Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-0525

Опубликовано: 13 янв. 2026
Источник: oracle-oval
Платформа: Oracle Linux 10

Описание

ELSA-2026-0525: postgresql16 security update (MODERATE)

[16.11-1.0.1]

  • Replace upstream reference [Orabug: 37044148]

[16.11-1]

  • Update to 16.11

[16.10-3]

  • Add tmpfiles.d configuration for PostgreSQL 16
  • Ensures proper directory permissions for /var/lib/pgsql

[16.10-2]

  • Add OpenSSL support to upgrade_configure function
  • This ensures upgrade server is compiled with OpenSSL support
  • Required for SSL/TLS connections during database upgrades

Обновленные пакеты

Oracle Linux 10

Oracle Linux aarch64

postgresql

16.11-1.0.1.el10_1

postgresql-contrib

16.11-1.0.1.el10_1

postgresql-docs

16.11-1.0.1.el10_1

postgresql-plperl

16.11-1.0.1.el10_1

postgresql-plpython3

16.11-1.0.1.el10_1

postgresql-pltcl

16.11-1.0.1.el10_1

postgresql-private-devel

16.11-1.0.1.el10_1

postgresql-private-libs

16.11-1.0.1.el10_1

postgresql-server

16.11-1.0.1.el10_1

postgresql-server-devel

16.11-1.0.1.el10_1

postgresql-static

16.11-1.0.1.el10_1

postgresql-test

16.11-1.0.1.el10_1

postgresql-upgrade

16.11-1.0.1.el10_1

postgresql-upgrade-devel

16.11-1.0.1.el10_1

postgresql-test-rpm-macros

16.11-1.0.1.el10_1

Oracle Linux x86_64

postgresql

16.11-1.0.1.el10_1

postgresql-contrib

16.11-1.0.1.el10_1

postgresql-docs

16.11-1.0.1.el10_1

postgresql-plperl

16.11-1.0.1.el10_1

postgresql-plpython3

16.11-1.0.1.el10_1

postgresql-pltcl

16.11-1.0.1.el10_1

postgresql-private-devel

16.11-1.0.1.el10_1

postgresql-private-libs

16.11-1.0.1.el10_1

postgresql-server

16.11-1.0.1.el10_1

postgresql-server-devel

16.11-1.0.1.el10_1

postgresql-static

16.11-1.0.1.el10_1

postgresql-test

16.11-1.0.1.el10_1

postgresql-upgrade

16.11-1.0.1.el10_1

postgresql-upgrade-devel

16.11-1.0.1.el10_1

postgresql-test-rpm-macros

16.11-1.0.1.el10_1

Связанные CVE

Связанные уязвимости

CVSS3: 5.9
ubuntu
10 месяцев назад

Integer wraparound in multiple PostgreSQL libpq client library functions allows an application input provider or network peer to cause libpq to undersize an allocation and write out-of-bounds by hundreds of megabytes. This results in a segmentation fault for the application using libpq. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.

CVSS3: 7.5
redhat
10 месяцев назад

Integer wraparound in multiple PostgreSQL libpq client library functions allows an application input provider or network peer to cause libpq to undersize an allocation and write out-of-bounds by hundreds of megabytes. This results in a segmentation fault for the application using libpq. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.

CVSS3: 5.9
nvd
10 месяцев назад

Integer wraparound in multiple PostgreSQL libpq client library functions allows an application input provider or network peer to cause libpq to undersize an allocation and write out-of-bounds by hundreds of megabytes. This results in a segmentation fault for the application using libpq. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.

CVSS3: 5.9
msrc
10 месяцев назад

PostgreSQL libpq undersizes allocations, via integer wraparound

CVSS3: 5.9
debian
10 месяцев назад

Integer wraparound in multiple PostgreSQL libpq client library functio ...