postgresql:18 security update
エラータID: AXSA:2026-1357:01
リリース日:
2026/07/28 Tuesday - 09:08
題名:
postgresql:18 security update
影響のあるチャネル:
MIRACLE LINUX 9 for x86_64
Severity:
High
Description:
以下項目について対処しました。
[Security Fix]
- PostgreSQL には、整数オーバーフローの問題があるため、リモート
の攻撃者により、PostgreSQL を実行しているユーザーの権限での任意
のコードの実行、およびサービス拒否攻撃を可能とする脆弱性が存在
します。(CVE-2026-6473)
- PostgreSQL には、シンボリックリンクの解釈処理に問題があるため、
ローカルの攻撃者により、情報の漏洩、データ破壊、およびサービス
拒否攻撃を可能とする脆弱性が存在します。(CVE-2026-6475)
- PostgreSQL の libpq の lo_export() 関数、lo_read() 関数、
lo_lseek64() 関数、lo_tell64() 関数には、バッファオーバーフローの
問題があるため、リモートの攻撃者により、任意のコードの実行を可能
とする脆弱性が存在します。(CVE-2026-6477)
- PostgreSQL には、タイミングサイドチャネル攻撃が可能となって
しまう問題があるため、リモートの攻撃者により、情報の漏洩、および
データ破壊を可能とする脆弱性が存在します。(CVE-2026-6478)
Modularity name: postgresql
Stream name: 18
解決策:
パッケージをアップデートしてください。
CVE:
CVE-2026-6473
Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds. This may execute arbitrary code as the operating system user running the database. In applications that pass gigabyte-scale user inputs to the relevant database functions, the application input provider may achieve a segmentation fault. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds. This may execute arbitrary code as the operating system user running the database. In applications that pass gigabyte-scale user inputs to the relevant database functions, the application input provider may achieve a segmentation fault. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
CVE-2026-6475
Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
CVE-2026-6477
Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
CVE-2026-6478
Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
追加情報:
N/A
ダウンロード:
SRPMS
- pgaudit-18.0-1.module+el9+1167+30043d1f.src.rpm
MD5: c264cd671a912d0f9d61431fc9bb09e3
SHA-256: f32fa115aed711e360189dd0b7a2f5ac544274272e4fa18bbc89cf0baa4e48f1
Size: 54.32 kB - pg_repack-1.5.3-1.module+el9+1167+30043d1f.src.rpm
MD5: 85770e1ab093982fd9e30bd4da8041c9
SHA-256: aaf3d5b959dbf65cc72798977aae3ef192a83eeb11fb70d16e06f401c54c37b7
Size: 106.63 kB - pgvector-0.8.1-1.module+el9+1167+30043d1f.src.rpm
MD5: e3ddb9762ab9ddeb87a3da3c1c097d6e
SHA-256: 84d53f2b305f1508996c03f1b3e1a8b4bbb24aa9efc8796c07dad7bcc8ed508f
Size: 127.79 kB - postgis-3.6.1-2.module+el9+1167+30043d1f.src.rpm
MD5: 6fb1d0fa3cdb444f5b78a5e4359141cc
SHA-256: fe63fb1f66d094b7039dc834e0034bfed7ebff48db671c5f0acbc3cd4939c0af
Size: 15.46 MB - postgres-decoderbufs-3.3.1-1.Final.module+el9+1167+30043d1f.src.rpm
MD5: afbd074460417db4c1ba09af9e1376ff
SHA-256: 10d36b64aa1b17844b835a82e9e1ec8b159579a8eb702acd52f481c2c7377408
Size: 21.53 kB - postgresql-18.4-2.module+el9+1167+30043d1f.src.rpm
MD5: ad3df5be5d3ef81f5a346fab43107af0
SHA-256: 1f14af77bdc662f8c2e2a4ef77baa569d2d1993c42f9a27c4b9c54bbd3c57d48
Size: 45.45 MB
Asianux Server 9 for x86_64
- pgaudit-18.0-1.module+el9+1167+30043d1f.x86_64.rpm
MD5: 4a0811763ed4a1bcfc29495aca63f977
SHA-256: 4f8cb6513c794a3b93d939b6be697f0ee1e41fd42697c3273637e2846245cf86
Size: 28.23 kB - pgaudit-debugsource-18.0-1.module+el9+1167+30043d1f.x86_64.rpm
MD5: 0e8e9cabb74c8bfddb8cdd747b63cad6
SHA-256: 6cebd2c869fc27469573d5a81fc66fab79b43a4f5e52910e398290edcf68c429
Size: 23.51 kB - pg_repack-1.5.3-1.module+el9+1167+30043d1f.x86_64.rpm
MD5: bd4dc3bcb5cb3660dacdd20d3e57183c
SHA-256: 5637996781787a6b150a0c17907de490518a1249f873cf851d412e4310ca62a8
Size: 93.03 kB - pg_repack-debugsource-1.5.3-1.module+el9+1167+30043d1f.x86_64.rpm
MD5: 30e41103eb25206b83985574304d502a
SHA-256: dbed3da8f04b4c6be93d74eaacf132f2935798183452dee6bc335a9f39332c43
Size: 49.40 kB - pgvector-0.8.1-1.module+el9+1167+30043d1f.x86_64.rpm
MD5: d642b2863d0a9bfc1c083d5b5367295b
SHA-256: d869c21382b17bc3e3075e9870d71bddea4d39b17105b2a39cbde70e972f3b0d
Size: 115.41 kB - pgvector-debugsource-0.8.1-1.module+el9+1167+30043d1f.x86_64.rpm
MD5: d45edcb733cde8fdc4d40e48a5fc41c1
SHA-256: 7a9c0648e7773919fa113bb80fce92b55a6330a7850b5d950ffbbbe04c2716d1
Size: 70.97 kB - postgis-3.6.1-2.module+el9+1167+30043d1f.x86_64.rpm
MD5: d940e3b848b8565d20b411bfb0f25ca2
SHA-256: ebbf8786211e5e648bf9e7edf8e8dea12bc862bec478b953acc85a92a53656fc
Size: 1.79 MB - postgis-client-3.6.1-2.module+el9+1167+30043d1f.x86_64.rpm
MD5: 9e590dfe60fd81979ef7a70047b0d2ce
SHA-256: 2f51d62be9ec4dfe048fce1bc095d9fcc7a6496c8282fedda46df7c84ba708b4
Size: 116.37 kB - postgis-debugsource-3.6.1-2.module+el9+1167+30043d1f.x86_64.rpm
MD5: a56fdf815020a27eb0451f6b3d5e9013
SHA-256: 83d65aac2ad32e231e985123df32f857a20029ef0b50252bf514248dee086fa0
Size: 1.07 MB - postgis-docs-3.6.1-2.module+el9+1167+30043d1f.x86_64.rpm
MD5: 089639d8078dd5a8a9ca2887710f4e81
SHA-256: 838112f86ff6c37c08ee863069fa54925cf5854c40b8b4e138ab7bc7fb9a9a58
Size: 7.96 kB - postgis-upgrade-3.6.1-2.module+el9+1167+30043d1f.x86_64.rpm
MD5: 69206b2f052b3a1772d5ae239841630e
SHA-256: df9476e6a3c6b0c5d110374716053684c9601bddd1ae0551d97240ce12a74441
Size: 791.96 kB - postgis-utils-3.6.1-2.module+el9+1167+30043d1f.x86_64.rpm
MD5: 0264f356e84f965f1e87744243ef1d7d
SHA-256: 8b6ec8e13690cae4c76fa5c7456e04f19dc13bf2f57f4fbc80693faaa9225791
Size: 36.51 kB - postgres-decoderbufs-3.3.1-1.Final.module+el9+1167+30043d1f.x86_64.rpm
MD5: c3eaaef085a512a73579448a8477e293
SHA-256: 9840978dc85950d5538f759cfbd6b46f0f4a58e6bcc12e5033eb8054b07f0492
Size: 21.86 kB - postgres-decoderbufs-debugsource-3.3.1-1.Final.module+el9+1167+30043d1f.x86_64.rpm
MD5: 356130d36ab3f6b2d0744714ebaf88e4
SHA-256: a1816d8fd9b89c9ecd9312306cde006663653c8b6062ee8084efbad7339428f3
Size: 16.58 kB - postgresql-18.4-2.module+el9+1167+30043d1f.x86_64.rpm
MD5: 78fcecdfebe4cb44e0545681c585182b
SHA-256: df63a185a0eba911aa0e32a326ac6721d826fdd337981025b51fc068da994e75
Size: 2.05 MB - postgresql-contrib-18.4-2.module+el9+1167+30043d1f.x86_64.rpm
MD5: 21adc0b2780322a3de43ddd360508a15
SHA-256: f3ea7061520c90d3ab656e86ae0c12ce7b215b422baabc9c5d875c3335d207af
Size: 1.08 MB - postgresql-debugsource-18.4-2.module+el9+1167+30043d1f.x86_64.rpm
MD5: d719f5a6a312c2a0fead9c8da1e1b530
SHA-256: d6d5620ab51b29af99a5c3cd01c3028a7c02175cdba42193299a938fa32d88a4
Size: 17.95 MB - postgresql-docs-18.4-2.module+el9+1167+30043d1f.x86_64.rpm
MD5: f09d1ba4a006f7264856c746c7416c65
SHA-256: 0644b315a7d56d89ac0f840d19ecde419c62bc854f1ba0bf1feed90d6659dc29
Size: 2.41 MB - postgresql-plperl-18.4-2.module+el9+1167+30043d1f.x86_64.rpm
MD5: 30ea1a54fb5ca8bdaecff0dd4accea68
SHA-256: 0ed51d5580b3b33fa2fd5f83dfae08cf6b4fe90f12bed1a1839a843b83009e73
Size: 79.66 kB - postgresql-plpython3-18.4-2.module+el9+1167+30043d1f.x86_64.rpm
MD5: 14582c6c050a29c80b9ef0aee3c88556
SHA-256: e1e247dd4774f463d5565fffcd71cc83f0d940c548d5c1497bcb0896f7e3a3e1
Size: 101.33 kB - postgresql-pltcl-18.4-2.module+el9+1167+30043d1f.x86_64.rpm
MD5: 2878e66369b7f721ef7c29dadf52dee1
SHA-256: 8ccd1c9577a7bcc61d3d63da84c609c2da28c88892b2be438c1467d8c7a9bbbb
Size: 53.40 kB - postgresql-private-devel-18.4-2.module+el9+1167+30043d1f.x86_64.rpm
MD5: 6f01449af3987ced142224363e233017
SHA-256: 7bfe55bdc0dfb6c3b842d81b0f824da9a8310bbafe013563b1254c95fdeb4cba
Size: 68.19 kB - postgresql-private-libs-18.4-2.module+el9+1167+30043d1f.x86_64.rpm
MD5: 71d8805807e45309163012dc395aa9e7
SHA-256: 887ed22601566b18fcc37a35492dfaa42541345a08e54d3f496ec59092a1476e
Size: 157.51 kB - postgresql-server-18.4-2.module+el9+1167+30043d1f.x86_64.rpm
MD5: d3d7bcb32693c3cac2145a5d894dd129
SHA-256: 8add6f977634516484a3d9a4426e7362cfb3531beddd8a9822f25a48ec7aa612
Size: 7.48 MB - postgresql-server-devel-18.4-2.module+el9+1167+30043d1f.x86_64.rpm
MD5: dab47c5f3677d32af81040ff38a370d5
SHA-256: c076d5f0469fb13449dad64263bcdf42169001eba09e1687e91b3e95c5bdeec6
Size: 1.62 MB - postgresql-static-18.4-2.module+el9+1167+30043d1f.x86_64.rpm
MD5: 7a43dccd9230854d0fb0a8714d521efe
SHA-256: be79ad1044db33da90055bc7b828de29f5525de62661cf7175bef8f4fd2b53e4
Size: 187.89 kB - postgresql-test-18.4-2.module+el9+1167+30043d1f.x86_64.rpm
MD5: 3818b43dc27bfa1b18d66b1173717cbd
SHA-256: f8c1174d08578cec3e8b211f7096340ba276006726792d028af06ff16001563a
Size: 2.00 MB - postgresql-test-rpm-macros-18.4-2.module+el9+1167+30043d1f.noarch.rpm
MD5: 7c49f693267724eb1c1eb83022da130f
SHA-256: a07a6a4dfa1e9998d9908cd175cff47be1a32df2b9fc8ea295b8b0d0e5c4bd00
Size: 9.23 kB - postgresql-upgrade-18.4-2.module+el9+1167+30043d1f.x86_64.rpm
MD5: 2fefd310fb63ef876f77ab98000c88ae
SHA-256: 6f900641f1f936029afccc65922727c6a74a4c5f23be687131e981aac0b5630d
Size: 5.32 MB - postgresql-upgrade-devel-18.4-2.module+el9+1167+30043d1f.x86_64.rpm
MD5: 9ad5cc35b3edd3c7be94a0b5112fcda9
SHA-256: d5c7243905e7be6ced7790c8c0f493ec0df67a9300b484d0bf8379a3d2ca1ba8
Size: 1.41 MB