Security News

Cybersecurity news aggregator

🔄
INFO Updates Red Hat Errata

RHSA-2026:27741: Important: postgresql security update

  • What: Security update for PostgreSQL
  • Impact: Red Hat Enterprise Linux 9 systems affected
Read Full Article →

Red Hat Product Errata RHSA-2026:27741 - Security Advisory Issued: 2026-06-22 Updated: 2026-06-22 RHSA-2026:27741 - Security Advisory Overview Updated Packages Synopsis Important: postgresql security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for postgresql is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description PostgreSQL is an advanced object-relational database management system (DBMS). Security Fix(es): postgresql: PostgreSQL: Operating system account hijack via symlink following in pg_basebackup and pg_rewind (CVE-2026-6475) postgresql: PostgreSQL libpq: Buffer overflow allows server superuser to overwrite client stack memory (CVE-2026-6477) postgresql: PostgreSQL: Credential recovery via covert timing channel in MD5 password comparison (CVE-2026-6478) postgresql: integer overflow can cause an undersized allocation and an out-of-bounds write (CVE-2026-6473) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 9 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 x86_64 Red Hat Enterprise Linux for IBM z Systems 9 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.8 s390x Red Hat Enterprise Linux for Power, little endian 9 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.8 ppc64le Red Hat Enterprise Linux for ARM 64 9 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.8 aarch64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.8 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.8 x86_64 Red Hat CodeReady Linux Builder for x86_64 9 x86_64 Red Hat CodeReady Linux Builder for Power, little endian 9 ppc64le Red Hat CodeReady Linux Builder for ARM 64 9 aarch64 Red Hat CodeReady Linux Builder for IBM z Systems 9 s390x Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 9.8 x86_64 Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 9.8 ppc64le Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 9.8 s390x Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 9.8 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.8 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.8 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.8 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.8 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.8 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.8 s390x Fixes BZ - 2477439 - CVE-2026-6475 postgresql: PostgreSQL: Operating system account hijack via symlink following in pg_basebackup and pg_rewind BZ - 2477442 - CVE-2026-6477 postgresql: PostgreSQL libpq: Buffer overflow allows server superuser to overwrite client stack memory BZ - 2477447 - CVE-2026-6478 postgresql: PostgreSQL: Credential recovery via covert timing channel in MD5 password comparison BZ - 2477448 - CVE-2026-6473 postgresql: integer overflow can cause an undersized allocation and an out-of-bounds write CVEs CVE-2026-6473 CVE-2026-6475 CVE-2026-6477 CVE-2026-6478 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 9 SRPM postgresql-13.23-3.el9_8.src.rpm SHA-256: dbfb3a1f702437c2a60cdc6c977ecc0688576e6ff2a389953e7bf6ced69c0ed0 x86_64 postgresql-13.23-3.el9_8.x86_64.rpm SHA-256: 10deb37cadf66177e4cdd2805d3125fb7cc6e3093487a3389f2eb33fc68a5fea postgresql-contrib-13.23-3.el9_8.x86_64.rpm SHA-256: e0c1f2d22f5d39df6768632fd4f3fb1891608e58af054f9c6616710637ec9882 postgresql-contrib-debuginfo-13.23-3.el9_8.x86_64.rpm SHA-256: c13f70b0d9125ecfaacf5d4c96d044159ae8b8986b5d13776ec4668c0a8663cc postgresql-debuginfo-13.23-3.el9_8.x86_64.rpm SHA-256: 05f1cc215492ff71e1729d2e5233c80aba059ad3a1a23cad8bb59152ad264fa8 postgresql-debugsource-13.23-3.el9_8.x86_64.rpm SHA-256: 3a40661eb678ecd092281f236a8c2f78574af5f8faf99f7f72f8c30a408390ae postgresql-docs-debuginfo-13.23-3.el9_8.x86_64.rpm SHA-256: 545b2629da0c7fc6393d6b472a56280f3ca32529fd737de9c5a63d9c80baa80d postgresql-plperl-13.23-3.el9_8.x86_64.rpm SHA-256: 106dad440bc71bcea5f98b82abc733edf05bd9be35bfd9d190b85bb93035736e postgresql-plperl-debuginfo-13.23-3.el9_8.x86_64.rpm SHA-256: f6f35f0eb563ad593fa195e563d2c21902c1af4f23a082e72c6a40766d16d430 postgresql-plpython3-13.23-3.el9_8.x86_64.rpm SHA-256: 00951503e8c14247335695186015344b7b12bff35131840bd30732d9e529bcb3 postgresql-plpython3-debuginfo-13.23-3.el9_8.x86_64.rpm SHA-256: 953be47c827fcacb098f87186ab7110a20aaeb33ca118b832c54e6c586e3e8b6 postgresql-pltcl-13.23-3.el9_8.x86_64.rpm SHA-256: 53a8edbc2496f8ca070373481428f3378595f117dab42e2406ec40acf3add443 postgresql-pltcl-debuginfo-13.23-3.el9_8.x86_64.rpm SHA-256: 0fa8accd9ecf4976b7baad17c7075aef8e3c5b04b512e9b98154f5a510696df6 postgresql-private-libs-13.23-3.el9_8.x86_64.rpm SHA-256: f822b91790dedc438c3a475aff2e2725cc53a007f9523b51b527104480f68faa postgresql-private-libs-debuginfo-13.23-3.el9_8.x86_64.rpm SHA-256: cd71791e64f2594d8360f684e7b32b69a1d860cca572d2d40b95139b5d0218f3 postgresql-server-13.23-3.el9_8.x86_64.rpm SHA-256: 30c1fd22df0fd125191c9a4143ffdca5fc339357fa0cc36f5a408ab033535533 postgresql-server-debuginfo-13.23-3.el9_8.x86_64.rpm SHA-256: 8dc7219d4c4fda69483a9923763eec3dee7ab99375ed129d5963860f01adc7e2 postgresql-server-devel-debuginfo-13.23-3.el9_8.x86_64.rpm SHA-256: 5298517344bdce1b136bcd025b1ccc57af30a0f340fc1b555b80345d89d23599 postgresql-test-debuginfo-13.23-3.el9_8.x86_64.rpm SHA-256: 9a979e23f59088d9af6157b42a60dff455e02adc7a7d14f90cdbd54aea78cef6 postgresql-upgrade-13.23-3.el9_8.x86_64.rpm SHA-256: 4cc435ed261abe64200465e388ab1b80ce4327c26990fb55427bc2a1334e5b54 postgresql-upgrade-debuginfo-13.23-3.el9_8.x86_64.rpm SHA-256: 30e24d8ab049f495f85b397d477f0f3d0f6e6446ec3dc5af7558fcb46f362f53 postgresql-upgrade-devel-debuginfo-13.23-3.el9_8.x86_64.rpm SHA-256: 66baf27d2749a1db8c32024737c1c0e12b324e7993ddd2ddac15b8826ad9ab58 Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 SRPM postgresql-13.23-3.el9_8.src.rpm SHA-256: dbfb3a1f702437c2a60cdc6c977ecc0688576e6ff2a389953e7bf6ced69c0ed0 x86_64 postgresql-13.23-3.el9_8.x86_64.rpm SHA-256: 10deb37cadf66177e4cdd2805d3125fb7cc6e3093487a3389f2eb33fc68a5fea postgresql-contrib-13.23-3.el9_8.x86_64.rpm SHA-256: e0c1f2d22f5d39df6768632fd4f3fb1891608e58af054f9c6616710637ec9882 postgresql-contrib-debuginfo-13.23-3.el9_8.x86_64.rpm SHA-256: c13f70b0d9125ecfaacf5d4c96d044159ae8b8986b5d13776ec4668c0a8663cc postgresql-debuginfo-13.23-3.el9_8.x86_64.rpm SHA-256: 05f1cc215492ff71e1729d2e5233c80aba059ad3a1a23cad8bb59152ad264fa8 postgresql-debugsource-13.23-3.el9_8.x86_64.rpm SHA-256: 3a40661eb678ecd092281f236a8c2f78574af5f8faf99f7f72f8c30a408390ae postgresql-docs-debuginfo-13.23-3.el9_8.x86_64.rpm SHA-256: 545b2629da0c7fc6393d6b472a56280f3ca32529fd737de9c5a63d9c80baa80d postgresql-plperl-13.23-3.el9_8.x86_64.rpm SHA-256: 106dad440bc71bcea5f98b82abc733edf05bd9be35bfd9d190b85bb93035736e postgresql-plperl-debuginfo-13.23-3.el9_8.x86_64.rpm SHA-256: f6f35f0eb563ad593fa195e563d2c21902c1af4f23a082e72c6a40766d16d430 postgresql-plpython3-13.23-3.el9_8.x86_64.rpm SHA-256: 00951503e8c14247335695186015344b7b12bff35131840bd30732d9e529bcb3 postgresql-plpython3-debuginfo-13.23-3.el9_8.x86_64.rpm SHA-256: 953be47c827fcacb098f87186ab7110a20aaeb33ca118b832c54e6c586e3e8b6 postgresql-pltcl-13.23-3.el9_8.x86_64.rpm SHA-256: 53a8edbc2496f8ca070373481428f3378595f117dab42e2406ec40acf3add443 postgresql-pltcl-debuginfo-13.23-3.el9_8.x86_64.rpm SHA-256: 0fa8accd9ecf4976b7baad17c7075aef8e3c5b04b512e9b98154f5a510696df6 postgresql-private-libs-13.23-3.el9_8.x86_64.rpm SHA-256: f822b91790dedc438c3a475aff2e2725cc53a007f9523b51b527104480f68faa postgresql-private-libs-debuginfo-13.23-3.el9_8.x86_64.rpm SHA-256: cd71791e64f2594d8360f684e7b32b69a1d860cca572d2d40b95139b5d0218f3 postgresql-server-13.23-3.el9_8.x86_64.rpm SHA-256: 30c1fd22df0fd125191c9a4143ffdca5fc339357fa0cc36f5a408ab033535533 postgresql-server-debuginfo-13.23-3.el9_8.x86_64.rpm SHA-256: 8dc7219d4c4fda69483a9923763eec3dee7ab99375ed129d5963860f01adc7e2 postgresql-server-devel-debuginfo-13.23-3.el9_8.x86_64.rpm SHA-256: 5298517344bdce1b136bcd025b1ccc57af30a0f340fc1b555b80345d89d23599 postgresql-test-debuginfo-13.23-3.el9_8.x86_64.rpm SHA-256: 9a979e23f59088d9af6157b42a60dff455e02adc7a7d14f90cdbd54aea78cef6 postgresql-upgrade-13.23-3.el9_8.x86_64.rpm SHA-256: 4cc435ed261abe64200465e388ab1b80ce4327c26990fb55427bc2a1334e5b54 postgresql-upgrade-debuginfo-13.23-3.el9_8.x86_64.rpm SHA-256: 30e24d8ab049f495f85b397d477f0f3d0f6e6446ec3dc5af7558fcb46f362f53 postgresql-upgrade-devel-debuginfo-13.23-3.el9_8.x86_64.rpm SHA-256: 66baf27d2749a1db8c32024737c1c0e12b324e7993ddd2ddac15b8826ad9ab58 Red Hat Enterprise Linux for IBM z Systems 9 SRPM postgresql-13.23-3.el9_8.src.rpm SHA-256: dbfb3a1f702437c2a60cdc6c977ecc0688576e6ff2a389953e7bf6ced69c0ed0 s390x postgresql-13.23-3.el9_8.s390x.rpm SHA-256: e16e68f564732f458a58b6eb01a99785b529168db0077ba6bd91719093a47c6f postgresql-contrib-13.23-3.el9_8.s390x.rpm SHA-256: dbd9165b7096ddbfa520

Share this article