postgresql:16 security update
エラータID: AXSA:2026-1358:01
リリース日:
2026/07/28 Tuesday - 09:11
題名:
postgresql:16 security update
影響のあるチャネル:
MIRACLE LINUX 9 for x86_64
Severity:
High
Description:
以下項目について対処しました。
[Security Fix]
- PostgreSQL には、整数オーバーフローの問題があるため、リモート
の攻撃者により、PostgreSQL を実行しているユーザーの権限での任意
のコードの実行、およびサービス拒否攻撃を可能とする脆弱性が存在
します。(CVE-2026-6473)
- PostgreSQL には、シンボリックリンクの解釈処理に問題があるため、
ローカルの攻撃者により、情報の漏洩、データ破壊、およびサービス
拒否攻撃を可能とする脆弱性が存在します。(CVE-2026-6475)
- PostgreSQL の libpq の lo_export() 関数、lo_read() 関数、
lo_lseek64() 関数、lo_tell64() 関数には、バッファオーバーフローの
問題があるため、リモートの攻撃者により、任意のコードの実行を可能
とする脆弱性が存在します。(CVE-2026-6477)
- PostgreSQL には、タイミングサイドチャネル攻撃が可能となって
しまう問題があるため、リモートの攻撃者により、情報の漏洩、および
データ破壊を可能とする脆弱性が存在します。(CVE-2026-6478)
Modularity name: postgresql
Stream name: 16
解決策:
パッケージをアップデートしてください。
CVE:
CVE-2026-6473
Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds. This may execute arbitrary code as the operating system user running the database. In applications that pass gigabyte-scale user inputs to the relevant database functions, the application input provider may achieve a segmentation fault. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds. This may execute arbitrary code as the operating system user running the database. In applications that pass gigabyte-scale user inputs to the relevant database functions, the application input provider may achieve a segmentation fault. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
CVE-2026-6475
Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
CVE-2026-6477
Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
CVE-2026-6478
Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
追加情報:
N/A
ダウンロード:
SRPMS
- pgaudit-16.0-1.module+el9+1166+c1810413.src.rpm
MD5: 938dca7f7b786279503e93132a2f2a1d
SHA-256: 9827a4c99307c5b87b2276158c793237c0ca57bd8641483d8846feb859855c5d
Size: 52.79 kB - pg_repack-1.5.1-1.module+el9+1166+c1810413.src.rpm
MD5: 35871cdf81e3ad8f492bd5fcf8f30502
SHA-256: bd6f73e1048f0c69773d00f1ae3aec28ba9a2d3c8c80bbfca0fd496a6e3dd7a1
Size: 105.44 kB - pgvector-0.6.2-2.module+el9+1166+c1810413.src.rpm
MD5: 4546d12f59a6bc08737004b53be3b41f
SHA-256: 06d3155eef8eb97354ef3bc55967ba7dbf15791d0804c69413338830ecfbdcd1
Size: 87.64 kB - postgis-3.5.3-5.module+el9+1166+c1810413.src.rpm
MD5: 2636922b22fb11b4759c598bbd5e0c79
SHA-256: 96c34403a33abf90aec7cbe8a47c48d9f2394af6479251bd33ae934ddb56c6d4
Size: 19.04 MB - postgres-decoderbufs-2.4.0-1.Final.module+el9+1166+c1810413.src.rpm
MD5: d7a1f50587409b5ad3d2cb4383e802e9
SHA-256: af9e98be4e3b6f48f1eaa12ea598f7a8be859023d193f8365310df0a4eed34ed
Size: 21.46 kB - postgresql-16.14-1.module+el9+1166+c1810413.src.rpm
MD5: 600f65a6cb7e78cfb28fee43664f24c2
SHA-256: 7a0fa4fa30259ff69c9f9893c559e4192a7c9d8305a3f2318d37bb2ff5392fdd
Size: 46.20 MB
Asianux Server 9 for x86_64
- pgaudit-16.0-1.module+el9+1166+c1810413.x86_64.rpm
MD5: 1888308a8e0b2e8ed9d610ecd6013137
SHA-256: 375dfccca19e14f904166f02bd9bba63373b8f3956c7d72a9bd15223193b055d
Size: 27.64 kB - pgaudit-debugsource-16.0-1.module+el9+1166+c1810413.x86_64.rpm
MD5: fbed2a01cfadc83cc0094e999f4987b0
SHA-256: 5477192a6f7037f1e3f1087618909e1e335c093be4cd8142f01f40522fbdb32b
Size: 22.84 kB - pg_repack-1.5.1-1.module+el9+1166+c1810413.x86_64.rpm
MD5: 02727546613fa6f96a51de846ead202c
SHA-256: 36b07d241e0550e82199aebffaf20c0dd7555e1f6c3a3d5432be644ee92cc9ac
Size: 92.51 kB - pg_repack-debugsource-1.5.1-1.module+el9+1166+c1810413.x86_64.rpm
MD5: af60fb97063e04b87e43b874747a05cb
SHA-256: 3a65b4d6b2db32aa3b2426d9a0e7e7a4a28e25d441f52ef50e2a94ecbd2af59c
Size: 49.03 kB - pgvector-0.6.2-2.module+el9+1166+c1810413.x86_64.rpm
MD5: fa96e8b7f118c45d0be7f2418a407f2a
SHA-256: c87e31af5a0cb4b4cd1338b5e004a1e55aac34d74579c5b5968f3bf64193731b
Size: 80.64 kB - pgvector-debugsource-0.6.2-2.module+el9+1166+c1810413.x86_64.rpm
MD5: 8fbb5625a6db32be74f5081e5f4af552
SHA-256: e04616a6dde340883ed3b1e3f3fc7a071fe384caaa2c1bd966f2e58d6c31c3af
Size: 54.87 kB - postgis-3.5.3-5.module+el9+1166+c1810413.x86_64.rpm
MD5: 514f3f17ec2597ad45e70fb4c5966076
SHA-256: 1e9f778d7fc3af8636eb7afbeb9052a78131c1f26927ebc2ff6cfe2b8cda315b
Size: 2.00 MB - postgis-client-3.5.3-5.module+el9+1166+c1810413.x86_64.rpm
MD5: 10283ec3b7040b8ded3fa590cddb828c
SHA-256: 66bdb1b3d5326e8c922d93c5fc0403f6833a254825d4ded4a9c7c3be1b7d9921
Size: 148.61 kB - postgis-debugsource-3.5.3-5.module+el9+1166+c1810413.x86_64.rpm
MD5: 2de017928adaeb23693e1f525f88269b
SHA-256: a3d88248bd539bb913b2eeb56582283d374441d15d2266464b6d3ef336299bf6
Size: 1.24 MB - postgis-docs-3.5.3-5.module+el9+1166+c1810413.x86_64.rpm
MD5: 31eaae3d6ea028f310a2bc1ab9b2eb10
SHA-256: a12246d803a3c09d289c348192e2896767e19e4033691d6832fb92c7bcc5b747
Size: 4.85 MB - postgis-upgrade-3.5.3-5.module+el9+1166+c1810413.x86_64.rpm
MD5: 50ca425ff6bebafe1cef0d55342e654e
SHA-256: ddb9da9a12c521d6883163fb147d68fc7d901c3b5f32ab86a29e68ac5d4f88d3
Size: 971.97 kB - postgis-utils-3.5.3-5.module+el9+1166+c1810413.x86_64.rpm
MD5: 4fca9d3a20407872d7e5fc510eca1d12
SHA-256: 692d94404ed817efb0d17129197e8b4ab654b2934c1e61185bd4e9b801fd2779
Size: 34.47 kB - postgres-decoderbufs-2.4.0-1.Final.module+el9+1166+c1810413.x86_64.rpm
MD5: 3baf569b7d83a71e67a91a53620aa7f0
SHA-256: 831e3b638bbf4a45296e6e82b987e6b143205b194f2baae886a0f7cd4b22b9de
Size: 21.83 kB - postgres-decoderbufs-debugsource-2.4.0-1.Final.module+el9+1166+c1810413.x86_64.rpm
MD5: a1b538ea900ac14f5c6f200d87c02749
SHA-256: fcf64828eb81bd199864097512b71ce1fe86aaf4fee5302d057bdf9077e09273
Size: 16.55 kB - postgresql-16.14-1.module+el9+1166+c1810413.x86_64.rpm
MD5: e2fd99671b87f04bf3c137cf10ad191c
SHA-256: 2a496e2fb7605222a9e3aebff2fca33e430213cda6a9593c664707e76f7778ea
Size: 1.96 MB - postgresql-contrib-16.14-1.module+el9+1166+c1810413.x86_64.rpm
MD5: 99957cd0c2debe6a87823c2af2745b24
SHA-256: 1858171abcbc86e30c368f26dea965bd3d9f3292680af96ddba2e372262bbb21
Size: 1.01 MB - postgresql-debugsource-16.14-1.module+el9+1166+c1810413.x86_64.rpm
MD5: 73f25282cd957404841f4275d0e1688a
SHA-256: da4e55051182b71395e6c44fcb716e9f5e315c3ee2cdee8036234a3b76b54cc8
Size: 17.02 MB - postgresql-docs-16.14-1.module+el9+1166+c1810413.x86_64.rpm
MD5: 0afc09679d8c4d76a2e6f3b53ffbb39c
SHA-256: bb8765abea726335f785004d7779e861dc7fefb7b03c170e5ad9cdd58bc47d5d
Size: 2.37 MB - postgresql-plperl-16.14-1.module+el9+1166+c1810413.x86_64.rpm
MD5: d462c206acad67371107ec997d37bd78
SHA-256: fbef9521da9bf1f485ad89b2535da8ea4f4c0e359fbeb0e8cb32f02fd71c87da
Size: 80.48 kB - postgresql-plpython3-16.14-1.module+el9+1166+c1810413.x86_64.rpm
MD5: c6facf4ca643ee07b3cab0d7b81fe1cc
SHA-256: 0c2f9c7b65bb37391b96ac9e53c47b1ab7d0b9e6316d21cab0849ee108d5fba9
Size: 102.94 kB - postgresql-pltcl-16.14-1.module+el9+1166+c1810413.x86_64.rpm
MD5: 1593928e27fcfaed812737c2d570157c
SHA-256: 4eaf5dc662f256538bd7a7ca8336733ef419a213e6b304bfca323c5ecc7d7402
Size: 53.48 kB - postgresql-private-devel-16.14-1.module+el9+1166+c1810413.x86_64.rpm
MD5: 75d8d8841f1cde6035338d84208fe361
SHA-256: 66691c649ae554541befb84db25a618f0f57f9b3f50be1fedebdba2fef88360e
Size: 66.33 kB - postgresql-private-libs-16.14-1.module+el9+1166+c1810413.x86_64.rpm
MD5: 94c18b06edee2c19e2d72b65a1ebe275
SHA-256: 93062355eee631d7c707c9a22129c271d4012e83c8ce8527649d6a92fd258700
Size: 143.21 kB - postgresql-server-16.14-1.module+el9+1166+c1810413.x86_64.rpm
MD5: ca1f8b534be56297669790e9cf57bc8a
SHA-256: fa79cd9266aecc1c2df0a7ceb304f61bdb0768aa1ebea597c7130f1018345d81
Size: 6.98 MB - postgresql-server-devel-16.14-1.module+el9+1166+c1810413.x86_64.rpm
MD5: 88965c58f2cb7100f6d248c7f167d2b5
SHA-256: f1c5287161305a27256143b7d406062cf8f6a5c31319b12a0a285b530d180ef7
Size: 1.49 MB - postgresql-static-16.14-1.module+el9+1166+c1810413.x86_64.rpm
MD5: 6b40eea0f3943d249661ad1d8740d7c8
SHA-256: 2599990ab8af70f4afc79d0d269832206d6a0e41d06b525bd7f01e970e60b0b0
Size: 132.44 kB - postgresql-test-16.14-1.module+el9+1166+c1810413.x86_64.rpm
MD5: ff28981823bf5798a8d73407f5616ad0
SHA-256: b672152cdfa327e5d92183e65423e58d3df8fa1863d0731d0555394acfaba614
Size: 1.80 MB - postgresql-test-rpm-macros-16.14-1.module+el9+1166+c1810413.noarch.rpm
MD5: 07b2e9025a91130310dcade585b8f6db
SHA-256: 7cc6fa794973fdbca51b86c093899d4a06b92c3d187fdc9e9a1c809e79f09cde
Size: 9.67 kB - postgresql-upgrade-16.14-1.module+el9+1166+c1810413.x86_64.rpm
MD5: 3b067ce178de55ddea1c31e3161fb8a4
SHA-256: 2f9fa5e0cb69a8cbce6ca57b8b97a6916019ffd7885216cb0bdf3868859ed6f4
Size: 5.15 MB - postgresql-upgrade-devel-16.14-1.module+el9+1166+c1810413.x86_64.rpm
MD5: 782c6d397db6a736d2485b07f17bcfaa
SHA-256: 8cc29480d39c7074ae7b14fc773a6fca58c670869d8ea2edf2de8b45819bbdb1
Size: 1.38 MB