Описание
ELSA-2026-28208: postgresql:13 security update (IMPORTANT)
pgaudit [1.5.0-1]
- Update to version 1.5.0 Related: #1855776
[1.4.0-4]
- Bump release for rebuild against libpq-12.1-3
[1.4.0-3]
- BuildRequires libpq-devel
[1.4.0-2]
- BuildRequires postgresql-server-devel
[1.4.0-1]
- Update to 1.4.0
[1.3.1-1]
- Update to 1.3.1 and apply patch for pgsql v12 compatibility
[1.2.0-4]
- SCLize the SPEC
[1.2.0-3]
[1.2.0-2]
[1.2.0-1]
- Initial RPM packaging for Fedora
- Based on Devrim Gunduz's packaging for PostgreSQL RPM Repo
pg_repack [1.4.6-3]
- Release bump - enable gating
[1.4.6-2]
- Rebuild
- Resolves:#1954442
[1.4.6-1]
- Rebase to upstream release 1.4.6
[1.4.5-2]
[1.4.5-1]
- Initial packaging
postgres-decoderbufs [0.10.0-2]
- Release bump for rebuild against libpq-12.1-3
- Wed Oct 09 2019 Patrik Novotny <panovotn@redhat.com - 0-10-0-1
- Initial release for upstream version 0.10.0
postgresql [13.23-3]
- Backport fix for CVE-2026-6478 from PostgreSQL 14.23
- Backport fixes for CVE-2026-6637, CVE-2026-6477, CVE-2026-6475, CVE-2026-6473
- Resolves: RHEL-179806
[13.23-2]
- fix CVE-2026-2004 CVE-2026-2005 CVE-2026-2006
[13.23-1]
- Update to 13.23
- Resolves: RHEL-128818 (CVE-2025-12818)
[13.22-1]
- Update to 13.22
[13.20-1]
- Update to 13.20
- Fix CVE-2025-1094
[13.18-1]
- Update to 13.18
- Fixes: CVE-2024-10976 CVE-2024-10978 CVE-2024-10979
[13.16-1]
- Update to 13.16
- Fix CVE-2024-7348
[13.14-1]
- Update to 13.14
- Fix CVE-2024-0985
[13.13-1]
- Update to 13.13
- Fixes: CVE-2023-5868 CVE-2023-5869 CVE-2023-5870 CVE-2023-39417
[13.11-2]
- Update postgresql-setup to 8.7 (https://github.com/devexp-db/postgresql-setup/pull/35)
- Resolves: #2207933
Обновленные пакеты
Oracle Linux 8
Oracle Linux aarch64
Module postgresql:13 is enabled
pg_repack
1.4.6-3.module+el8.9.0+90098+1560b6c2
pgaudit
1.5.0-1.module+el8.9.0+90098+1560b6c2
postgres-decoderbufs
0.10.0-2.module+el8.9.0+90098+1560b6c2
postgresql
13.23-3.module+el8.10.0+90927+50389279
postgresql-contrib
13.23-3.module+el8.10.0+90927+50389279
postgresql-docs
13.23-3.module+el8.10.0+90927+50389279
postgresql-plperl
13.23-3.module+el8.10.0+90927+50389279
postgresql-plpython3
13.23-3.module+el8.10.0+90927+50389279
postgresql-pltcl
13.23-3.module+el8.10.0+90927+50389279
postgresql-server
13.23-3.module+el8.10.0+90927+50389279
postgresql-server-devel
13.23-3.module+el8.10.0+90927+50389279
postgresql-static
13.23-3.module+el8.10.0+90927+50389279
postgresql-test
13.23-3.module+el8.10.0+90927+50389279
postgresql-test-rpm-macros
13.23-3.module+el8.10.0+90927+50389279
postgresql-upgrade
13.23-3.module+el8.10.0+90927+50389279
postgresql-upgrade-devel
13.23-3.module+el8.10.0+90927+50389279
Oracle Linux x86_64
Module postgresql:13 is enabled
pg_repack
1.4.6-3.module+el8.9.0+90098+1560b6c2
pgaudit
1.5.0-1.module+el8.9.0+90098+1560b6c2
postgres-decoderbufs
0.10.0-2.module+el8.9.0+90098+1560b6c2
postgresql
13.23-3.module+el8.10.0+90927+50389279
postgresql-contrib
13.23-3.module+el8.10.0+90927+50389279
postgresql-docs
13.23-3.module+el8.10.0+90927+50389279
postgresql-plperl
13.23-3.module+el8.10.0+90927+50389279
postgresql-plpython3
13.23-3.module+el8.10.0+90927+50389279
postgresql-pltcl
13.23-3.module+el8.10.0+90927+50389279
postgresql-server
13.23-3.module+el8.10.0+90927+50389279
postgresql-server-devel
13.23-3.module+el8.10.0+90927+50389279
postgresql-static
13.23-3.module+el8.10.0+90927+50389279
postgresql-test
13.23-3.module+el8.10.0+90927+50389279
postgresql-test-rpm-macros
13.23-3.module+el8.10.0+90927+50389279
postgresql-upgrade
13.23-3.module+el8.10.0+90927+50389279
postgresql-upgrade-devel
13.23-3.module+el8.10.0+90927+50389279
Связанные CVE
Связанные уязвимости
Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
PostgreSQL discloses MD5-hashed passwords via covert timing channel
Covert timing channel in comparison of MD5-hashed password in PostgreS ...