postgresql-jdbc-42.2.14-4.el8_10
エラータID: AXSA:2026-782:01
PostgreSQL is an advanced object-relational database management system. The postgresql-jdbc package includes the .jar files needed for Java programs to access a PostgreSQL database.
Security Fix(es):
* jdbc.postgresql.org: pgjdbc: Client-side Denial of Service via malicious SCRAM-SHA-256 authentication (CVE-2026-42198)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-42198
pgjdbc is an open source postgresql JDBC Driver. From version 42.2.0 to before version 42.7.11, pgjdbc is vulnerable to a client-side denial of service during SCRAM-SHA-256 authentication. A malicious server can instruct the driver to perform SCRAM authentication with a very large iteration count. With a large enough value, the client spends an unbounded amount of CPU time inside PBKDF2 before authentication can fail. A single attempt ties up a CPU core. Repeated or concurrent attempts exhaust client CPU and can wedge connection pools. In affected versions, loginTimeout did not fully mitigate this problem. When loginTimeout expired, the caller could stop waiting, but the worker thread performing the connection attempt could continue running and burning CPU inside the SCRAM PBKDF2 computation. This issue has been patched in version 42.7.11.
Update packages.
pgjdbc is an open source postgresql JDBC Driver. From version 42.2.0 to before version 42.7.11, pgjdbc is vulnerable to a client-side denial of service during SCRAM-SHA-256 authentication. A malicious server can instruct the driver to perform SCRAM authentication with a very large iteration count. With a large enough value, the client spends an unbounded amount of CPU time inside PBKDF2 before authentication can fail. A single attempt ties up a CPU core. Repeated or concurrent attempts exhaust client CPU and can wedge connection pools. In affected versions, loginTimeout did not fully mitigate this problem. When loginTimeout expired, the caller could stop waiting, but the worker thread performing the connection attempt could continue running and burning CPU inside the SCRAM PBKDF2 computation. This issue has been patched in version 42.7.11.
N/A
SRPMS
- postgresql-jdbc-42.2.14-4.el8_10.src.rpm
MD5: 3883cabe120babc7cb8ca92d54a7ddca
SHA-256: 172aa0c6c66781b227fb1fd464bfaffca59c33006f7734532655a3357a97ea65
Size: 887.46 kB
Asianux Server 8 for x86_64
- postgresql-jdbc-42.2.14-4.el8_10.noarch.rpm
MD5: ffcc2ccd21ac3ecb542003752451f79e
SHA-256: 667a198117d4554e9389a95739e700ef3a29f79e1a4f2b8f37d78797a44a7979
Size: 753.98 kB - postgresql-jdbc-javadoc-42.2.14-4.el8_10.noarch.rpm
MD5: e813a4ac62e771dd9bc64c27764b6473
SHA-256: 15cbc1a10dd1d577a66ef69ab323ed962cfb709bfb41a06ce86532692b50ffac
Size: 659.23 kB