Описание
ELSA-2026-52395: postgresql security update (IMPORTANT)
[13.23-5]
- Apply patch for CVE-2026-6479 in prep section
- Resolves: CVE-2026-6479
[13.23-4]
- Backport fix for CVE-2026-6479 from PostgreSQL 14.23 (SSL/GSS init causes denial of service via uncontrolled recursion)
- Resolves: CVE-2026-6479
Обновленные пакеты
Oracle Linux 9
Oracle Linux aarch64
postgresql-docs
13.23-5.el9_8
postgresql-private-devel
13.23-5.el9_8
postgresql-server-devel
13.23-5.el9_8
postgresql-static
13.23-5.el9_8
postgresql-test
13.23-5.el9_8
postgresql-test-rpm-macros
13.23-5.el9_8
postgresql-upgrade-devel
13.23-5.el9_8
postgresql
13.23-5.el9_8
postgresql-contrib
13.23-5.el9_8
postgresql-plperl
13.23-5.el9_8
postgresql-plpython3
13.23-5.el9_8
postgresql-pltcl
13.23-5.el9_8
postgresql-private-libs
13.23-5.el9_8
postgresql-server
13.23-5.el9_8
postgresql-upgrade
13.23-5.el9_8
Oracle Linux x86_64
postgresql
13.23-5.el9_8
postgresql-contrib
13.23-5.el9_8
postgresql-plperl
13.23-5.el9_8
postgresql-plpython3
13.23-5.el9_8
postgresql-pltcl
13.23-5.el9_8
postgresql-private-libs
13.23-5.el9_8
postgresql-server
13.23-5.el9_8
postgresql-upgrade
13.23-5.el9_8
postgresql-docs
13.23-5.el9_8
postgresql-private-devel
13.23-5.el9_8
postgresql-server-devel
13.23-5.el9_8
postgresql-static
13.23-5.el9_8
postgresql-test
13.23-5.el9_8
postgresql-test-rpm-macros
13.23-5.el9_8
postgresql-upgrade-devel
13.23-5.el9_8
Связанные CVE
Связанные уязвимости
Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL AF_UNIX socket to achieve sustained denial of service. If SSL and GSS are both disabled, an attacker can do the same via access to a PostgreSQL TCP socket. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL AF_UNIX socket to achieve sustained denial of service. If SSL and GSS are both disabled, an attacker can do the same via access to a PostgreSQL TCP socket. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL AF_UNIX socket to achieve sustained denial of service. If SSL and GSS are both disabled, an attacker can do the same via access to a PostgreSQL TCP socket. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
PostgreSQL SSL/GSS init causes denial of service, via uncontrolled recursion
Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an ...