Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-14681

Опубликовано: 13 авг. 2026
Источник: redhat
CVSS3: 4.2

Описание

Improper enforcement of message integrity in PostgreSQL GSSAPI support allows a user to negotiate GSSAPI contrary to pg_hba.conf rules, via initial direct TLS connection. Despite a pg_hba.conf that appears to require GSSAPI, the connection may exchange data over TLS encryption alone. If the TLS settings are more permissive than the GSS settings, the connection may continue with lesser protection. Within major versions 17-18, minor versions before PostgreSQL 18.5 and 17.11 are affected. Versions before PostgreSQL 17 are unaffected.

A flaw was found in PostgreSQL. Improper enforcement of message integrity in PostgreSQL's GSSAPI (Generic Security Service Application Program Interface) support allows a user to negotiate GSSAPI contrary to pg_hba.conf rules by initiating a direct TLS (Transport Layer Security) connection. This enables the connection to proceed with only TLS encryption, even when GSSAPI is required. If the TLS settings are less secure than the GSSAPI settings, the connection may operate with reduced protection, potentially leading to information disclosure or integrity compromise.

Отчет

This Moderate severity flaw in PostgreSQL's GSSAPI support allows a remote, authenticated attacker with low privileges to bypass pg_hba.conf rules requiring GSSAPI encryption. By initiating a direct TLS connection, the attacker can force a less secure connection if TLS settings are more permissive, potentially compromising data integrity and confidentiality. The high attack complexity reduces the overall risk.

Меры по смягчению последствий

To mitigate the risk associated with this flaw, restrict network access to the PostgreSQL server to only trusted hosts and networks. This reduces the attack surface and limits the ability of unauthorized users to establish connections that could bypass GSSAPI enforcement via direct TLS. Warning: Restricting network access may impact legitimate client connections if not configured carefully. Changes to firewall rules or network configurations may require a service reload or restart to take effect.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10postgresql16Not affected
Red Hat Enterprise Linux 10postgresql18Fix deferred
Red Hat Enterprise Linux 6postgresqlNot affected
Red Hat Enterprise Linux 7postgresqlNot affected
Red Hat Enterprise Linux 8postgresql:12/postgresqlNot affected
Red Hat Enterprise Linux 8postgresql:15/postgresqlNot affected
Red Hat Enterprise Linux 8postgresql:16/postgresqlNot affected
Red Hat Enterprise Linux 9postgresqlNot affected
Red Hat Enterprise Linux 9postgresql:15/postgresqlNot affected
Red Hat Enterprise Linux 9postgresql:16/postgresqlNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-924
https://bugzilla.redhat.com/show_bug.cgi?id=2515315postgresql: PostgreSQL: Improper enforcement of GSSAPI encryption via direct TLS connection

4.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.2
ubuntu
около 1 месяца назад

Improper enforcement of message integrity in PostgreSQL GSSAPI support allows a user to negotiate GSSAPI contrary to pg_hba.conf rules, via initial direct TLS connection. Despite a pg_hba.conf that appears to require GSSAPI, the connection may exchange data over TLS encryption alone. If the TLS settings are more permissive than the GSS settings, the connection may continue with lesser protection. Within major versions 17-18, minor versions before PostgreSQL 18.6 and 17.11 are affected. Versions before PostgreSQL 17 are unaffected.

CVSS3: 4.2
nvd
около 1 месяца назад

Improper enforcement of message integrity in PostgreSQL GSSAPI support allows a user to negotiate GSSAPI contrary to pg_hba.conf rules, via initial direct TLS connection. Despite a pg_hba.conf that appears to require GSSAPI, the connection may exchange data over TLS encryption alone. If the TLS settings are more permissive than the GSS settings, the connection may continue with lesser protection. Within major versions 17-18, minor versions before PostgreSQL 18.6 and 17.11 are affected. Versions before PostgreSQL 17 are unaffected.

CVSS3: 4.2
debian
около 1 месяца назад

Improper enforcement of message integrity in PostgreSQL GSSAPI support ...

CVSS3: 4.2
github
около 1 месяца назад

Improper enforcement of message integrity in PostgreSQL GSSAPI support allows a user to negotiate GSSAPI contrary to pg_hba.conf rules, via initial direct TLS connection. Despite a pg_hba.conf that appears to require GSSAPI, the connection may exchange data over TLS encryption alone. If the TLS settings are more permissive than the GSS settings, the connection may continue with lesser protection. Within major versions 17-18, minor versions before PostgreSQL 18.5 and 17.11 are affected. Versions before PostgreSQL 17 are unaffected.

CVSS3: 5
fstec
около 1 месяца назад

Уязвимость компонента GSSAPI системы управления базами данных PostgreSQL, связанная с ошибками смешения типов данных, позволяющая нарушителю проводить атаки типа "человек посередине"

4.2 Medium

CVSS3