Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:28208

Опубликовано: 23 июн. 2026
Источник: rocky
Оценка: Important

Описание

Important: postgresql:13 security update

PostgreSQL is an advanced object-relational database management system (DBMS).

Security Fix(es):

  • postgresql: PostgreSQL: Credential recovery via covert timing channel in MD5 password comparison (CVE-2026-6478)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
pgauditx86_641.module+el8.10.0+40055+b85d5ce2pgaudit-1.5.0-1.module+el8.10.0+40055+b85d5ce2.x86_64.rpm
pg_repackx86_643.module+el8.10.0+1862+29bef648pg_repack-1.4.6-3.module+el8.10.0+1862+29bef648.x86_64.rpm
pg_repackx86_643.module+el8.10.0+40055+b85d5ce2pg_repack-1.4.6-3.module+el8.10.0+40055+b85d5ce2.x86_64.rpm
postgres-decoderbufsx86_642.module+el8.10.0+40055+b85d5ce2postgres-decoderbufs-0.10.0-2.module+el8.10.0+40055+b85d5ce2.x86_64.rpm
postgres-decoderbufsx86_642.module+el8.10.0+1862+29bef648postgres-decoderbufs-0.10.0-2.module+el8.10.0+1862+29bef648.x86_64.rpm
postgresqlx86_643.module+el8.10.0+40216+e5e48d6cpostgresql-13.23-3.module+el8.10.0+40216+e5e48d6c.x86_64.rpm
postgresql-contribx86_643.module+el8.10.0+40216+e5e48d6cpostgresql-contrib-13.23-3.module+el8.10.0+40216+e5e48d6c.x86_64.rpm
postgresql-docsx86_643.module+el8.10.0+40216+e5e48d6cpostgresql-docs-13.23-3.module+el8.10.0+40216+e5e48d6c.x86_64.rpm
postgresql-plperlx86_643.module+el8.10.0+40216+e5e48d6cpostgresql-plperl-13.23-3.module+el8.10.0+40216+e5e48d6c.x86_64.rpm
postgresql-plpython3x86_643.module+el8.10.0+40216+e5e48d6cpostgresql-plpython3-13.23-3.module+el8.10.0+40216+e5e48d6c.x86_64.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 6.5
ubuntu
3 месяца назад

Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 8.2
redhat
3 месяца назад

Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 6.5
nvd
3 месяца назад

Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 6.5
msrc
3 месяца назад

PostgreSQL discloses MD5-hashed passwords via covert timing channel

CVSS3: 6.5
debian
3 месяца назад

Covert timing channel in comparison of MD5-hashed password in PostgreS ...