Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-0525

Опубликовано: 13 янв. 2026
Источник: oracle-oval
Платформа: Oracle Linux 10

Описание

ELSA-2026-0525: postgresql16 security update (MODERATE)

[16.11-1.0.1]

  • Replace upstream reference [Orabug: 37044148]

[16.11-1]

  • Update to 16.11

[16.10-3]

  • Add tmpfiles.d configuration for PostgreSQL 16
  • Ensures proper directory permissions for /var/lib/pgsql

[16.10-2]

  • Add OpenSSL support to upgrade_configure function
  • This ensures upgrade server is compiled with OpenSSL support
  • Required for SSL/TLS connections during database upgrades

Обновленные пакеты

Oracle Linux 10

Oracle Linux aarch64

postgresql

16.11-1.0.1.el10_1

postgresql-contrib

16.11-1.0.1.el10_1

postgresql-docs

16.11-1.0.1.el10_1

postgresql-plperl

16.11-1.0.1.el10_1

postgresql-plpython3

16.11-1.0.1.el10_1

postgresql-pltcl

16.11-1.0.1.el10_1

postgresql-private-devel

16.11-1.0.1.el10_1

postgresql-private-libs

16.11-1.0.1.el10_1

postgresql-server

16.11-1.0.1.el10_1

postgresql-server-devel

16.11-1.0.1.el10_1

postgresql-static

16.11-1.0.1.el10_1

postgresql-test

16.11-1.0.1.el10_1

postgresql-upgrade

16.11-1.0.1.el10_1

postgresql-upgrade-devel

16.11-1.0.1.el10_1

postgresql-test-rpm-macros

16.11-1.0.1.el10_1

Oracle Linux x86_64

postgresql

16.11-1.0.1.el10_1

postgresql-contrib

16.11-1.0.1.el10_1

postgresql-docs

16.11-1.0.1.el10_1

postgresql-plperl

16.11-1.0.1.el10_1

postgresql-plpython3

16.11-1.0.1.el10_1

postgresql-pltcl

16.11-1.0.1.el10_1

postgresql-private-devel

16.11-1.0.1.el10_1

postgresql-private-libs

16.11-1.0.1.el10_1

postgresql-server

16.11-1.0.1.el10_1

postgresql-server-devel

16.11-1.0.1.el10_1

postgresql-static

16.11-1.0.1.el10_1

postgresql-test

16.11-1.0.1.el10_1

postgresql-upgrade

16.11-1.0.1.el10_1

postgresql-upgrade-devel

16.11-1.0.1.el10_1

postgresql-test-rpm-macros

16.11-1.0.1.el10_1

Связанные CVE

Связанные уязвимости

CVSS3: 5.9
ubuntu
3 месяца назад

Integer wraparound in multiple PostgreSQL libpq client library functions allows an application input provider or network peer to cause libpq to undersize an allocation and write out-of-bounds by hundreds of megabytes. This results in a segmentation fault for the application using libpq. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.

CVSS3: 5.9
nvd
3 месяца назад

Integer wraparound in multiple PostgreSQL libpq client library functions allows an application input provider or network peer to cause libpq to undersize an allocation and write out-of-bounds by hundreds of megabytes. This results in a segmentation fault for the application using libpq. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.

CVSS3: 5.9
msrc
3 месяца назад

PostgreSQL libpq undersizes allocations, via integer wraparound

CVSS3: 5.9
debian
3 месяца назад

Integer wraparound in multiple PostgreSQL libpq client library functio ...

rocky
18 дней назад

Moderate: libpq security update