libpq-13.23-3.el9_8
エラータID: AXSA:2026-1531:04
The libpq package provides the PostgreSQL client library, which allows client programs to connect to PostgreSQL servers.
Security Fix(es):
* postgresql: PostgreSQL libpq: Buffer overflow allows server superuser to overwrite client stack memory (CVE-2026-6477)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-6477
Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Update packages.
Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
N/A
SRPMS
- libpq-13.23-3.el9_8.src.rpm
MD5: 4230282b4e721c213d10dcffde08db80
SHA-256: e485632bd9a36e83402e841d8f0ebd29de75290a58f14527bc89bcf3533c24bc
Size: 20.71 MB
Asianux Server 9 for x86_64
- libpq-13.23-3.el9_8.i686.rpm
MD5: 74f3d755c0be1a209e128a9698d27a7f
SHA-256: e5bce2eb0e1a79b4286a68530bbbfa74fb07c8af32dac2edca4aa4d43b3bece4
Size: 219.37 kB - libpq-13.23-3.el9_8.x86_64.rpm
MD5: 27a538359d4558e555386e6a51d8a121
SHA-256: 56809f2095d0103b2bfeaa4e32838378cae78cbfc322ccc801f09a7ef6584347
Size: 212.59 kB - libpq-devel-13.23-3.el9_8.i686.rpm
MD5: 172c0964f6a3356f5e429e8db234e1ab
SHA-256: 4c25680887a30bb7c08527ebf8356876c1c1fab5ea56f10de628ff4625d9a66d
Size: 102.03 kB - libpq-devel-13.23-3.el9_8.x86_64.rpm
MD5: 07ce49af73a83fe1061fcd3b494f82df
SHA-256: 53f7a3ff579166e0fa9c0e8df3bb3e64d0ff37f4456b2fb133bdb2b50beb7121
Size: 101.19 kB