pgdg | source
libpgjava | 42.7.11-1.pgdg12+1 | bookworm-pgdg | source
libpgjava | 42.7.10-1.pgdg12+1 | bookworm-pgdg | source
libpgjava | 42.7.11-1.pgdg11+1 | bullseye-pgdg | source
libpgjava | 42.7.10-1.pgdg11+1 | bullseye-pgdg | source
libpgjava | 42.7.11-1.pgdg26.04+1 | resolute-pgdg | source
libpgjava | 42.7.10-1.pgdg26.04+1 | resolute-pgdg | source
libpgjava | 42.7.11-1.pgdg25.10+1 | questing-pgdg | source
libpgjava | 42.7.10-1.pgdg25.10+1 | questing-pgdg | source
libpgjava | 42.7.11-1.pgdg24.04+1 | noble-pgdg | source
libpgjava | 42.7.10-1.pgdg24.04+1 | noble-pgdg | source
libpgjava | 42.7.11-1.pgdg22.04+1 | jammy-pgdg | source
libpgjava | 42.7.10-1.pgdg22.04+1 | jammy-pgdg | source
libpostgresql-jdbc-java | 42.7.11-1.pgdg+1 | sid-pgdg | amd64, arm64, ppc64el
libpostgresql-jdbc-java | 42.7.10-1.pgdg+1 | sid-pgdg | amd64, arm64, ppc64el
libpostgresql-jdbc-java | 42.7.11-1.pgdg14+1 | forky-pgdg | amd64, arm64, ppc64el
libpostgresql-jdbc-java | 42.7.10-1.pgdg14+1 | forky-pgdg | amd64, arm64, ppc64el
libpostgresql-jdbc-java | 42.7.11-1.pgdg13+1 | trixie-pgdg | amd64, arm64, ppc64el
libpostgresql-jdbc-java | 42.7.10-1.pgdg13+1 | trixie-pgdg | amd64, arm64, ppc64el
libpostgresql-jdbc-java | 42.7.11-1.pgdg12+1 | bookworm-pgdg | amd64, arm64, ppc64el
libpostgresql-jdbc-java | 42.7.10-1.pgdg12+1 | bookworm-pgdg | amd64, arm64, ppc64el
libpostgresql-jdbc-java | 42.7.11-1.pgdg11+1 | bullseye-pgdg | amd64, arm64, ppc64el
libpostgresql-jdbc-java | 42.7.10-1.pgdg11+1 | bullseye-pgdg | amd64, arm64, ppc64el
libpostgresql-jdbc-java | 42.7.11-1.pgdg26.04+1 | resolute-pgdg | amd64, arm64, ppc64el
libpostgresql-jdbc-java | 42.7.10-1.pgdg26.04+1 | resolute-pgdg | amd64, arm64, ppc64el
libpostgresql-jdbc-java | 42.7.11-1.pgdg25.10+1 | questing-pgdg | amd64
libpostgresql-jdbc-java | 42.7.10-1.pgdg25.10+1 | questing-pgdg | amd64
libpostgresql-jdbc-java | 42.7.11-1.pgdg24.04+1 | noble-pgdg | amd64, arm64, ppc64el
libpostgresql-jdbc-java | 42.7.10-1.pgdg24.04+1 | noble-pgdg | amd64, arm64, ppc64el
libpostgresql-jdbc-java | 42.7.11-1.pgdg22.04+1 | jammy-pgdg | amd64, arm64, ppc64el
libpostgresql-jdbc-java | 42.7.10-1.pgdg22.04+1 | jammy-pgdg | amd64, arm64, ppc64el
The public mirrors serving apt.postgresql.org are synced hourly,
the updated packages will be available there shortly.
reply
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Reply to all the recipients using the --to and --cc options:
reply via email
To: [email protected]
Cc: [email protected], [email protected]
Subject: Re: libpgjava updated to version 42.7.11-1.pgdg+1
In-Reply-To: <[email protected]>
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox