Red Hat Product Errata RHSA-2026:52396 - Security Advisory Issued: 2026-08-10 Updated: 2026-08-10 RHSA-2026:52396 - Security Advisory Overview Updated Packages Synopsis Important: postgresql:12 security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for the postgresql:12 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description PostgreSQL is an advanced object-relational database management system (DBMS). Security Fix(es): postgresql: PostgreSQL: Denial of Service via uncontrolled recursion in SSL/GSS negotiation (CVE-2026-6479) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 8 x86_64 Red Hat Enterprise Linux for IBM z Systems 8 s390x Red Hat Enterprise Linux for Power, little endian 8 ppc64le Red Hat Enterprise Linux for ARM 64 8 aarch64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 8.10 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 8.10 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 8.10 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 8.10 s390x Fixes BZ - 2477445 - CVE-2026-6479 postgresql: PostgreSQL: Denial of Service via uncontrolled recursion in SSL/GSS negotiation CVEs CVE-2026-6479 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 8 SRPM pg_repack-1.4.6-3.module+el8.9.0+19330+c97ddbdf.src.rpm SHA-256: 1cbc962593d701f09b2c8a8dfb1e206e852043e0a96766317eafd546e15a806a pgaudit-1.4.0-7.module+el8.10.0+22214+9beb89d6.src.rpm SHA-256: bd2a5a516de8e8a06636108da6c102147b118b7247c809e1966f36f24f79710a postgres-decoderbufs-0.10.0-2.module+el8.9.0+19330+c97ddbdf.src.rpm SHA-256: b79ff680d5741bb168bacd301cdc8c6ff7f05253d002b14e6c924ef8784e7368 postgresql-12.22-9.module+el8.10.0+24635+941a3cac.src.rpm SHA-256: c921ddf3929f5f9c6ea2024c966c600a94adbb7e2ad992ea5fdc1280ef4a1c71 x86_64 postgresql-test-rpm-macros-12.22-9.module+el8.10.0+24635+941a3cac.noarch.rpm SHA-256: 897aa1baf95ffb8b911794e18a9b9381864301eb19cdc7a5c608e1ad7e2b5db9 postgresql-test-rpm-macros-12.22-9.module+el8.10.0+24635+941a3cac.noarch.rpm SHA-256: 897aa1baf95ffb8b911794e18a9b9381864301eb19cdc7a5c608e1ad7e2b5db9 pg_repack-1.4.6-3.module+el8.9.0+19330+c97ddbdf.x86_64.rpm SHA-256: be75ac51e2a37841a624ffbeee588c0235593ab7fa9797e2f7512542325b5030 pg_repack-debuginfo-1.4.6-3.module+el8.9.0+19330+c97ddbdf.x86_64.rpm SHA-256: be696c570b6e018728f0162d8aac7363c0f9071e56fb056ee58293781d84a45d pg_repack-debugsource-1.4.6-3.module+el8.9.0+19330+c97ddbdf.x86_64.rpm SHA-256: 93946f79436baa572dc89205a544236c72727cea49e308ca33689209e989115e pgaudit-1.4.0-7.module+el8.10.0+22214+9beb89d6.x86_64.rpm SHA-256: fa761e10d90afd8bbce7f09e6be78c586fde6de1b92a04d0dec2ef17a8e5fd63 pgaudit-debuginfo-1.4.0-7.module+el8.10.0+22214+9beb89d6.x86_64.rpm SHA-256: 7263c07acefd3424053b57c6f738891baa375b0d587d7e73ed161cc6ebc30e83 pgaudit-debugsource-1.4.0-7.module+el8.10.0+22214+9beb89d6.x86_64.rpm SHA-256: 64883a18f87d9b53c56d82f5c04ecb7822b3fd0b4e2d36abe6869b2d0c3039b8 postgres-decoderbufs-0.10.0-2.module+el8.9.0+19330+c97ddbdf.x86_64.rpm SHA-256: addef98efff06393dcd4fa16f30d28a05f9ab0dae8c3eedf4380308b614ef5ea postgres-decoderbufs-debuginfo-0.10.0-2.module+el8.9.0+19330+c97ddbdf.x86_64.rpm SHA-256: 7899e2282c4506feeb12fd6df50363969973de57bcdddc2609e33f0b8b270559 postgres-decoderbufs-debugsource-0.10.0-2.module+el8.9.0+19330+c97ddbdf.x86_64.rpm SHA-256: 82b297e53b774bb4081f14e69b04e60cb5925a37478636a9fbbb2bc4f7e4866c postgresql-12.22-9.module+el8.10.0+24635+941a3cac.x86_64.rpm SHA-256: afaacd0bafac5f64fd0ca3df3320fe171a208106889e98d7721ceb9d55653b79 postgresql-contrib-12.22-9.module+el8.10.0+24635+941a3cac.x86_64.rpm SHA-256: 49b1798e12508177eb007d59c31dee8b27ff9117fca4050e56aa7eb253de1f13 postgresql-contrib-debuginfo-12.22-9.module+el8.10.0+24635+941a3cac.x86_64.rpm SHA-256: 1f732c02272b07f5878e0165eee6cb46ffe60f3177f1ae0092b2cc8653b7baea postgresql-debuginfo-12.22-9.module+el8.10.0+24635+941a3cac.x86_64.rpm SHA-256: 14e47bbca3c0e32f7c3e85a59bf1fa1c67f48f465ca9d62dc4ae457a8a005f27 postgresql-debugsource-12.22-9.module+el8.10.0+24635+941a3cac.x86_64.rpm SHA-256: 5c8bebb14d6bb1dc4674bae8ae896b35ee2114bc2b756e4e234e137f54071f5b postgresql-docs-12.22-9.module+el8.10.0+24635+941a3cac.x86_64.rpm SHA-256: c48357cb35b01d29d452b4a4ca88a459891dca5c609e9e029f59215a54b47c69 postgresql-docs-debuginfo-12.22-9.module+el8.10.0+24635+941a3cac.x86_64.rpm SHA-256: c27a5c3fe2ae39d3399b29a9fff202dda7ded39cc27ab220c6b601806fa3ae98 postgresql-plperl-12.22-9.module+el8.10.0+24635+941a3cac.x86_64.rpm SHA-256: d7c32c3ca9bf4e17bfed2f4e11637984806776e80c76d5da9ecf3244f2a966ab postgresql-plperl-debuginfo-12.22-9.module+el8.10.0+24635+941a3cac.x86_64.rpm SHA-256: 01b661138ae4cc61a35ac45f3a01bbec05a04dbd747d4d02d66a9e37dd017590 postgresql-plpython3-12.22-9.module+el8.10.0+24635+941a3cac.x86_64.rpm SHA-256: 432f317a3771ad8a237dccf7f9ba95c6d1fd8daeb9b8818599cfce77da555c76 postgresql-plpython3-debuginfo-12.22-9.module+el8.10.0+24635+941a3cac.x86_64.rpm SHA-256: 1df53694e8c700ed6cdd4318100c37441441cd3eec137b035d2434748c00627b postgresql-pltcl-12.22-9.module+el8.10.0+24635+941a3cac.x86_64.rpm SHA-256: 663f544efa255aa7ec36e084e33c12cd60bc2abb89793d76e3d2d0b63a045883 postgresql-pltcl-debuginfo-12.22-9.module+el8.10.0+24635+941a3cac.x86_64.rpm SHA-256: 5b4008ff5f2b70daba02b71579654fef406a7faf67a6104687672b95744fcb58 postgresql-server-12.22-9.module+el8.10.0+24635+941a3cac.x86_64.rpm SHA-256: 9391e8bd0776699be7bde7d16f82631f67c41f92f638c433f9440946cb865d4d postgresql-server-debuginfo-12.22-9.module+el8.10.0+24635+941a3cac.x86_64.rpm SHA-256: 43ddbca4aff2d0e85d46f4aa50f6d2d919860d488fa198f3bb589f1fed31ebfb postgresql-server-devel-12.22-9.module+el8.10.0+24635+941a3cac.x86_64.rpm SHA-256: 871ce6940657ef5d3b0f0e7641a8bfe082f1689a1c0b29e37cde0f8273756469 postgresql-server-devel-debuginfo-12.22-9.module+el8.10.0+24635+941a3cac.x86_64.rpm SHA-256: 0d0cbb8af8e57ffef350daf03f045fe630a4b83b0ca5c2117af8701e933b060d postgresql-static-12.22-9.module+el8.10.0+24635+941a3cac.x86_64.rpm SHA-256: 89ff7c0a0aaa56dcfa8b5b58457467553798789bdfafbd86d03c5efe82dad15a postgresql-test-12.22-9.module+el8.10.0+24635+941a3cac.x86_64.rpm SHA-256: 8664a0e1155fa43f1a08cb42dbc6bbdd7de9f357fbd8d6c23478def256b97bb5 postgresql-test-debuginfo-12.22-9.module+el8.10.0+24635+941a3cac.x86_64.rpm SHA-256: 31a3ab9c47c6dfa582f96d7daa5e201ae6dd9bc8dd30fd03696635718e45c7d9 postgresql-test-rpm-macros-12.22-9.module+el8.10.0+24635+941a3cac.noarch.rpm SHA-256: 897aa1baf95ffb8b911794e18a9b9381864301eb19cdc7a5c608e1ad7e2b5db9 postgresql-upgrade-12.22-9.module+el8.10.0+24635+941a3cac.x86_64.rpm SHA-256: a47cfc81f5bdcd80b96574e49e2d8d8fe3c89f9b3831b3904dbca2ce9b40bbc3 postgresql-upgrade-debuginfo-12.22-9.module+el8.10.0+24635+941a3cac.x86_64.rpm SHA-256: fae5fc785523fff9f1fe5176810a3492a056a79271f8af72914d67dac23c9467 postgresql-upgrade-devel-12.22-9.module+el8.10.0+24635+941a3cac.x86_64.rpm SHA-256: 9149edc1c6d4c4f2886e0ed9fa2cd1c01b062508e94a219b09016f913ed1304a postgresql-upgrade-devel-debuginfo-12.22-9.module+el8.10.0+24635+941a3cac.x86_64.rpm SHA-256: 17e217ef9bfa73db0fcf0c35448b5a1032f3f0152fa55b7a036a046a80eddfc3 postgresql-test-rpm-macros-12.22-9.module+el8.10.0+24635+941a3cac.noarch.rpm SHA-256: 897aa1baf95ffb8b911794e18a9b9381864301eb19cdc7a5c608e1ad7e2b5db9 Red Hat Enterprise Linux for IBM z Systems 8 SRPM pg_repack-1.4.6-3.module+el8.9.0+19330+c97ddbdf.src.rpm SHA-256: 1cbc962593d701f09b2c8a8dfb1e206e852043e0a96766317eafd546e15a806a pgaudit-1.4.0-7.module+el8.10.0+22214+9beb89d6.src.rpm SHA-256: bd2a5a516de8e8a06636108da6c102147b118b7247c809e1966f36f24f79710a postgres-decoderbufs-0.10.0-2.module+el8.9.0+19330+c97ddbdf.src.rpm SHA-256: b79ff680d5741bb168bacd301cdc8c6ff7f05253d002b14e6c924ef8784e7368 postgresql-12.22-9.module+el8.10.0+24635+941a3cac.src.rpm SHA-256: c921ddf3929f5f9c6ea2024c966c600a94adbb7e2ad992ea5fdc1280ef4a1c71 s390x postgresql-test-rpm-macros-12.22-9.module+el8.10.0+24635+941a3cac.noarch.rpm SHA-256: 897aa1baf95ffb8b911794e18a9b9381864301eb19cdc7a5c608e1ad7e2b5db9 postgresql-test-rpm-macros-12.22-9.module+el8.10.0+24635+941a3cac.noarch.rpm SHA-256: 897aa1baf95ffb8b911794e18a9b9381864301eb19cdc7a5c608e1ad7e2b5db9 postgresql-test-rpm-macros-12.22-9.module+el8.10.0+24635+941a3cac.noarch.rpm SHA-256: 897aa1baf95ffb8b911794e18a9b9381864301eb19cdc7a5c608e1ad7e2b5db9 pg_repack-1.4.6-3.module+el8.9.0+19330+c97ddbdf.s390x.rpm SHA-256: ac0c3fff4f5d56fbf309523a1f8ed176444de1c911d847a53877d3880eb49048 pg_repack-debuginfo-1.4.6-3.module+el8.9.0+19330+c97ddbdf.s390x.rpm SHA-256: 96604cee626a584332e771f53bff85b344b64ae67636f1c12f0a460629c3935c pg_repack-debugsource-1.4.6-3.module+el8.9.0+19330+c97ddbdf.s390x.rpm SHA-256: 727a472219bf9273309e55156921118cb5a9d969d23d9e0dd50e3cfaf6ea56e4 pgaudit-1.4.0-7.module+el8.10.0+22214+9beb89d6.s390x.rpm SHA-256: 2a9bde7038775164fedfad9c59a4368b595c03edbe8a54d733da8831f7d3ee62 pgaudit-debuginfo-1.4.0-7.module+el8.10.0+22214+9beb89d6.s390x.rpm SHA-256: 0c596ef208a4533cbe67f9dcd00ee7d8369a7d5000d33dca0baa3c220bb85064 pgaudit-debugsource-1.4.0-7.module+el8.10.0+22214+9beb89d6.s390x.rpm SHA-256: 63cc1b4b9a7fda18599a7f0fd699d
A critical denial-of-service vulnerability (CVE-2026-6479, CVSS 7.5 High) in PostgreSQL allows attackers to crash the database server via uncontrolled recursion during SSL/GSS negotiation. Affected versions include PostgreSQL 14.x before 14.23, 15.x before 15.18, 16.x before 16.14, 17.x before 17.10, and 18.x before 18.4. The fix requires upgrading to the respective patched versions listed.