Red Hat Product Errata RHSA-2026:57633 - Security Advisory Issued: 2026-08-20 Updated: 2026-08-20 RHSA-2026:57633 - Security Advisory Overview Updated Packages Synopsis Important: postgresql security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for postgresql is now available for Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description PostgreSQL is an advanced object-relational database management system (DBMS). Security Fix(es): postgresql: PostgreSQL: Denial of Service via uncontrolled recursion in SSL/GSS negotiation (CVE-2026-6479) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux Server - AUS 9.2 x86_64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2 x86_64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.2 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.2 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.2 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.2 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.2 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.2 s390x Fixes BZ - 2477445 - CVE-2026-6479 postgresql: PostgreSQL: Denial of Service via uncontrolled recursion in SSL/GSS negotiation CVEs CVE-2026-6479 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux Server - AUS 9.2 SRPM postgresql-13.23-1.el9_2.4.src.rpm SHA-256: e47043011d4ebed6222b37d02772551bc941933188806e43baa7e168b5e9b074 x86_64 postgresql-13.23-1.el9_2.4.x86_64.rpm SHA-256: 3378d658c84469abac21ef3bc81ac244c23de40c92973a2d0f16d53f94deb35c postgresql-contrib-13.23-1.el9_2.4.x86_64.rpm SHA-256: 1c01f9e70b175c56434ea6131592b9e446e999cb255178baa376d8c30364ba9d postgresql-contrib-debuginfo-13.23-1.el9_2.4.x86_64.rpm SHA-256: 07e0029dcf7a4180d72d3f1adb889cc0329aaeafdb22dd01e2e8979dec3d3a14 postgresql-debuginfo-13.23-1.el9_2.4.x86_64.rpm SHA-256: 28b1f88c62a09e33ded65698325159527ecb729c4fabfae9b4663d85e18ffcf4 postgresql-debugsource-13.23-1.el9_2.4.x86_64.rpm SHA-256: 97d417e34578f3cfe8735e84c842eef7bf621682320217edecfdf6581e33e97f postgresql-docs-debuginfo-13.23-1.el9_2.4.x86_64.rpm SHA-256: 408ffb33586287ea572b48587f55bef77f8bd48055ec2ddc43f44f72ef0953ba postgresql-plperl-13.23-1.el9_2.4.x86_64.rpm SHA-256: 0cc202c50df84bd3db9ca3934958df1019e17b655178d4e1519ea18806e0f7e0 postgresql-plperl-debuginfo-13.23-1.el9_2.4.x86_64.rpm SHA-256: b3b03addacbc4a5ee640178d6eddff16ef2f7198d9d748b930444ca4a19a6ec9 postgresql-plpython3-13.23-1.el9_2.4.x86_64.rpm SHA-256: 0560df6ec27e82b4789a22f0555c521e75c2ea7d57aaf052de0e9fbc8dfa9c7a postgresql-plpython3-debuginfo-13.23-1.el9_2.4.x86_64.rpm SHA-256: afe7223c1395ee6e576844f6b07029a8ac4873f14b06f373c0e6bebe0a9a32e5 postgresql-pltcl-13.23-1.el9_2.4.x86_64.rpm SHA-256: 7a25de56fd52d435d89a76e5f89e36aebe56725278a2ee11ac454724d2663d21 postgresql-pltcl-debuginfo-13.23-1.el9_2.4.x86_64.rpm SHA-256: 50fd655edb64d9350eed4042d3823ad47023dc0d0d4b0ed4ed1dfad8850c1770 postgresql-private-libs-13.23-1.el9_2.4.x86_64.rpm SHA-256: 8cc9d4d334575c31baba1cbbb5407acb7d9b803f95436886d1e97d9fd01506e2 postgresql-private-libs-debuginfo-13.23-1.el9_2.4.x86_64.rpm SHA-256: 1e097448f2bb967978ae6582556f38c5c9af8ab900afada91c511f4677286597 postgresql-server-13.23-1.el9_2.4.x86_64.rpm SHA-256: c620aa40e04ec9c21505c805eee858089cb7f386b5a6afdba1fc4e729b5a5787 postgresql-server-debuginfo-13.23-1.el9_2.4.x86_64.rpm SHA-256: 339be84f820f903bee6b66d4ed484b31de2718d7567c882ea59962c9c1a68e40 postgresql-server-devel-debuginfo-13.23-1.el9_2.4.x86_64.rpm SHA-256: fb35b998d07e70bfd25b730291edce0d093df58e957d662022a4157c8220091f postgresql-test-debuginfo-13.23-1.el9_2.4.x86_64.rpm SHA-256: 63113bd588e02c7fcaabf708b75e85f7205613d834aa7e7c5be8809908316ab4 postgresql-upgrade-13.23-1.el9_2.4.x86_64.rpm SHA-256: 404e916c942192ca0eb2cdae8f7a4a996f4d32aed19d51e149ebaf02935c2853 postgresql-upgrade-debuginfo-13.23-1.el9_2.4.x86_64.rpm SHA-256: 6209ee3dd4037267aca29311f8673cfb046042a27cd329b8c42d486c5e6df362 postgresql-upgrade-devel-debuginfo-13.23-1.el9_2.4.x86_64.rpm SHA-256: 4637141e103f92cb9f7aebbd5811bb704a4a93a51ee0581059ba4c5715a52d42 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2 SRPM postgresql-13.23-1.el9_2.4.src.rpm SHA-256: e47043011d4ebed6222b37d02772551bc941933188806e43baa7e168b5e9b074 ppc64le postgresql-13.23-1.el9_2.4.ppc64le.rpm SHA-256: 6fda291305da290dcdb69c9bfefff4d6941e4d5ceeba968f82ca2240710b0b6f postgresql-contrib-13.23-1.el9_2.4.ppc64le.rpm SHA-256: de8a7815eb51de4711cb5faff477a32bbf846d76c95034472f524a69c8b5d46b postgresql-contrib-debuginfo-13.23-1.el9_2.4.ppc64le.rpm SHA-256: 56661245a942125906106f769714efe7b41d40e3575eb250d181310dcb168cbd postgresql-debuginfo-13.23-1.el9_2.4.ppc64le.rpm SHA-256: 0ead5a7bc6735326060b5e2e28616bc92e55353cf286812707e1defea8ecaedf postgresql-debugsource-13.23-1.el9_2.4.ppc64le.rpm SHA-256: 3af4af6375ad1e33ce74b5c447e71ba7437b900f7af2c2eedd31b74845ff51c8 postgresql-docs-debuginfo-13.23-1.el9_2.4.ppc64le.rpm SHA-256: 610adde1ce7c37e48f4abc82e1d35316aa637cdf2f6745b6d633a2d67b94c41b postgresql-plperl-13.23-1.el9_2.4.ppc64le.rpm SHA-256: 919cb418acee15c255b56f14e3e4494c42b9c6447ca5a15f0627fa4dfe12ab99 postgresql-plperl-debuginfo-13.23-1.el9_2.4.ppc64le.rpm SHA-256: b605dc076365fce30f60bdf87b8a3f21ab3dc79c2f4e2c5e3fe01fde0505155f postgresql-plpython3-13.23-1.el9_2.4.ppc64le.rpm SHA-256: 8929b885427a0682fddd5d71baadc9a561c1b499aabfdaf1604ab35d4eac80c5 postgresql-plpython3-debuginfo-13.23-1.el9_2.4.ppc64le.rpm SHA-256: e9bfeda557f5a4fc0dec70570e76166d9c410067668d5580b5be19c5abe81133 postgresql-pltcl-13.23-1.el9_2.4.ppc64le.rpm SHA-256: 5a77b548dc35e110cdf462d8c429f15681c3e788a5ddde15c0c9888cba773849 postgresql-pltcl-debuginfo-13.23-1.el9_2.4.ppc64le.rpm SHA-256: 53c4c4eba1b3bade4f5950b6a1cb6e290c81e702a22261a5cdc3231149e1ae5b postgresql-private-libs-13.23-1.el9_2.4.ppc64le.rpm SHA-256: 9fd1e5fc8df175860848c3c1f9c766089c6b62b759ba91e3009da263ff7ad24f postgresql-private-libs-debuginfo-13.23-1.el9_2.4.ppc64le.rpm SHA-256: 12d9664091e3acf26eb0bfe8bec4503d46fea8094ba71133388527ae09da7ffb postgresql-server-13.23-1.el9_2.4.ppc64le.rpm SHA-256: a62f5072fabc9e4b7ad392dcfa08e65c180b394e30165c36c1bfe5be3463f252 postgresql-server-debuginfo-13.23-1.el9_2.4.ppc64le.rpm SHA-256: fbe1e1ef7f6e6d0765c8b0469895554f2169921033a6a320be78114f7b6fd428 postgresql-server-devel-debuginfo-13.23-1.el9_2.4.ppc64le.rpm SHA-256: 632fcb370a7418e958c95db5d091a8612634b06b4d86a51e541f708a29f8dc91 postgresql-test-debuginfo-13.23-1.el9_2.4.ppc64le.rpm SHA-256: d988fa5855c555f10c77863b6efed629d1f91eaaa4f32299469ecc1dec4af5f7 postgresql-upgrade-13.23-1.el9_2.4.ppc64le.rpm SHA-256: f6902c7c40d6af80cb10cb1c95e1ce7da1dd7321e46aeefb0e68b21502b95b08 postgresql-upgrade-debuginfo-13.23-1.el9_2.4.ppc64le.rpm SHA-256: 1c49c4148ce01322c1cfb64f67940fb4e73b6c0dd34142e90e155d2ce1711bf6 postgresql-upgrade-devel-debuginfo-13.23-1.el9_2.4.ppc64le.rpm SHA-256: d3381bbdf02039ba2ca9963b32c6397f51eb83937bbdbda87689547663e75458 Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2 SRPM postgresql-13.23-1.el9_2.4.src.rpm SHA-256: e47043011d4ebed6222b37d02772551bc941933188806e43baa7e168b5e9b074 x86_64 postgresql-13.23-1.el9_2.4.x86_64.rpm SHA-256: 3378d658c84469abac21ef3bc81ac244c23de40c92973a2d0f16d53f94deb35c postgresql-contrib-13.23-1.el9_2.4.x86_64.rpm SHA-256: 1c01f9e70b175c56434ea6131592b9e446e999cb255178baa376d8c30364ba9d postgresql-contrib-debuginfo-13.23-1.el9_2.4.x86_64.rpm SHA-256: 07e0029dcf7a4180d72d3f1adb889cc0329aaeafdb22dd01e2e8979dec3d3a14 postgresql-debuginfo-13.23-1.el9_2.4.x86_64.rpm SHA-256: 28b1f88c62a09e33ded65698325159527ecb729c4fabfae9b4663d85e18ffcf4 postgresql-debugsource-13.23-1.el9_2.4.x86_64.rpm SHA-256: 97d417e34578f3cfe8735e84c842eef7bf621682320217edecfdf6581e33e97f postgresql-docs-debuginfo-13.23-1.el9_2.4.x86_64.rpm SHA-256: 408ffb33586287ea572b48587f55bef77f8bd48055ec2ddc43f44f72ef0953ba postgresql-plperl-13.23-1.el9_2.4.x86_64.rpm SHA-256: 0cc202c50df84bd3db9ca3934958df1019e17b655178d4e1519ea18806e0f7e0 postgresql-plperl-debuginfo-13.23-1.el9_2.4.x86_64.rpm SHA-256: b3b03addacbc4a5ee640178d6eddff16ef2f7198d9d748b930444ca4a19a6ec9 postgresql-plpython3-13.23-1.el9_2.4.x86_64.rpm SHA-256: 0560df6ec27e82b4789a22f0555c521e75c2ea7d57aaf052de0e9fbc8dfa9c7a postgresql-plpython3-debuginfo-13.23-1.el9_2.4.x86_64.rpm SHA-256: afe7223c1395ee6e576844f6b07029a8ac4873f14b06f373c0e6bebe0a9a32e5 postgresql-pltcl-13.23-1.el9_2.4.x86_64.rpm SHA-256: 7a25de56fd52d435d89a76e5f89e36aebe56725278a2ee11ac454724d2663d21 postgresql-pltcl-debuginfo-13.23-1.el9_2.4.x86_64.rpm SHA-256: 50fd655edb64d9350eed4042d3823ad47023dc0d0d4b0ed4ed1dfad8850c1770 postgresql-private-libs-13.23-1.el9_2.4.x86_64.rpm SHA-256: 8cc9d4d334575c31baba1cbbb5407acb7d9b803f95436886d1e97d9fd01506e2 postgresql-private-libs-debuginfo-13.23-1.el9_2.4.x86_64.rpm SHA-256: 1e097448f2bb967978ae6582556f38c5c9af8ab900afada91c511f4677286597 postgresql-server-13.23-1.el9_2.4.x86_64.rpm SHA-256: c620aa40e04ec
A vulnerability (CVE-2026-6479, CVSS 7.5 HIGH) in PostgreSQL allows a Denial of Service via uncontrolled recursion during SSL/GSS negotiation. The flaw affects PostgreSQL versions earlier than 14.23, versions 15.0 through 15.17, 16.0 through 16.13, 17.0 through 17.9, and 18.0 through 18.3. Red Hat has rated this update as Important for affected RHEL 9.2 streams, and the fix requires upgrading to the patched packages provided in the advisory.