Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-52395

Опубликовано: 11 авг. 2026
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2026-52395: postgresql security update (IMPORTANT)

[13.23-5]

  • Apply patch for CVE-2026-6479 in prep section
  • Resolves: CVE-2026-6479

[13.23-4]

  • Backport fix for CVE-2026-6479 from PostgreSQL 14.23 (SSL/GSS init causes denial of service via uncontrolled recursion)
  • Resolves: CVE-2026-6479

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

postgresql-docs

13.23-5.el9_8

postgresql-private-devel

13.23-5.el9_8

postgresql-server-devel

13.23-5.el9_8

postgresql-static

13.23-5.el9_8

postgresql-test

13.23-5.el9_8

postgresql-test-rpm-macros

13.23-5.el9_8

postgresql-upgrade-devel

13.23-5.el9_8

postgresql

13.23-5.el9_8

postgresql-contrib

13.23-5.el9_8

postgresql-plperl

13.23-5.el9_8

postgresql-plpython3

13.23-5.el9_8

postgresql-pltcl

13.23-5.el9_8

postgresql-private-libs

13.23-5.el9_8

postgresql-server

13.23-5.el9_8

postgresql-upgrade

13.23-5.el9_8

Oracle Linux x86_64

postgresql

13.23-5.el9_8

postgresql-contrib

13.23-5.el9_8

postgresql-plperl

13.23-5.el9_8

postgresql-plpython3

13.23-5.el9_8

postgresql-pltcl

13.23-5.el9_8

postgresql-private-libs

13.23-5.el9_8

postgresql-server

13.23-5.el9_8

postgresql-upgrade

13.23-5.el9_8

postgresql-docs

13.23-5.el9_8

postgresql-private-devel

13.23-5.el9_8

postgresql-server-devel

13.23-5.el9_8

postgresql-static

13.23-5.el9_8

postgresql-test

13.23-5.el9_8

postgresql-test-rpm-macros

13.23-5.el9_8

postgresql-upgrade-devel

13.23-5.el9_8

Связанные CVE

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL AF_UNIX socket to achieve sustained denial of service. If SSL and GSS are both disabled, an attacker can do the same via access to a PostgreSQL TCP socket. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 7.5
redhat
4 месяца назад

Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL AF_UNIX socket to achieve sustained denial of service. If SSL and GSS are both disabled, an attacker can do the same via access to a PostgreSQL TCP socket. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 7.5
nvd
4 месяца назад

Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL AF_UNIX socket to achieve sustained denial of service. If SSL and GSS are both disabled, an attacker can do the same via access to a PostgreSQL TCP socket. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 7.5
msrc
4 месяца назад

PostgreSQL SSL/GSS init causes denial of service, via uncontrolled recursion

CVSS3: 7.5
debian
4 месяца назад

Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an ...