postgresql-13.23-3.el9_8
エラータID: AXSA:2026-1366:07
PostgreSQL is an advanced object-relational database management system (DBMS).
Security Fix(es):
* postgresql: PostgreSQL: Operating system account hijack via symlink following in pg_basebackup and pg_rewind (CVE-2026-6475)
* postgresql: PostgreSQL libpq: Buffer overflow allows server superuser to overwrite client stack memory (CVE-2026-6477)
* postgresql: PostgreSQL: Credential recovery via covert timing channel in MD5 password comparison (CVE-2026-6478)
* postgresql: integer overflow can cause an undersized allocation and an out-of-bounds write (CVE-2026-6473)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-6473
Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds. This may execute arbitrary code as the operating system user running the database. In applications that pass gigabyte-scale user inputs to the relevant database functions, the application input provider may achieve a segmentation fault. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
CVE-2026-6475
Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
CVE-2026-6477
Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
CVE-2026-6478
Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Update packages.
Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds. This may execute arbitrary code as the operating system user running the database. In applications that pass gigabyte-scale user inputs to the relevant database functions, the application input provider may achieve a segmentation fault. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
N/A
SRPMS
- postgresql-13.23-3.el9_8.src.rpm
MD5: 181b22cc77a8a3be97593de6976979ee
SHA-256: 8680370f4e50a5675e19087a46cdb727f21b7b724f306b9c621c8d546809a3db
Size: 48.98 MB
Asianux Server 9 for x86_64
- postgresql-13.23-3.el9_8.x86_64.rpm
MD5: c4ab64f58e542d3448e95b34b84dce6f
SHA-256: ff2e4ab547ade339b205919335397015108889a820a08b789cb1b7f226e03604
Size: 1.62 MB - postgresql-contrib-13.23-3.el9_8.x86_64.rpm
MD5: d49db9e8963b4569ad4de53e78aeb89b
SHA-256: 2aad922a567161cfc0a60d6b74235e4e546ca8f5adaa9d67b6fbfc88ce8003fd
Size: 885.28 kB - postgresql-docs-13.23-3.el9_8.x86_64.rpm
MD5: a727e37105197bade7952c6a10c6919a
SHA-256: 1ffc290eb3e31e9ad87b3c2d65611b3063265f52f3fcbf0d1e417631a973f160
Size: 9.66 MB - postgresql-plperl-13.23-3.el9_8.x86_64.rpm
MD5: 5b947d425eeb5ead01a4b7588622ed97
SHA-256: 340cec10a53830e56747bfde599a4da32126a1e209f19fee6b846ecb669c4dbb
Size: 74.91 kB - postgresql-plpython3-13.23-3.el9_8.x86_64.rpm
MD5: 0b5d3bfeea03865b15e678adcc7b1797
SHA-256: 754aeb0512f0710a3b8f49d5de1218343ffc29b9d25b849bcbbf49919ded696c
Size: 95.07 kB - postgresql-pltcl-13.23-3.el9_8.x86_64.rpm
MD5: a74ab8e6c796490400f0e5aed3153122
SHA-256: f8cf0d0f241cd7fd55a37400d00fbaf6481b2d3fd4ccfa405d1c62eeeb6de1fa
Size: 48.91 kB - postgresql-private-devel-13.23-3.el9_8.x86_64.rpm
MD5: 316738d7a1b420b2a403da7215162080
SHA-256: eb51aed2849937618b7ffe0ce8038238c1c184447565a20c7839ddc95e843d5d
Size: 63.74 kB - postgresql-private-libs-13.23-3.el9_8.x86_64.rpm
MD5: de6ee3e8a099e13986e64158725a7991
SHA-256: 60213304cfc45ef9d9e6083d286d52f3884fd656eb49153823f3fb779b81cff8
Size: 138.23 kB - postgresql-server-13.23-3.el9_8.x86_64.rpm
MD5: 598f26099e445b1e1bdb61b748da8138
SHA-256: e1582a3e26745c00e62a9dcf44c6b1c0ba8c172578d7294b5b8ed7a1c2da5843
Size: 5.76 MB - postgresql-server-devel-13.23-3.el9_8.x86_64.rpm
MD5: 0b935fd9b0f92f41effcd1c0cdbee05b
SHA-256: 53f61ece1e5647bb25f96ed2c1ba9f40daedbbca20fdd39e35149e7dcffb5f3a
Size: 1.31 MB - postgresql-static-13.23-3.el9_8.x86_64.rpm
MD5: ecaa9efbb4067ea1013d329ecb4d697c
SHA-256: 253788891c5725e20a5fc94e32519d4e00bfb52574056cc29862f67608b450f7
Size: 127.03 kB - postgresql-test-13.23-3.el9_8.x86_64.rpm
MD5: 2864fbad889f3f4144cc6966f4e9ebcd
SHA-256: e739cc16e7c3dc85d4b090fa035bf180b5cb8b06ea18b6be698032fd6ae6924d
Size: 1.54 MB - postgresql-test-rpm-macros-13.23-3.el9_8.noarch.rpm
MD5: f9018954af709c5f349b8799d6c685eb
SHA-256: d5873b5303ca8cdede49a3e8780047d45ff4a1f8e7d8a66770ef7f60c8fbe036
Size: 9.66 kB - postgresql-upgrade-13.23-3.el9_8.x86_64.rpm
MD5: aaa2854a9b0925c34e7e5e921336fee6
SHA-256: c6d2ff2b595ad382c5044f60f0efa6cd65067ad8222a1f22b870d55ae8d90aaf
Size: 4.60 MB - postgresql-upgrade-devel-13.23-3.el9_8.x86_64.rpm
MD5: 22d7d9738d96e815d34ebdc35806e9e0
SHA-256: d2aa2b983049c8404648ebbe3153c18aeff785c7fba7f2df73f2a586ff7a48a0
Size: 1.20 MB