[security - high] postgresql:16 security update
エラータID: AXSA:2026-1358:01
PostgreSQL is an advanced object-relational database management system (DBMS).
Security Fix(es):
* postgresql: PostgreSQL: Operating system account hijack via symlink following in pg_basebackup and pg_rewind (CVE-2026-6475)
* postgresql: PostgreSQL libpq: Buffer overflow allows server superuser to overwrite client stack memory (CVE-2026-6477)
* postgresql: PostgreSQL: Credential recovery via covert timing channel in MD5 password comparison (CVE-2026-6478)
* postgresql: integer overflow can cause an undersized allocation and an out-of-bounds write (CVE-2026-6473)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-6473
Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds. This may execute arbitrary code as the operating system user running the database. In applications that pass gigabyte-scale user inputs to the relevant database functions, the application input provider may achieve a segmentation fault. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
CVE-2026-6475
Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
CVE-2026-6477
Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
CVE-2026-6478
Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Modularity name: "postgresql"
Stream name: "16"
Update packages.
Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds. This may execute arbitrary code as the operating system user running the database. In applications that pass gigabyte-scale user inputs to the relevant database functions, the application input provider may achieve a segmentation fault. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
N/A
SRPMS
- pgaudit-16.0-1.module+el9+1166+c1810413.src.rpm
MD5: 938dca7f7b786279503e93132a2f2a1d
SHA-256: 9827a4c99307c5b87b2276158c793237c0ca57bd8641483d8846feb859855c5d
Size: 52.79 kB - pg_repack-1.5.1-1.module+el9+1166+c1810413.src.rpm
MD5: 35871cdf81e3ad8f492bd5fcf8f30502
SHA-256: bd6f73e1048f0c69773d00f1ae3aec28ba9a2d3c8c80bbfca0fd496a6e3dd7a1
Size: 105.44 kB - pgvector-0.6.2-2.module+el9+1166+c1810413.src.rpm
MD5: 4546d12f59a6bc08737004b53be3b41f
SHA-256: 06d3155eef8eb97354ef3bc55967ba7dbf15791d0804c69413338830ecfbdcd1
Size: 87.64 kB - postgis-3.5.3-5.module+el9+1166+c1810413.src.rpm
MD5: 2636922b22fb11b4759c598bbd5e0c79
SHA-256: 96c34403a33abf90aec7cbe8a47c48d9f2394af6479251bd33ae934ddb56c6d4
Size: 19.04 MB - postgres-decoderbufs-2.4.0-1.Final.module+el9+1166+c1810413.src.rpm
MD5: d7a1f50587409b5ad3d2cb4383e802e9
SHA-256: af9e98be4e3b6f48f1eaa12ea598f7a8be859023d193f8365310df0a4eed34ed
Size: 21.46 kB - postgresql-16.14-1.module+el9+1166+c1810413.src.rpm
MD5: 600f65a6cb7e78cfb28fee43664f24c2
SHA-256: 7a0fa4fa30259ff69c9f9893c559e4192a7c9d8305a3f2318d37bb2ff5392fdd
Size: 46.20 MB
Asianux Server 9 for x86_64
- pgaudit-16.0-1.module+el9+1166+c1810413.x86_64.rpm
MD5: 1888308a8e0b2e8ed9d610ecd6013137
SHA-256: 375dfccca19e14f904166f02bd9bba63373b8f3956c7d72a9bd15223193b055d
Size: 27.64 kB - pgaudit-debugsource-16.0-1.module+el9+1166+c1810413.x86_64.rpm
MD5: fbed2a01cfadc83cc0094e999f4987b0
SHA-256: 5477192a6f7037f1e3f1087618909e1e335c093be4cd8142f01f40522fbdb32b
Size: 22.84 kB - pg_repack-1.5.1-1.module+el9+1166+c1810413.x86_64.rpm
MD5: 02727546613fa6f96a51de846ead202c
SHA-256: 36b07d241e0550e82199aebffaf20c0dd7555e1f6c3a3d5432be644ee92cc9ac
Size: 92.51 kB - pg_repack-debugsource-1.5.1-1.module+el9+1166+c1810413.x86_64.rpm
MD5: af60fb97063e04b87e43b874747a05cb
SHA-256: 3a65b4d6b2db32aa3b2426d9a0e7e7a4a28e25d441f52ef50e2a94ecbd2af59c
Size: 49.03 kB - pgvector-0.6.2-2.module+el9+1166+c1810413.x86_64.rpm
MD5: fa96e8b7f118c45d0be7f2418a407f2a
SHA-256: c87e31af5a0cb4b4cd1338b5e004a1e55aac34d74579c5b5968f3bf64193731b
Size: 80.64 kB - pgvector-debugsource-0.6.2-2.module+el9+1166+c1810413.x86_64.rpm
MD5: 8fbb5625a6db32be74f5081e5f4af552
SHA-256: e04616a6dde340883ed3b1e3f3fc7a071fe384caaa2c1bd966f2e58d6c31c3af
Size: 54.87 kB - postgis-3.5.3-5.module+el9+1166+c1810413.x86_64.rpm
MD5: 514f3f17ec2597ad45e70fb4c5966076
SHA-256: 1e9f778d7fc3af8636eb7afbeb9052a78131c1f26927ebc2ff6cfe2b8cda315b
Size: 2.00 MB - postgis-client-3.5.3-5.module+el9+1166+c1810413.x86_64.rpm
MD5: 10283ec3b7040b8ded3fa590cddb828c
SHA-256: 66bdb1b3d5326e8c922d93c5fc0403f6833a254825d4ded4a9c7c3be1b7d9921
Size: 148.61 kB - postgis-debugsource-3.5.3-5.module+el9+1166+c1810413.x86_64.rpm
MD5: 2de017928adaeb23693e1f525f88269b
SHA-256: a3d88248bd539bb913b2eeb56582283d374441d15d2266464b6d3ef336299bf6
Size: 1.24 MB - postgis-docs-3.5.3-5.module+el9+1166+c1810413.x86_64.rpm
MD5: 31eaae3d6ea028f310a2bc1ab9b2eb10
SHA-256: a12246d803a3c09d289c348192e2896767e19e4033691d6832fb92c7bcc5b747
Size: 4.85 MB - postgis-upgrade-3.5.3-5.module+el9+1166+c1810413.x86_64.rpm
MD5: 50ca425ff6bebafe1cef0d55342e654e
SHA-256: ddb9da9a12c521d6883163fb147d68fc7d901c3b5f32ab86a29e68ac5d4f88d3
Size: 971.97 kB - postgis-utils-3.5.3-5.module+el9+1166+c1810413.x86_64.rpm
MD5: 4fca9d3a20407872d7e5fc510eca1d12
SHA-256: 692d94404ed817efb0d17129197e8b4ab654b2934c1e61185bd4e9b801fd2779
Size: 34.47 kB - postgres-decoderbufs-2.4.0-1.Final.module+el9+1166+c1810413.x86_64.rpm
MD5: 3baf569b7d83a71e67a91a53620aa7f0
SHA-256: 831e3b638bbf4a45296e6e82b987e6b143205b194f2baae886a0f7cd4b22b9de
Size: 21.83 kB - postgres-decoderbufs-debugsource-2.4.0-1.Final.module+el9+1166+c1810413.x86_64.rpm
MD5: a1b538ea900ac14f5c6f200d87c02749
SHA-256: fcf64828eb81bd199864097512b71ce1fe86aaf4fee5302d057bdf9077e09273
Size: 16.55 kB - postgresql-16.14-1.module+el9+1166+c1810413.x86_64.rpm
MD5: e2fd99671b87f04bf3c137cf10ad191c
SHA-256: 2a496e2fb7605222a9e3aebff2fca33e430213cda6a9593c664707e76f7778ea
Size: 1.96 MB - postgresql-contrib-16.14-1.module+el9+1166+c1810413.x86_64.rpm
MD5: 99957cd0c2debe6a87823c2af2745b24
SHA-256: 1858171abcbc86e30c368f26dea965bd3d9f3292680af96ddba2e372262bbb21
Size: 1.01 MB - postgresql-debugsource-16.14-1.module+el9+1166+c1810413.x86_64.rpm
MD5: 73f25282cd957404841f4275d0e1688a
SHA-256: da4e55051182b71395e6c44fcb716e9f5e315c3ee2cdee8036234a3b76b54cc8
Size: 17.02 MB - postgresql-docs-16.14-1.module+el9+1166+c1810413.x86_64.rpm
MD5: 0afc09679d8c4d76a2e6f3b53ffbb39c
SHA-256: bb8765abea726335f785004d7779e861dc7fefb7b03c170e5ad9cdd58bc47d5d
Size: 2.37 MB - postgresql-plperl-16.14-1.module+el9+1166+c1810413.x86_64.rpm
MD5: d462c206acad67371107ec997d37bd78
SHA-256: fbef9521da9bf1f485ad89b2535da8ea4f4c0e359fbeb0e8cb32f02fd71c87da
Size: 80.48 kB - postgresql-plpython3-16.14-1.module+el9+1166+c1810413.x86_64.rpm
MD5: c6facf4ca643ee07b3cab0d7b81fe1cc
SHA-256: 0c2f9c7b65bb37391b96ac9e53c47b1ab7d0b9e6316d21cab0849ee108d5fba9
Size: 102.94 kB - postgresql-pltcl-16.14-1.module+el9+1166+c1810413.x86_64.rpm
MD5: 1593928e27fcfaed812737c2d570157c
SHA-256: 4eaf5dc662f256538bd7a7ca8336733ef419a213e6b304bfca323c5ecc7d7402
Size: 53.48 kB - postgresql-private-devel-16.14-1.module+el9+1166+c1810413.x86_64.rpm
MD5: 75d8d8841f1cde6035338d84208fe361
SHA-256: 66691c649ae554541befb84db25a618f0f57f9b3f50be1fedebdba2fef88360e
Size: 66.33 kB - postgresql-private-libs-16.14-1.module+el9+1166+c1810413.x86_64.rpm
MD5: 94c18b06edee2c19e2d72b65a1ebe275
SHA-256: 93062355eee631d7c707c9a22129c271d4012e83c8ce8527649d6a92fd258700
Size: 143.21 kB - postgresql-server-16.14-1.module+el9+1166+c1810413.x86_64.rpm
MD5: ca1f8b534be56297669790e9cf57bc8a
SHA-256: fa79cd9266aecc1c2df0a7ceb304f61bdb0768aa1ebea597c7130f1018345d81
Size: 6.98 MB - postgresql-server-devel-16.14-1.module+el9+1166+c1810413.x86_64.rpm
MD5: 88965c58f2cb7100f6d248c7f167d2b5
SHA-256: f1c5287161305a27256143b7d406062cf8f6a5c31319b12a0a285b530d180ef7
Size: 1.49 MB - postgresql-static-16.14-1.module+el9+1166+c1810413.x86_64.rpm
MD5: 6b40eea0f3943d249661ad1d8740d7c8
SHA-256: 2599990ab8af70f4afc79d0d269832206d6a0e41d06b525bd7f01e970e60b0b0
Size: 132.44 kB - postgresql-test-16.14-1.module+el9+1166+c1810413.x86_64.rpm
MD5: ff28981823bf5798a8d73407f5616ad0
SHA-256: b672152cdfa327e5d92183e65423e58d3df8fa1863d0731d0555394acfaba614
Size: 1.80 MB - postgresql-test-rpm-macros-16.14-1.module+el9+1166+c1810413.noarch.rpm
MD5: 07b2e9025a91130310dcade585b8f6db
SHA-256: 7cc6fa794973fdbca51b86c093899d4a06b92c3d187fdc9e9a1c809e79f09cde
Size: 9.67 kB - postgresql-upgrade-16.14-1.module+el9+1166+c1810413.x86_64.rpm
MD5: 3b067ce178de55ddea1c31e3161fb8a4
SHA-256: 2f9fa5e0cb69a8cbce6ca57b8b97a6916019ffd7885216cb0bdf3868859ed6f4
Size: 5.15 MB - postgresql-upgrade-devel-16.14-1.module+el9+1166+c1810413.x86_64.rpm
MD5: 782c6d397db6a736d2485b07f17bcfaa
SHA-256: 8cc29480d39c7074ae7b14fc773a6fca58c670869d8ea2edf2de8b45819bbdb1
Size: 1.38 MB