Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:52395

Опубликовано: 18 авг. 2026
Источник: rocky
Оценка: Important

Описание

Important: postgresql security update

PostgreSQL is an advanced object-relational database management system (DBMS).

Security Fix(es):

  • postgresql: PostgreSQL: Denial of Service via uncontrolled recursion in SSL/GSS negotiation (CVE-2026-6479)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 9

НаименованиеАрхитектураРелизRPM
postgresqlaarch645.el9_8postgresql-13.23-5.el9_8.aarch64.rpm
postgresql-contribaarch645.el9_8postgresql-contrib-13.23-5.el9_8.aarch64.rpm
postgresql-plperlaarch645.el9_8postgresql-plperl-13.23-5.el9_8.aarch64.rpm
postgresql-plpython3aarch645.el9_8postgresql-plpython3-13.23-5.el9_8.aarch64.rpm
postgresql-pltclaarch645.el9_8postgresql-pltcl-13.23-5.el9_8.aarch64.rpm
postgresql-private-libsaarch645.el9_8postgresql-private-libs-13.23-5.el9_8.aarch64.rpm
postgresql-serveraarch645.el9_8postgresql-server-13.23-5.el9_8.aarch64.rpm
postgresql-upgradeaarch645.el9_8postgresql-upgrade-13.23-5.el9_8.aarch64.rpm
postgresqlx86_645.el9_8postgresql-13.23-5.el9_8.x86_64.rpm
postgresql-contribx86_645.el9_8postgresql-contrib-13.23-5.el9_8.x86_64.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL AF_UNIX socket to achieve sustained denial of service. If SSL and GSS are both disabled, an attacker can do the same via access to a PostgreSQL TCP socket. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 7.5
redhat
4 месяца назад

Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL AF_UNIX socket to achieve sustained denial of service. If SSL and GSS are both disabled, an attacker can do the same via access to a PostgreSQL TCP socket. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 7.5
nvd
4 месяца назад

Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL AF_UNIX socket to achieve sustained denial of service. If SSL and GSS are both disabled, an attacker can do the same via access to a PostgreSQL TCP socket. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 7.5
msrc
4 месяца назад

PostgreSQL SSL/GSS init causes denial of service, via uncontrolled recursion

CVSS3: 7.5
debian
4 месяца назад

Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an ...