Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-6478

Опубликовано: 14 мая 2026
Источник: redhat
CVSS3: 8.2

Описание

Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

A flaw was found in PostgreSQL. This vulnerability, a covert timing channel, exists in the comparison of MD5-hashed passwords during authentication. A remote attacker could exploit this to recover user credentials, gaining unauthorized access to the database. This issue specifically impacts databases that retain MD5-hashed passwords from upgrades of PostgreSQL 13 or earlier.

Меры по смягчению последствий

To mitigate this vulnerability, ensure that all PostgreSQL user passwords are not hashed using MD5. Users should migrate to stronger hashing algorithms such as scram-sha-256. This can be achieved by altering user passwords, which will automatically update their hash to the currently configured default. For example, to change a user's password: ALTER USER username WITH PASSWORD 'new_password'; This action will require users to re-authenticate. If a service relies on these credentials, it may require a restart to pick up the new authentication details.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6postgresqlOut of support scope
Red Hat Enterprise Linux 7postgresqlAffected
Red Hat Enterprise Linux 8postgresqlNot affected
Red Hat Enterprise Linux 8postgresql-jdbcNot affected
Self-service automation portal 2ansible-automation-platform/bootc-automation-portal-rhel9Affected
Red Hat Enterprise Linux 10postgresql18FixedRHSA-2026:2774222.06.2026
Red Hat Enterprise Linux 10postgresql16FixedRHSA-2026:2774322.06.2026
Red Hat Enterprise Linux 10.0 Extended Update Supportpostgresql16FixedRHSA-2026:2771822.06.2026
Red Hat Enterprise Linux 8postgresqlFixedRHSA-2026:2618116.06.2026
Red Hat Enterprise Linux 8libpqFixedRHSA-2026:2773822.06.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-385
https://bugzilla.redhat.com/show_bug.cgi?id=2477447postgresql: PostgreSQL: Credential recovery via covert timing channel in MD5 password comparison

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
3 месяца назад

Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 6.5
nvd
3 месяца назад

Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 6.5
msrc
3 месяца назад

PostgreSQL discloses MD5-hashed passwords via covert timing channel

CVSS3: 6.5
debian
3 месяца назад

Covert timing channel in comparison of MD5-hashed password in PostgreS ...

rocky
около 1 месяца назад

Important: postgresql:13 security update

8.2 High

CVSS3