[security - high] postgresql:18 security update
エラータID: AXSA:2026-1357:01
PostgreSQL is an advanced object-relational database management system (DBMS).
Security Fix(es):
* postgresql: PostgreSQL: Operating system account hijack via symlink following in pg_basebackup and pg_rewind (CVE-2026-6475)
* postgresql: PostgreSQL libpq: Buffer overflow allows server superuser to overwrite client stack memory (CVE-2026-6477)
* postgresql: PostgreSQL: Credential recovery via covert timing channel in MD5 password comparison (CVE-2026-6478)
* postgresql: integer overflow can cause an undersized allocation and an out-of-bounds write (CVE-2026-6473)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-6473
Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds. This may execute arbitrary code as the operating system user running the database. In applications that pass gigabyte-scale user inputs to the relevant database functions, the application input provider may achieve a segmentation fault. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
CVE-2026-6475
Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
CVE-2026-6477
Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
CVE-2026-6478
Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Modularity name: "postgresql"
Stream name: "18"
Update packages.
Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds. This may execute arbitrary code as the operating system user running the database. In applications that pass gigabyte-scale user inputs to the relevant database functions, the application input provider may achieve a segmentation fault. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
N/A
SRPMS
- pgaudit-18.0-1.module+el9+1167+30043d1f.src.rpm
MD5: c264cd671a912d0f9d61431fc9bb09e3
SHA-256: f32fa115aed711e360189dd0b7a2f5ac544274272e4fa18bbc89cf0baa4e48f1
Size: 54.32 kB - pg_repack-1.5.3-1.module+el9+1167+30043d1f.src.rpm
MD5: 85770e1ab093982fd9e30bd4da8041c9
SHA-256: aaf3d5b959dbf65cc72798977aae3ef192a83eeb11fb70d16e06f401c54c37b7
Size: 106.63 kB - pgvector-0.8.1-1.module+el9+1167+30043d1f.src.rpm
MD5: e3ddb9762ab9ddeb87a3da3c1c097d6e
SHA-256: 84d53f2b305f1508996c03f1b3e1a8b4bbb24aa9efc8796c07dad7bcc8ed508f
Size: 127.79 kB - postgis-3.6.1-2.module+el9+1167+30043d1f.src.rpm
MD5: 6fb1d0fa3cdb444f5b78a5e4359141cc
SHA-256: fe63fb1f66d094b7039dc834e0034bfed7ebff48db671c5f0acbc3cd4939c0af
Size: 15.46 MB - postgres-decoderbufs-3.3.1-1.Final.module+el9+1167+30043d1f.src.rpm
MD5: afbd074460417db4c1ba09af9e1376ff
SHA-256: 10d36b64aa1b17844b835a82e9e1ec8b159579a8eb702acd52f481c2c7377408
Size: 21.53 kB - postgresql-18.4-2.module+el9+1167+30043d1f.src.rpm
MD5: ad3df5be5d3ef81f5a346fab43107af0
SHA-256: 1f14af77bdc662f8c2e2a4ef77baa569d2d1993c42f9a27c4b9c54bbd3c57d48
Size: 45.45 MB
Asianux Server 9 for x86_64
- pgaudit-18.0-1.module+el9+1167+30043d1f.x86_64.rpm
MD5: 4a0811763ed4a1bcfc29495aca63f977
SHA-256: 4f8cb6513c794a3b93d939b6be697f0ee1e41fd42697c3273637e2846245cf86
Size: 28.23 kB - pgaudit-debugsource-18.0-1.module+el9+1167+30043d1f.x86_64.rpm
MD5: 0e8e9cabb74c8bfddb8cdd747b63cad6
SHA-256: 6cebd2c869fc27469573d5a81fc66fab79b43a4f5e52910e398290edcf68c429
Size: 23.51 kB - pg_repack-1.5.3-1.module+el9+1167+30043d1f.x86_64.rpm
MD5: bd4dc3bcb5cb3660dacdd20d3e57183c
SHA-256: 5637996781787a6b150a0c17907de490518a1249f873cf851d412e4310ca62a8
Size: 93.03 kB - pg_repack-debugsource-1.5.3-1.module+el9+1167+30043d1f.x86_64.rpm
MD5: 30e41103eb25206b83985574304d502a
SHA-256: dbed3da8f04b4c6be93d74eaacf132f2935798183452dee6bc335a9f39332c43
Size: 49.40 kB - pgvector-0.8.1-1.module+el9+1167+30043d1f.x86_64.rpm
MD5: d642b2863d0a9bfc1c083d5b5367295b
SHA-256: d869c21382b17bc3e3075e9870d71bddea4d39b17105b2a39cbde70e972f3b0d
Size: 115.41 kB - pgvector-debugsource-0.8.1-1.module+el9+1167+30043d1f.x86_64.rpm
MD5: d45edcb733cde8fdc4d40e48a5fc41c1
SHA-256: 7a9c0648e7773919fa113bb80fce92b55a6330a7850b5d950ffbbbe04c2716d1
Size: 70.97 kB - postgis-3.6.1-2.module+el9+1167+30043d1f.x86_64.rpm
MD5: d940e3b848b8565d20b411bfb0f25ca2
SHA-256: ebbf8786211e5e648bf9e7edf8e8dea12bc862bec478b953acc85a92a53656fc
Size: 1.79 MB - postgis-client-3.6.1-2.module+el9+1167+30043d1f.x86_64.rpm
MD5: 9e590dfe60fd81979ef7a70047b0d2ce
SHA-256: 2f51d62be9ec4dfe048fce1bc095d9fcc7a6496c8282fedda46df7c84ba708b4
Size: 116.37 kB - postgis-debugsource-3.6.1-2.module+el9+1167+30043d1f.x86_64.rpm
MD5: a56fdf815020a27eb0451f6b3d5e9013
SHA-256: 83d65aac2ad32e231e985123df32f857a20029ef0b50252bf514248dee086fa0
Size: 1.07 MB - postgis-docs-3.6.1-2.module+el9+1167+30043d1f.x86_64.rpm
MD5: 089639d8078dd5a8a9ca2887710f4e81
SHA-256: 838112f86ff6c37c08ee863069fa54925cf5854c40b8b4e138ab7bc7fb9a9a58
Size: 7.96 kB - postgis-upgrade-3.6.1-2.module+el9+1167+30043d1f.x86_64.rpm
MD5: 69206b2f052b3a1772d5ae239841630e
SHA-256: df9476e6a3c6b0c5d110374716053684c9601bddd1ae0551d97240ce12a74441
Size: 791.96 kB - postgis-utils-3.6.1-2.module+el9+1167+30043d1f.x86_64.rpm
MD5: 0264f356e84f965f1e87744243ef1d7d
SHA-256: 8b6ec8e13690cae4c76fa5c7456e04f19dc13bf2f57f4fbc80693faaa9225791
Size: 36.51 kB - postgres-decoderbufs-3.3.1-1.Final.module+el9+1167+30043d1f.x86_64.rpm
MD5: c3eaaef085a512a73579448a8477e293
SHA-256: 9840978dc85950d5538f759cfbd6b46f0f4a58e6bcc12e5033eb8054b07f0492
Size: 21.86 kB - postgres-decoderbufs-debugsource-3.3.1-1.Final.module+el9+1167+30043d1f.x86_64.rpm
MD5: 356130d36ab3f6b2d0744714ebaf88e4
SHA-256: a1816d8fd9b89c9ecd9312306cde006663653c8b6062ee8084efbad7339428f3
Size: 16.58 kB - postgresql-18.4-2.module+el9+1167+30043d1f.x86_64.rpm
MD5: 78fcecdfebe4cb44e0545681c585182b
SHA-256: df63a185a0eba911aa0e32a326ac6721d826fdd337981025b51fc068da994e75
Size: 2.05 MB - postgresql-contrib-18.4-2.module+el9+1167+30043d1f.x86_64.rpm
MD5: 21adc0b2780322a3de43ddd360508a15
SHA-256: f3ea7061520c90d3ab656e86ae0c12ce7b215b422baabc9c5d875c3335d207af
Size: 1.08 MB - postgresql-debugsource-18.4-2.module+el9+1167+30043d1f.x86_64.rpm
MD5: d719f5a6a312c2a0fead9c8da1e1b530
SHA-256: d6d5620ab51b29af99a5c3cd01c3028a7c02175cdba42193299a938fa32d88a4
Size: 17.95 MB - postgresql-docs-18.4-2.module+el9+1167+30043d1f.x86_64.rpm
MD5: f09d1ba4a006f7264856c746c7416c65
SHA-256: 0644b315a7d56d89ac0f840d19ecde419c62bc854f1ba0bf1feed90d6659dc29
Size: 2.41 MB - postgresql-plperl-18.4-2.module+el9+1167+30043d1f.x86_64.rpm
MD5: 30ea1a54fb5ca8bdaecff0dd4accea68
SHA-256: 0ed51d5580b3b33fa2fd5f83dfae08cf6b4fe90f12bed1a1839a843b83009e73
Size: 79.66 kB - postgresql-plpython3-18.4-2.module+el9+1167+30043d1f.x86_64.rpm
MD5: 14582c6c050a29c80b9ef0aee3c88556
SHA-256: e1e247dd4774f463d5565fffcd71cc83f0d940c548d5c1497bcb0896f7e3a3e1
Size: 101.33 kB - postgresql-pltcl-18.4-2.module+el9+1167+30043d1f.x86_64.rpm
MD5: 2878e66369b7f721ef7c29dadf52dee1
SHA-256: 8ccd1c9577a7bcc61d3d63da84c609c2da28c88892b2be438c1467d8c7a9bbbb
Size: 53.40 kB - postgresql-private-devel-18.4-2.module+el9+1167+30043d1f.x86_64.rpm
MD5: 6f01449af3987ced142224363e233017
SHA-256: 7bfe55bdc0dfb6c3b842d81b0f824da9a8310bbafe013563b1254c95fdeb4cba
Size: 68.19 kB - postgresql-private-libs-18.4-2.module+el9+1167+30043d1f.x86_64.rpm
MD5: 71d8805807e45309163012dc395aa9e7
SHA-256: 887ed22601566b18fcc37a35492dfaa42541345a08e54d3f496ec59092a1476e
Size: 157.51 kB - postgresql-server-18.4-2.module+el9+1167+30043d1f.x86_64.rpm
MD5: d3d7bcb32693c3cac2145a5d894dd129
SHA-256: 8add6f977634516484a3d9a4426e7362cfb3531beddd8a9822f25a48ec7aa612
Size: 7.48 MB - postgresql-server-devel-18.4-2.module+el9+1167+30043d1f.x86_64.rpm
MD5: dab47c5f3677d32af81040ff38a370d5
SHA-256: c076d5f0469fb13449dad64263bcdf42169001eba09e1687e91b3e95c5bdeec6
Size: 1.62 MB - postgresql-static-18.4-2.module+el9+1167+30043d1f.x86_64.rpm
MD5: 7a43dccd9230854d0fb0a8714d521efe
SHA-256: be79ad1044db33da90055bc7b828de29f5525de62661cf7175bef8f4fd2b53e4
Size: 187.89 kB - postgresql-test-18.4-2.module+el9+1167+30043d1f.x86_64.rpm
MD5: 3818b43dc27bfa1b18d66b1173717cbd
SHA-256: f8c1174d08578cec3e8b211f7096340ba276006726792d028af06ff16001563a
Size: 2.00 MB - postgresql-test-rpm-macros-18.4-2.module+el9+1167+30043d1f.noarch.rpm
MD5: 7c49f693267724eb1c1eb83022da130f
SHA-256: a07a6a4dfa1e9998d9908cd175cff47be1a32df2b9fc8ea295b8b0d0e5c4bd00
Size: 9.23 kB - postgresql-upgrade-18.4-2.module+el9+1167+30043d1f.x86_64.rpm
MD5: 2fefd310fb63ef876f77ab98000c88ae
SHA-256: 6f900641f1f936029afccc65922727c6a74a4c5f23be687131e981aac0b5630d
Size: 5.32 MB - postgresql-upgrade-devel-18.4-2.module+el9+1167+30043d1f.x86_64.rpm
MD5: 9ad5cc35b3edd3c7be94a0b5112fcda9
SHA-256: d5c7243905e7be6ced7790c8c0f493ec0df67a9300b484d0bf8379a3d2ca1ba8
Size: 1.41 MB