Security News

Cybersecurity news aggregator

🔄
INFO Updates Red Hat Errata

RHSA-2026:44420: Important: libpq security update

  • What: Security update for libpq
  • Impact: Red Hat Enterprise Linux 8.4 systems
Read Full Article →

Red Hat Product Errata RHSA-2026:44420 - Security Advisory Issued: 2026-07-23 Updated: 2026-07-23 RHSA-2026:44420 - Security Advisory Overview Updated Packages Synopsis Important: libpq security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for libpq is now available for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support and Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The libpq package provides the PostgreSQL client library, which allows client programs to connect to PostgreSQL servers. Security Fix(es): postgresql: PostgreSQL: Operating system account hijack via symlink following in pg_basebackup and pg_rewind (CVE-2026-6475) postgresql: PostgreSQL libpq: Buffer overflow allows server superuser to overwrite client stack memory (CVE-2026-6477) postgresql: PostgreSQL: Credential recovery via covert timing channel in MD5 password comparison (CVE-2026-6478) postgresql: integer overflow can cause an undersized allocation and an out-of-bounds write (CVE-2026-6473) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life 8.4 x86_64 Red Hat Enterprise Linux Server - AUS 8.4 x86_64 Fixes BZ - 2477439 - CVE-2026-6475 postgresql: PostgreSQL: Operating system account hijack via symlink following in pg_basebackup and pg_rewind BZ - 2477442 - CVE-2026-6477 postgresql: PostgreSQL libpq: Buffer overflow allows server superuser to overwrite client stack memory BZ - 2477447 - CVE-2026-6478 postgresql: PostgreSQL: Credential recovery via covert timing channel in MD5 password comparison BZ - 2477448 - CVE-2026-6473 postgresql: integer overflow can cause an undersized allocation and an out-of-bounds write CVEs CVE-2026-6473 CVE-2026-6475 CVE-2026-6477 CVE-2026-6478 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life 8.4 SRPM libpq-13.23-1.el8_4.1.src.rpm SHA-256: fa0f1251c20d879acad4d7920265d1efc04f27f8289a68511391883dc50ea5e4 x86_64 libpq-13.23-1.el8_4.1.i686.rpm SHA-256: f86695179ef0cd9078205a9fccbdc6aea5866d1acacef390a41cc0b5dfa8dd24 libpq-13.23-1.el8_4.1.x86_64.rpm SHA-256: ef02b84a791d14cf5554755d92ea14a0ab31c14cb9bdd1dbbc6702a7b3fe740e libpq-debuginfo-13.23-1.el8_4.1.i686.rpm SHA-256: 91528877c4543eb8414d6ff47c8326c984b25878d7f1cc2d2cf47f406105c55d libpq-debuginfo-13.23-1.el8_4.1.x86_64.rpm SHA-256: 5786127599bbca11e6eab975df22d0f67d60e6df1fa53c3da756cca45ac6dd2a libpq-debugsource-13.23-1.el8_4.1.i686.rpm SHA-256: 3a7078de211eda70ebe107f78685b6e238728c5dd1ae4647a4d7325fa27910e0 libpq-debugsource-13.23-1.el8_4.1.x86_64.rpm SHA-256: a617ac341eb1e8eff478220b22a119d915cd905478f2318e00928fb7031868a5 libpq-devel-13.23-1.el8_4.1.i686.rpm SHA-256: 59c77aa3a6ce9dde28f769a9098e9ff54d0f8283023febec2f54d4976c408970 libpq-devel-13.23-1.el8_4.1.x86_64.rpm SHA-256: 4e7beb78da747f571b574a391ab69e4c4144a16a644c16383612f20c06fc3556 libpq-devel-debuginfo-13.23-1.el8_4.1.i686.rpm SHA-256: 94b28e6c9020f551404bfdaffe9923ac391ab8b8342b9ee9f21ce3da6beb2ef5 libpq-devel-debuginfo-13.23-1.el8_4.1.x86_64.rpm SHA-256: 4a9da16ba1f4fedbc57306026efcd937bcd6419111569f6117d0577ecf68b996 Red Hat Enterprise Linux Server - AUS 8.4 SRPM libpq-13.23-1.el8_4.1.src.rpm SHA-256: fa0f1251c20d879acad4d7920265d1efc04f27f8289a68511391883dc50ea5e4 x86_64 libpq-13.23-1.el8_4.1.i686.rpm SHA-256: f86695179ef0cd9078205a9fccbdc6aea5866d1acacef390a41cc0b5dfa8dd24 libpq-13.23-1.el8_4.1.x86_64.rpm SHA-256: ef02b84a791d14cf5554755d92ea14a0ab31c14cb9bdd1dbbc6702a7b3fe740e libpq-debuginfo-13.23-1.el8_4.1.i686.rpm SHA-256: 91528877c4543eb8414d6ff47c8326c984b25878d7f1cc2d2cf47f406105c55d libpq-debuginfo-13.23-1.el8_4.1.x86_64.rpm SHA-256: 5786127599bbca11e6eab975df22d0f67d60e6df1fa53c3da756cca45ac6dd2a libpq-debugsource-13.23-1.el8_4.1.i686.rpm SHA-256: 3a7078de211eda70ebe107f78685b6e238728c5dd1ae4647a4d7325fa27910e0 libpq-debugsource-13.23-1.el8_4.1.x86_64.rpm SHA-256: a617ac341eb1e8eff478220b22a119d915cd905478f2318e00928fb7031868a5 libpq-devel-13.23-1.el8_4.1.i686.rpm SHA-256: 59c77aa3a6ce9dde28f769a9098e9ff54d0f8283023febec2f54d4976c408970 libpq-devel-13.23-1.el8_4.1.x86_64.rpm SHA-256: 4e7beb78da747f571b574a391ab69e4c4144a16a644c16383612f20c06fc3556 libpq-devel-debuginfo-13.23-1.el8_4.1.i686.rpm SHA-256: 94b28e6c9020f551404bfdaffe9923ac391ab8b8342b9ee9f21ce3da6beb2ef5 libpq-devel-debuginfo-13.23-1.el8_4.1.x86_64.rpm SHA-256: 4a9da16ba1f4fedbc57306026efcd937bcd6419111569f6117d0577ecf68b996 The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .

Share this article