Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-6479

Опубликовано: 14 мая 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL AF_UNIX socket to achieve sustained denial of service. If SSL and GSS are both disabled, an attacker can do the same via access to a PostgreSQL TCP socket. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

A flaw was found in PostgreSQL. Uncontrolled recursion during SSL (Secure Sockets Layer) and GSS (Generic Security Service) negotiation allows an attacker to achieve a sustained denial of service. This can be exploited by an attacker with access to a PostgreSQL AF_UNIX socket. If SSL and GSS are both disabled, the same denial of service can be achieved via a PostgreSQL TCP socket.

Отчет

Uncontrolled recursion during PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL socket to trigger sustained CPU/stack exhaustion, resulting in denial of service. This affects the core connection-negotiation path, which runs unconditionally for every incoming connection attempt regardless of configuration — there is no optional feature or code path that must be enabled for exploitation, unlike some other recent flaws in this batch. Fix versions are 18.4, 17.10, 16.14, 15.18, and 14.23; PostgreSQL 12 and 13 branches are not listed as affected by upstream and do not contain the vulnerable recursion path. Affects were determined purely by comparing each shipped build's PostgreSQL version against these per-major-version fix thresholds.

Меры по смягчению последствий

Upgrade to PostgreSQL 18.4, 17.10, 16.14, 15.18, or 14.23 (matching your major version) or later. Restricting network/socket access to trusted clients reduces exposure but does not eliminate the vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6postgresqlNot affected
Red Hat Enterprise Linux 7postgresqlNot affected
Red Hat Enterprise Linux 8postgresql:12/postgresqlNot affected
Red Hat Enterprise Linux 9postgresqlNot affected
Self-service automation portal 2ansible-automation-platform/bootc-automation-portal-rhel9Affected
Red Hat Enterprise Linux 10postgresql18FixedRHSA-2026:2774222.06.2026
Red Hat Enterprise Linux 10postgresql16FixedRHSA-2026:2774322.06.2026
Red Hat Enterprise Linux 10.0 Extended Update Supportpostgresql16FixedRHSA-2026:2771822.06.2026
Red Hat Enterprise Linux 8postgresqlFixedRHSA-2026:2618116.06.2026
Red Hat Enterprise Linux 8postgresqlFixedRHSA-2026:2814323.06.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-606
https://bugzilla.redhat.com/show_bug.cgi?id=2477445postgresql: PostgreSQL: Denial of Service via uncontrolled recursion in SSL/GSS negotiation

EPSS

Процентиль: 38%
0.00471
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL AF_UNIX socket to achieve sustained denial of service. If SSL and GSS are both disabled, an attacker can do the same via access to a PostgreSQL TCP socket. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 7.5
nvd
3 месяца назад

Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL AF_UNIX socket to achieve sustained denial of service. If SSL and GSS are both disabled, an attacker can do the same via access to a PostgreSQL TCP socket. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 7.5
msrc
3 месяца назад

PostgreSQL SSL/GSS init causes denial of service, via uncontrolled recursion

CVSS3: 7.5
debian
3 месяца назад

Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an ...

CVSS3: 7.5
github
3 месяца назад

Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL AF_UNIX socket to achieve sustained denial of service. If SSL and GSS are both disabled, an attacker can do the same via access to a PostgreSQL TCP socket. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

EPSS

Процентиль: 38%
0.00471
Низкий

7.5 High

CVSS3