AWS Security ChangesHomeSearch

AWS AmazonRDS: Aurora PostgreSQL release notes: CVE fixes and Babelfish role validation

Service: AmazonRDS · 2026-09-27 · Security-related high

File: AmazonRDS/latest/AuroraPostgreSQLReleaseNotes/AuroraPostgreSQL.Updates.md · Type: authz · CVE: CVE-2026-14671, CVE-2026-2003, CVE-2026-2004, CVE-2026-2005, CVE-2026-2006, CVE-2026-2007, CVE-2026-3172, CVE-2026-6472, CVE-2026-6473, CVE-2026-6474, CVE-2026-6475, CVE-2026-6476, CVE-2026-6477, CVE-2026-6478, CVE-2026-6479, CVE-2026-6575, CVE-2026-6637, CVE-2026-6638

Summary

Adds release notes for Aurora PostgreSQL versions 18.4.2, 17.10.2, 16.14.2, 15.18.2, and 14.23.2 (Sept 14, 2026) including backported fixes for CVE-2026-14671, plus 14.6.16 and 13.9.16 (Aug 07, 2026) with a long list of PostgreSQL CVE backports, a babelfish_set_role permission validation fix, and an Encryption in Transit CPU overhead fix. Also adds 12.9.19 and 11.21.13 (Aug 2026) entries with CVE-2026-6472 through CVE-2026-6638 and the babelfish_set_role fix. Includes numerous editorial wording/punctuation edits to older release note entries.

Security assessment

The added release notes explicitly list backported fixes for multiple named PostgreSQL community security CVEs (e.g., CVE-2026-14671 and the CVE-2026-2003..2007 / CVE-2026-6472..6638 set) addressed in new engine versions, and add a security enhancement: 'Improved permission validation in the babelfish_set_role function when setting roles.' That is a concrete authorization-validation fix (role escalation/privilege boundary) in Babelfish, plus Encryption in Transit stability work. These are patched vulnerabilities released to customers, matching the high-severity criteria for fixed CVEs and authorization fixes.

Evidence

    * [CVE-2026-14671](https://nvd.nist.gov/vuln/detail/CVE-2026-14671).

Diff

diff --git a/AmazonRDS/latest/AuroraPostgreSQLReleaseNotes/AuroraPostgreSQL.Updates.md b/AmazonRDS/latest/AuroraPostgreSQLReleaseNotes/AuroraPostgreSQL.Updates.md
index b7796bd61..97e565c57 100644
--- a//AmazonRDS/latest/AuroraPostgreSQLReleaseNotes/AuroraPostgreSQL.Updates.md
+++ b//AmazonRDS/latest/AuroraPostgreSQLReleaseNotes/AuroraPostgreSQL.Updates.md
@@ -69,0 +70,2 @@ This release of Aurora PostgreSQL is compatible with PostgreSQL 18.4. For more i
+  * Aurora PostgreSQL 18.4.2, September 14, 2026
+
@@ -76,0 +79,35 @@ This release of Aurora PostgreSQL is compatible with PostgreSQL 18.4. For more i
+#### Aurora PostgreSQL 18.4.2, September 14, 2026
+
+**Critical stability enhancements**
+
+  * Fixed an issue with index scan prefetch that could return duplicate rows, and increased I/O wait times.
+
+  * HypoPG will only consider hypothetical indexes during EXPLAIN that were created by the current role.
+
+
+
+
+**High priority enhancements**
+
+  * Backported fixes for the following PostgreSQL community security issues:
+
+    * [CVE-2026-14671](https://nvd.nist.gov/vuln/detail/CVE-2026-14671).
+
+
+
+
+**General enhancements**
+
+  * Fixed multiple issues to improve the reliability of client connections during Zero Downtime Patching (ZDP).
+
+  * Fixed an issue with reader instances, improving replica stability.
+
+  * Fixed an issue that can cause the replica to restart when an internal counter that tracks the reader's position in the replication stream overflows.
+
+  * Fixed an issue that can cause the database to restart when a storage configuration change occurs while a metadata synchronization operation is still in progress.
+
+  * Fixed an issue that can cause a database instance to restart due to a memory management issue in storage node connection handling.
+
+
+
+
@@ -407,0 +445,2 @@ This release of Aurora PostgreSQL is compatible with PostgreSQL 17.10. For more
+  * Aurora PostgreSQL 17.10.2, September 14, 2026
+
@@ -414,0 +454,35 @@ This release of Aurora PostgreSQL is compatible with PostgreSQL 17.10. For more
+#### Aurora PostgreSQL 17.10.2, September 14, 2026
+
+**Critical stability enhancements**
+
+  * Fixed an issue with index scan prefetch that could return duplicate rows, and increased I/O wait times.
+
+  * HypoPG will only consider hypothetical indexes during EXPLAIN that were created by the current role.
+
+
+
+
+**High priority enhancements**
+
+  * Backported fixes for the following PostgreSQL community security issues:
+
+    * [CVE-2026-14671](https://nvd.nist.gov/vuln/detail/CVE-2026-14671).
+
+
+
+
+**General enhancements**
+
+  * Fixed multiple issues to improve the reliability of client connections during Zero Downtime Patching (ZDP).
+
+  * Fixed an issue with reader instances, improving replica stability.
+
+  * Fixed an issue that can cause the replica to restart when an internal counter that tracks the reader's position in the replication stream overflows.
+
+  * Fixed an issue that can cause the database to restart when a storage configuration change occurs while a metadata synchronization operation is still in progress.
+
+  * Fixed an issue that can cause a database instance to restart due to a memory management issue in storage node connection handling.
+
+
+
+
@@ -2039,0 +2114,2 @@ This release of Aurora PostgreSQL is compatible with PostgreSQL 16.14. For more
+  * Aurora PostgreSQL 16.14.2, September 14, 2026
+
@@ -2046,0 +2123,35 @@ This release of Aurora PostgreSQL is compatible with PostgreSQL 16.14. For more
+#### Aurora PostgreSQL 16.14.2, September 14, 2026
+
+**Critical stability enhancements**
+
+  * Fixed an issue with index scan prefetch that could return duplicate rows, and increased I/O wait times.
+
+  * HypoPG will only consider hypothetical indexes during EXPLAIN that were created by the current role.
+
+
+
+
+**High priority enhancements**
+
+  * Backported fixes for the following PostgreSQL community security issues:
+
+    * [CVE-2026-14671](https://nvd.nist.gov/vuln/detail/CVE-2026-14671).
+
+
+
+
+**General enhancements**
+
+  * Fixed multiple issues to improve the reliability of client connections during Zero Downtime Patching (ZDP).
+
+  * Fixed an issue with reader instances, improving replica stability.
+
+  * Fixed an issue that can cause the replica to restart when an internal counter that tracks the reader's position in the replication stream overflows.
+
+  * Fixed an issue that can cause the database to restart when a storage configuration change occurs while a metadata synchronization operation is still in progress.
+
+  * Fixed an issue that can cause a database instance to restart due to a memory management issue in storage node connection handling.
+
+
+
+
@@ -4866,0 +4978,2 @@ This release of Aurora PostgreSQL is compatible with PostgreSQL 15.18. For more
+  * Aurora PostgreSQL 15.18.2, September 14, 2026
+
@@ -4873,0 +4987,35 @@ This release of Aurora PostgreSQL is compatible with PostgreSQL 15.18. For more
+#### Aurora PostgreSQL 15.18.2, September 14, 2026
+
+**Critical stability enhancements**
+
+  * Fixed an issue with index scan prefetch that could return duplicate rows, and increased I/O wait times.
+
+  * HypoPG will only consider hypothetical indexes during EXPLAIN that were created by the current role.
+
+
+
+
+**High priority enhancements**
+
+  * Backported fixes for the following PostgreSQL community security issues:
+
+    * [CVE-2026-14671](https://nvd.nist.gov/vuln/detail/CVE-2026-14671).
+
+
+
+
+**General enhancements**
+
+  * Fixed multiple issues to improve the reliability of client connections during Zero Downtime Patching (ZDP).
+
+  * Fixed an issue with reader instances, improving replica stability.
+
+  * Fixed an issue that can cause the replica to restart when an internal counter that tracks the reader's position in the replication stream overflows.
+
+  * Fixed an issue that can cause the database to restart when a storage configuration change occurs while a metadata synchronization operation is still in progress.
+
+  * Fixed an issue that can cause a database instance to restart due to a memory management issue in storage node connection handling.
+
+
+
+
@@ -8728,0 +8877,2 @@ This release of Aurora PostgreSQL is compatible with PostgreSQL 14.23. For more
+  * Aurora PostgreSQL 14.23.2, September 14, 2026
+
@@ -8735,0 +8886,35 @@ This release of Aurora PostgreSQL is compatible with PostgreSQL 14.23. For more
+#### Aurora PostgreSQL 14.23.2, September 14, 2026
+
+**Critical stability enhancements**
+
+  * Fixed an issue with index scan prefetch that could return duplicate rows, and increased I/O wait times.
+
+  * HypoPG will only consider hypothetical indexes during EXPLAIN that were created by the current role.
+
+
+
+
+**High priority enhancements**
+
+  * Backported fixes for the following PostgreSQL community security issues:
+
+    * [CVE-2026-14671](https://nvd.nist.gov/vuln/detail/CVE-2026-14671).
+
+
+
+
+**General enhancements**
+
+  * Fixed multiple issues to improve the reliability of client connections during Zero Downtime Patching (ZDP).
+
+  * Fixed an issue with reader instances, improving replica stability.
+
+  * Fixed an issue that can cause the replica to restart when an internal counter that tracks the reader's position in the replication stream overflows.
+
+  * Fixed an issue that can cause the database to restart when a storage configuration change occurs while a metadata synchronization operation is still in progress.
+
+  * Fixed an issue that can cause a database instance to restart due to a memory management issue in storage node connection handling.
+
+
+
+
@@ -12435,0 +12621,2 @@ This release of Aurora PostgreSQL is compatible with PostgreSQL 14.6. For more i