Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:28208

Опубликовано: 23 июн. 2026
Источник: rocky
Оценка: Important

Описание

Important: postgresql:13 security update

PostgreSQL is an advanced object-relational database management system (DBMS).

Security Fix(es):

  • postgresql: PostgreSQL: Credential recovery via covert timing channel in MD5 password comparison (CVE-2026-6478)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
pgauditaarch641.module+el8.10.0+40055+b85d5ce2pgaudit-1.5.0-1.module+el8.10.0+40055+b85d5ce2.aarch64.rpm
pg_repackaarch643.module+el8.10.0+40055+b85d5ce2pg_repack-1.4.6-3.module+el8.10.0+40055+b85d5ce2.aarch64.rpm
pg_repackaarch643.module+el8.10.0+1862+29bef648pg_repack-1.4.6-3.module+el8.10.0+1862+29bef648.aarch64.rpm
postgres-decoderbufsaarch642.module+el8.10.0+40055+b85d5ce2postgres-decoderbufs-0.10.0-2.module+el8.10.0+40055+b85d5ce2.aarch64.rpm
postgres-decoderbufsaarch642.module+el8.10.0+1862+29bef648postgres-decoderbufs-0.10.0-2.module+el8.10.0+1862+29bef648.aarch64.rpm
postgresqlaarch643.module+el8.10.0+40216+e5e48d6cpostgresql-13.23-3.module+el8.10.0+40216+e5e48d6c.aarch64.rpm
postgresql-contribaarch643.module+el8.10.0+40216+e5e48d6cpostgresql-contrib-13.23-3.module+el8.10.0+40216+e5e48d6c.aarch64.rpm
postgresql-docsaarch643.module+el8.10.0+40216+e5e48d6cpostgresql-docs-13.23-3.module+el8.10.0+40216+e5e48d6c.aarch64.rpm
postgresql-plperlaarch643.module+el8.10.0+40216+e5e48d6cpostgresql-plperl-13.23-3.module+el8.10.0+40216+e5e48d6c.aarch64.rpm
postgresql-plpython3aarch643.module+el8.10.0+40216+e5e48d6cpostgresql-plpython3-13.23-3.module+el8.10.0+40216+e5e48d6c.aarch64.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 6.5
ubuntu
4 месяца назад

Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 8.2
redhat
4 месяца назад

Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 6.5
nvd
4 месяца назад

Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 6.5
msrc
4 месяца назад

PostgreSQL discloses MD5-hashed passwords via covert timing channel

CVSS3: 6.5
debian
4 месяца назад

Covert timing channel in comparison of MD5-hashed password in PostgreS ...