Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:34043: Important: postgresql:12 security update

This security update addresses multiple vulnerabilities in PostgreSQL 12, including a high-severity symlink-following flaw in pg_basebackup and pg_rewind allowing OS account hijack (CVE-2026-6475, CVSS 8.8), a high-severity buffer overflow in libpq enabling a server superuser to overwrite client stack memory (CVE-2026-6477, CVSS 8.8), and a medium-severity timing channel for MD5 password credential recovery (CVE-2026-6478, CVSS 6.5). According to NVD data, PostgreSQL versions prior to 14.23, 15.18, 16.14, 17.10, and 18.4 are affected. The advisory provides a Red Hat-specific patch for PostgreSQL 12 on specific RHEL 8.8 update services; users of other distributions or major versions must upgrade to the fixed versions listed.
Read Full Article →

Red Hat Product Errata RHSA-2026:34043 - Security Advisory Issued: 2026-07-01 Updated: 2026-07-01 RHSA-2026:34043 - Security Advisory Overview Updated Packages Synopsis Important: postgresql:12 security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for the postgresql:12 module is now available for Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions and Red Hat Enterprise Linux 8.8 Telecommunications Update Service. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description PostgreSQL is an advanced object-relational database management system (DBMS). Security Fix(es): postgresql: PostgreSQL: Operating system account hijack via symlink following in pg_basebackup and pg_rewind (CVE-2026-6475) postgresql: PostgreSQL libpq: Buffer overflow allows server superuser to overwrite client stack memory (CVE-2026-6477) postgresql: PostgreSQL: Credential recovery via covert timing channel in MD5 password comparison (CVE-2026-6478) postgresql: integer overflow can cause an undersized allocation and an out-of-bounds write (CVE-2026-6473) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.8 x86_64 Red Hat Enterprise Linux Server - TUS 8.8 x86_64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.8 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.8 x86_64 Fixes BZ - 2477439 - CVE-2026-6475 postgresql: PostgreSQL: Operating system account hijack via symlink following in pg_basebackup and pg_rewind BZ - 2477442 - CVE-2026-6477 postgresql: PostgreSQL libpq: Buffer overflow allows server superuser to overwrite client stack memory BZ - 2477447 - CVE-2026-6478 postgresql: PostgreSQL: Credential recovery via covert timing channel in MD5 password comparison BZ - 2477448 - CVE-2026-6473 postgresql: integer overflow can cause an undersized allocation and an out-of-bounds write CVEs CVE-2026-6473 CVE-2026-6475 CVE-2026-6477 CVE-2026-6478 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.8 SRPM pg_repack-1.4.6-3.module+el8.5.0+11354+78b3c9c5.src.rpm SHA-256: 82c8ea0e72ae72fc696a5bffd3ff569476d7210a9506ad99c98c48c163a37843 pgaudit-1.4.0-5.module+el8.5.0+11354+78b3c9c5.src.rpm SHA-256: 45156076f19a7507973697923e14147b1285d7bb00615978a347aa878e384aae postgres-decoderbufs-0.10.0-2.module+el8.5.0+11354+78b3c9c5.src.rpm SHA-256: b521220b59d18b13b7a35c744b144c952ebde08f2553747cecc0e86b8737eaea postgresql-12.22-1.module+el8.8.0+24458+21f81c54.4.src.rpm SHA-256: 1deb3a11db57c70bc0ff86c3ac13e8dd69059f891fd5a72e41a44a25fb7ba646 x86_64 pg_repack-1.4.6-3.module+el8.5.0+11354+78b3c9c5.x86_64.rpm SHA-256: cb60723f9b6e3601abcb4c474a4878f8582b1edde031af7e721df820da5b62dd pg_repack-debuginfo-1.4.6-3.module+el8.5.0+11354+78b3c9c5.x86_64.rpm SHA-256: c8caad1c9ba892a7e2de313f3b1738cb6fefaf427fc5d483a8521b97e8e1a02c pg_repack-debugsource-1.4.6-3.module+el8.5.0+11354+78b3c9c5.x86_64.rpm SHA-256: a8741b343a45194fe30396317552c1aa3776fa9a9d73beee505db60c7996370e pgaudit-1.4.0-5.module+el8.5.0+11354+78b3c9c5.x86_64.rpm SHA-256: e56e99127598dbabd012dd019b7a4c33a738add836a0aa5f4b489cc8513d10b4 pgaudit-debuginfo-1.4.0-5.module+el8.5.0+11354+78b3c9c5.x86_64.rpm SHA-256: ba48771ef15f6946785b8f016e420cc502344a0248262fb55034b3d011fec2a6 pgaudit-debugsource-1.4.0-5.module+el8.5.0+11354+78b3c9c5.x86_64.rpm SHA-256: 256f06fce473bd9eadcb7465a0e6bdf551c92c49778ac6ec91847eb1932db840 postgres-decoderbufs-0.10.0-2.module+el8.5.0+11354+78b3c9c5.x86_64.rpm SHA-256: 2eb5e674808b184a01f53b8bf84b334bf210b1affaad6dda7c599eb42065922c postgres-decoderbufs-debuginfo-0.10.0-2.module+el8.5.0+11354+78b3c9c5.x86_64.rpm SHA-256: 53bcf8ca8e4d43b7185391409dd87f5604a437d9b15a25f4113927545e8e1450 postgres-decoderbufs-debugsource-0.10.0-2.module+el8.5.0+11354+78b3c9c5.x86_64.rpm SHA-256: 9610cb4d1cd18812a51b238a38e1260e8b86243b4cb4536da621195e148313ef postgresql-12.22-1.module+el8.8.0+24458+21f81c54.4.x86_64.rpm SHA-256: 99d747c28f08282ddc54be7bf2bbd873f95b0748318aab77ebf0a31e70f26156 postgresql-contrib-12.22-1.module+el8.8.0+24458+21f81c54.4.x86_64.rpm SHA-256: f34a20925d98ed454edadf44945b9d00cfefb2ffd517bc40e0ca8042af625043 postgresql-contrib-debuginfo-12.22-1.module+el8.8.0+24458+21f81c54.4.x86_64.rpm SHA-256: b4c47479d4a255e2a6be8454cae2c3ffadf5fb01a9a0bd19fdd80b3aa3ebbddb postgresql-debuginfo-12.22-1.module+el8.8.0+24458+21f81c54.4.x86_64.rpm SHA-256: 4196167eefb55943498ae8106040ce88f56e70c22fc8d4d56bafc9ed7ce1ace0 postgresql-debugsource-12.22-1.module+el8.8.0+24458+21f81c54.4.x86_64.rpm SHA-256: b68c5bf7ce7286dfd72d496f734b6e9100e36ec989c08cab386a43a90144940a postgresql-docs-12.22-1.module+el8.8.0+24458+21f81c54.4.x86_64.rpm SHA-256: 70c35d97c64581f590ed7e3459982acf2149c30f50aac04b30ac9a9353b7e0e7 postgresql-docs-debuginfo-12.22-1.module+el8.8.0+24458+21f81c54.4.x86_64.rpm SHA-256: 16f29add3250531a63d09c707ba4662e366b31d776cfff1d5201d98455bbdcd1 postgresql-plperl-12.22-1.module+el8.8.0+24458+21f81c54.4.x86_64.rpm SHA-256: 2457b1e62d95bac6ca93225d621284660a877aa82553e0b66ae5b8c5f9133742 postgresql-plperl-debuginfo-12.22-1.module+el8.8.0+24458+21f81c54.4.x86_64.rpm SHA-256: c9d2bc38558f1e762a617fc33431c4c188447ba873301f487692fcdbb65fca68 postgresql-plpython3-12.22-1.module+el8.8.0+24458+21f81c54.4.x86_64.rpm SHA-256: bbe9f9de51cd5a84d360b3f35eb94aa47f9c1f2e8a0a19f0348ca97321adf6a2 postgresql-plpython3-debuginfo-12.22-1.module+el8.8.0+24458+21f81c54.4.x86_64.rpm SHA-256: 4dc18936f96045e7a3933d28f9bb559931598f43855cadec9f19e34745284ebd postgresql-pltcl-12.22-1.module+el8.8.0+24458+21f81c54.4.x86_64.rpm SHA-256: 3d39cb8440f0d596e9704debeee010ea3c6407ec2229a1c948daa2eda2ece960 postgresql-pltcl-debuginfo-12.22-1.module+el8.8.0+24458+21f81c54.4.x86_64.rpm SHA-256: 4c9635b26bb62138da9a83238f03513ef857c1db758e1645be797515ce5a33dd postgresql-server-12.22-1.module+el8.8.0+24458+21f81c54.4.x86_64.rpm SHA-256: 116e2ac7639712fd83642fc37d6b5ca6c833360133059e3553347e8cd7b0ae07 postgresql-server-debuginfo-12.22-1.module+el8.8.0+24458+21f81c54.4.x86_64.rpm SHA-256: e1a6c8801785bd463182ffd1ba1686833ea7584badb78b1d39d815a2ff40d924 postgresql-server-devel-12.22-1.module+el8.8.0+24458+21f81c54.4.x86_64.rpm SHA-256: f25e7aaac324ff46391563b16a6c25ea5bb7ecfc058366cf1aa9103ef117a714 postgresql-server-devel-debuginfo-12.22-1.module+el8.8.0+24458+21f81c54.4.x86_64.rpm SHA-256: a8778f7b468e20e0917f42084cdf5c375907a42acdd40cf0d9fb7120cd282d25 postgresql-static-12.22-1.module+el8.8.0+24458+21f81c54.4.x86_64.rpm SHA-256: dd5aaa0d76e9f0c249951ee45c5ef1d89c75c3b76f8d947ffc05f0dff4ce9cba postgresql-test-12.22-1.module+el8.8.0+24458+21f81c54.4.x86_64.rpm SHA-256: a8c36626b1bebbdd3c95d537cd28de609168872b73a053a41df533e7f28ce1b3 postgresql-test-debuginfo-12.22-1.module+el8.8.0+24458+21f81c54.4.x86_64.rpm SHA-256: a66e9de26a45e9a53a932c986599f4acf7bbce8fcd5e8177a3cba6899e0480ad postgresql-test-rpm-macros-12.22-1.module+el8.8.0+24458+21f81c54.4.noarch.rpm SHA-256: 3cab442dc6d204c8b5ebfce360180c22fcb0f8fedfc2d4040babbd97726628d6 postgresql-upgrade-12.22-1.module+el8.8.0+24458+21f81c54.4.x86_64.rpm SHA-256: b4edabb7cf1ebb31f1c5fcf31af0e1348643648ec90c5bdfd06d8a29cb96b910 postgresql-upgrade-debuginfo-12.22-1.module+el8.8.0+24458+21f81c54.4.x86_64.rpm SHA-256: 5ba52e2f0c44e774f67b748e443b9f9d87657de7f675d299beef6d275a934c50 postgresql-upgrade-devel-12.22-1.module+el8.8.0+24458+21f81c54.4.x86_64.rpm SHA-256: 6b4ca071db30333ce8f36c54568840c3d119edb5b55902631a4fe9614edea20e postgresql-upgrade-devel-debuginfo-12.22-1.module+el8.8.0+24458+21f81c54.4.x86_64.rpm SHA-256: b0eea186401e02ddcd24874cc38cbac52034f73d5761019e5d77fe80ed6e066c postgresql-test-rpm-macros-12.22-1.module+el8.8.0+24458+21f81c54.4.noarch.rpm SHA-256: 3cab442dc6d204c8b5ebfce360180c22fcb0f8fedfc2d4040babbd97726628d6 Red Hat Enterprise Linux Server - TUS 8.8 SRPM pg_repack-1.4.6-3.module+el8.5.0+11354+78b3c9c5.src.rpm SHA-256: 82c8ea0e72ae72fc696a5bffd3ff569476d7210a9506ad99c98c48c163a37843 pgaudit-1.4.0-5.module+el8.5.0+11354+78b3c9c5.src.rpm SHA-256: 45156076f19a7507973697923e14147b1285d7bb00615978a347aa878e384aae postgres-decoderbufs-0.10.0-2.module+el8.5.0+11354+78b3c9c5.src.rpm SHA-256: b521220b59d18b13b7a35c744b144c952ebde08f2553747cecc0e86b8737eaea postgresql-12.22-1.module+el8.8.0+24458+21f81c54.4.src.rpm SHA-256: 1deb3a11db57c70bc0ff86c3ac13e8dd69059f891fd5a72e41a44a25fb7ba646 x86_64 pg_repack-1.4.6-3.module+el8.5.0+11354+78b3c9c5.x86_64.rpm SHA-256: cb60723f9b6e3601abcb4c474a4878f8582b1edde031af7e721df820da5b62dd pg_repack-debuginfo-1.4.6-3.module+el8.5.0+11354+78b3c9c5.x86_64.rpm SHA-256: c8caad1c9ba892a7e2de313f3b1738cb6fefaf427fc5d483a8521b97e8e1a02c pg_repack-debugsource-1.4.6-3.module+el8.5.0+11354+78b3c9c5.x86_64.rpm SHA-256: a8741b343a45194fe30396317552c1aa3776fa9a9d73beee505db60c7996370e pgaudit-1.4.0-5.module+el8.5.0+11354+78b3c9c5.x86_64.rpm SHA-256: e56e99127598dbabd012dd019b7a4c33a738add836a0aa5f4b489cc8513d10b4 pgaudit-debuginfo-1.4.0-5.module+el8.5.0+11354+78b3c9c5.x86_64.rpm SHA-256: ba48771ef15f6946785b8f016e420cc502344a0248262fb55034b3d011fec2a6 pgaudit-debugsource-1.4.0-5.module+el8.5.0+11354+78b3c9c5.x86_64.rpm SHA-256: 256f06fce473bd9eadcb74

Share this article