Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:28037: Important: postgresql:15 security update

This Red Hat security advisory addresses multiple Important-severity vulnerabilities in PostgreSQL 15, including a symlink-following flaw in pg_basebackup and pg_rewind allowing OS account hijack (CVE-2026-6475) and a libpq buffer overflow enabling a server superuser to overwrite client stack memory (CVE-2026-6477), both with a CVSS score of 8.8. Affected versions are PostgreSQL 15.0 through 15.17, and the fixed version is PostgreSQL 15.18.
Read Full Article →

Red Hat Product Errata RHSA-2026:28037 - Security Advisory Issued: 2026-06-22 Updated: 2026-06-22 RHSA-2026:28037 - Security Advisory Overview Updated Packages Synopsis Important: postgresql:15 security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for the postgresql:15 module is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description PostgreSQL is an advanced object-relational database management system (DBMS). Security Fix(es): postgresql: PostgreSQL: Operating system account hijack via symlink following in pg_basebackup and pg_rewind (CVE-2026-6475) postgresql: PostgreSQL libpq: Buffer overflow allows server superuser to overwrite client stack memory (CVE-2026-6477) postgresql: PostgreSQL: Credential recovery via covert timing channel in MD5 password comparison (CVE-2026-6478) postgresql: integer overflow can cause an undersized allocation and an out-of-bounds write (CVE-2026-6473) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 9 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 x86_64 Red Hat Enterprise Linux for IBM z Systems 9 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.8 s390x Red Hat Enterprise Linux for Power, little endian 9 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.8 ppc64le Red Hat Enterprise Linux for ARM 64 9 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.8 aarch64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.8 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.8 x86_64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.8 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.8 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.8 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.8 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.8 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.8 s390x Fixes BZ - 2477439 - CVE-2026-6475 postgresql: PostgreSQL: Operating system account hijack via symlink following in pg_basebackup and pg_rewind BZ - 2477442 - CVE-2026-6477 postgresql: PostgreSQL libpq: Buffer overflow allows server superuser to overwrite client stack memory BZ - 2477447 - CVE-2026-6478 postgresql: PostgreSQL: Credential recovery via covert timing channel in MD5 password comparison BZ - 2477448 - CVE-2026-6473 postgresql: integer overflow can cause an undersized allocation and an out-of-bounds write CVEs CVE-2026-6473 CVE-2026-6475 CVE-2026-6477 CVE-2026-6478 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 9 SRPM pg_repack-1.4.8-2.module+el9.8.0+24091+17775505.src.rpm SHA-256: 24ea55d7dbe454feb16d7819cf0bbe0585f40d6d27fde14e9b437330a9e1e53c pgaudit-1.7.0-1.module+el9.8.0+24091+17775505.src.rpm SHA-256: a58e7c56ab421eb27366cc1457b625fbfc7f3b3be1c364db128816e172757311 postgres-decoderbufs-1.9.7-1.Final.module+el9.8.0+24091+17775505.src.rpm SHA-256: 3147df39b94424fbda8e45182a9798bbef339439be5a73ef24f32c762aab7d95 postgresql-15.18-1.module+el9.8.0+24358+32c5830e.src.rpm SHA-256: 5955f781730fe817b08b7ddc3d2117a7c0a0c95ed2fd2044cbc1ff7d1eba1b28 x86_64 postgresql-test-rpm-macros-15.18-1.module+el9.8.0+24358+32c5830e.noarch.rpm SHA-256: 54f6885ce66f99de424a00a52912344b55f644ec0d4b4a844a69696d18110f13 postgresql-test-rpm-macros-15.18-1.module+el9.8.0+24358+32c5830e.noarch.rpm SHA-256: 54f6885ce66f99de424a00a52912344b55f644ec0d4b4a844a69696d18110f13 pg_repack-1.4.8-2.module+el9.8.0+24091+17775505.x86_64.rpm SHA-256: ec0e39ca2dfa1e8fa06ecd380542bf5fa3fc5731ced4f2ebe002792faafbd124 pg_repack-debuginfo-1.4.8-2.module+el9.8.0+24091+17775505.x86_64.rpm SHA-256: 3c5d39f37e0e5277bfe67a01a7802dbd287e283cb8899b774100d5e92f1496de pg_repack-debugsource-1.4.8-2.module+el9.8.0+24091+17775505.x86_64.rpm SHA-256: 98b27bde04811b8bb036a9db0d02c71c8abaef96b560c447fd59eb2b37ff309a pgaudit-1.7.0-1.module+el9.8.0+24091+17775505.x86_64.rpm SHA-256: 8b3c5d2c8ddf3c0a1334a65740c90b6e6fbbd7c2c7769c5133196698ac846a71 pgaudit-debuginfo-1.7.0-1.module+el9.8.0+24091+17775505.x86_64.rpm SHA-256: 28c733b57cbf1442cc5a8968fa87fcb1bd847fbc405d70e609b91e77a7909ee4 pgaudit-debugsource-1.7.0-1.module+el9.8.0+24091+17775505.x86_64.rpm SHA-256: 1f55ad8f054c29fc3c1f286d18730facf0b7ad8d05a334fa6ba18a930b6a7b06 postgres-decoderbufs-1.9.7-1.Final.module+el9.8.0+24091+17775505.x86_64.rpm SHA-256: 5cc3cc83e3539761f2fdda41154f157ebb95310f3f3206761c6facadfc94773b postgres-decoderbufs-debuginfo-1.9.7-1.Final.module+el9.8.0+24091+17775505.x86_64.rpm SHA-256: 1f22ee2849bc3bfcd496b9095b27f5a327d7262a07d9b2e8202072531b4cfda4 postgres-decoderbufs-debugsource-1.9.7-1.Final.module+el9.8.0+24091+17775505.x86_64.rpm SHA-256: c2aee006fc16980d3022562489621b88fd32a334b4d2136e6f98118cfe4e9d3c postgresql-15.18-1.module+el9.8.0+24358+32c5830e.x86_64.rpm SHA-256: 1f2f8e5526bac45da979c876fbb9a069459ec5a6476d89398433048005fb786b postgresql-contrib-15.18-1.module+el9.8.0+24358+32c5830e.x86_64.rpm SHA-256: 46fca4e63b0d2a3a37c165d06890626e44e6f067993aa033742be2fe3988a5b4 postgresql-contrib-debuginfo-15.18-1.module+el9.8.0+24358+32c5830e.x86_64.rpm SHA-256: 6403ad601f160231596366b89702f37d183a3f3a90dad62aff45ccd6de7fcd4e postgresql-debuginfo-15.18-1.module+el9.8.0+24358+32c5830e.x86_64.rpm SHA-256: b7281c7acb4760ffa5852a49756166cf7f1c6f5442d0bcb645df4e5522a047a2 postgresql-debugsource-15.18-1.module+el9.8.0+24358+32c5830e.x86_64.rpm SHA-256: 2551e004b869b2e0ff73d4c1dfe31d5fa4d18a26d675b88d1f8cd19ca46d15c4 postgresql-docs-15.18-1.module+el9.8.0+24358+32c5830e.x86_64.rpm SHA-256: dbda7ee1b6451e43010adeeae4c1c9126a707e705b534a75cce564e2569679ed postgresql-docs-debuginfo-15.18-1.module+el9.8.0+24358+32c5830e.x86_64.rpm SHA-256: 0808815c87cf4652474db1c032465d9e4ea5c78550c9f1bcb8ad4db011854dde postgresql-plperl-15.18-1.module+el9.8.0+24358+32c5830e.x86_64.rpm SHA-256: 22069369f84ad1f795b6ef7af30e9389ed6676f8e033e343cfb25b9aaebd9314 postgresql-plperl-debuginfo-15.18-1.module+el9.8.0+24358+32c5830e.x86_64.rpm SHA-256: 0d60fd9f6d89bd944d8832bc800a97cb63f3335e58166593049cbb6179b88e55 postgresql-plpython3-15.18-1.module+el9.8.0+24358+32c5830e.x86_64.rpm SHA-256: e6bda23f1b83227b8fafb6893fcf0108d27c0b94fe8793f70bc4e763850915c9 postgresql-plpython3-debuginfo-15.18-1.module+el9.8.0+24358+32c5830e.x86_64.rpm SHA-256: 852434174ad1b72cd138849a24057f2ceb64fa8c1c30ed85c56d5308b1f4807e postgresql-pltcl-15.18-1.module+el9.8.0+24358+32c5830e.x86_64.rpm SHA-256: 83322fd9eb177dbeb74c7e80d172d33e3c871101abebfe4769124c4223d4e9f6 postgresql-pltcl-debuginfo-15.18-1.module+el9.8.0+24358+32c5830e.x86_64.rpm SHA-256: 75e67f86c52cfc3c1a386a97d705e2afab9f1d63314e561fe706972e3f5bec3d postgresql-private-devel-15.18-1.module+el9.8.0+24358+32c5830e.x86_64.rpm SHA-256: b294ced67b960ac9a4c42cdcb9a105e5c60888ac7903155f00a46930c5356f88 postgresql-private-libs-15.18-1.module+el9.8.0+24358+32c5830e.x86_64.rpm SHA-256: a8fca7c9e1d9cf9aa6eb95fd39e90068960190b40cac303f546930cab667ae11 postgresql-private-libs-debuginfo-15.18-1.module+el9.8.0+24358+32c5830e.x86_64.rpm SHA-256: 033e0dd3f4cd5fca1b586ca9c11f4e1aaab687fa274ed24aa035caa8d84aba94 postgresql-server-15.18-1.module+el9.8.0+24358+32c5830e.x86_64.rpm SHA-256: 605acfcc76954a6dd793921a21c43ddbc95eb933df4fb400d8bb4d812c414962 postgresql-server-debuginfo-15.18-1.module+el9.8.0+24358+32c5830e.x86_64.rpm SHA-256: 73119bbe310a3a151183f94eec848f9c1e19ed8545d357b0d34ec0d702a7c71d postgresql-server-devel-15.18-1.module+el9.8.0+24358+32c5830e.x86_64.rpm SHA-256: ed028ad656aab8a5888018f0311291fc12deb476aa8628a4897bd3a972384712 postgresql-server-devel-debuginfo-15.18-1.module+el9.8.0+24358+32c5830e.x86_64.rpm SHA-256: f64c2bf36dd9ca5311c6e9462750150a1f5096969c030241d3637f1461882362 postgresql-static-15.18-1.module+el9.8.0+24358+32c5830e.x86_64.rpm SHA-256: 3b78cd491906ed1fdb05908b8aa33748f6145230053cc2bd42a7eec5facc12b0 postgresql-test-15.18-1.module+el9.8.0+24358+32c5830e.x86_64.rpm SHA-256: 487d77281da184a5c68672951d7db653fb57c093276a52da96c5488d1a23a70e postgresql-test-debuginfo-15.18-1.module+el9.8.0+24358+32c5830e.x86_64.rpm SHA-256: 321f39c794a4a4bf50fda4a4559cb11f027808a9eb866e2bfc5f65de8883a1bf postgresql-test-rpm-macros-15.18-1.module+el9.8.0+24358+32c5830e.noarch.rpm SHA-256: 54f6885ce66f99de424a00a52912344b55f644ec0d4b4a844a69696d18110f13 postgresql-upgrade-15.18-1.module+el9.8.0+24358+32c5830e.x86_64.rpm SHA-256: 621dd25da6e38a4af21bc014b017b3f7da2c8500d694be9b1e3c5035d8de102a postgresql-upgrade-debuginfo-15.18-1.module+el9.8.0+24358+32c5830e.x86_64.rpm SHA-256: 46ee25b2b8ea5ffc6c74b8da4284a65d4e5b0ba930f790c6757aeb0a9b7610ed postgresql-upgrade-devel-15.18-1.module+el9.8.0+24358+32c5830e.x86_64.rpm SHA-256: b4618512de3c4ad09340048a949817a88cb0ab7067ddc4ce00d42429d0d67b74 postgresql-upgrade-devel-debuginfo-15.18-1.module+el9.8.0+24358+32c5830e.x86_64.rpm SHA-256: a4eeb4aaa12a2238256af4871d131b6ea8a65b733dc74b3d5cefa6a92906e520 postgresql-test-rpm-macros-15.18-1.module+el9.8.0+24358+32c5830e.noarch.rpm SHA-256: 54f6885ce66f99de424a00a52912344b55f644ec0d4

Share this article