Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:52396

Опубликовано: 18 авг. 2026
Источник: rocky
Оценка: Important

Описание

Important: postgresql:12 security update

PostgreSQL is an advanced object-relational database management system (DBMS).

Security Fix(es):

  • postgresql: PostgreSQL: Denial of Service via uncontrolled recursion in SSL/GSS negotiation (CVE-2026-6479)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
pgauditaarch647.module+el8.9.0+1735+a332307bpgaudit-1.4.0-7.module+el8.9.0+1735+a332307b.aarch64.rpm
pg_repackaarch643.module+el8.9.0+1594+4a6adae9pg_repack-1.4.6-3.module+el8.9.0+1594+4a6adae9.aarch64.rpm
pg_repackaarch643.module+el8.10.0+1862+29bef648pg_repack-1.4.6-3.module+el8.10.0+1862+29bef648.aarch64.rpm
pg_repackaarch643.module+el8.9.0+1603+444d1b54pg_repack-1.4.6-3.module+el8.9.0+1603+444d1b54.aarch64.rpm
pg_repackaarch643.module+el8.10.0+40055+b85d5ce2pg_repack-1.4.6-3.module+el8.10.0+40055+b85d5ce2.aarch64.rpm
postgres-decoderbufsaarch642.module+el8.10.0+1862+29bef648postgres-decoderbufs-0.10.0-2.module+el8.10.0+1862+29bef648.aarch64.rpm
postgres-decoderbufsaarch642.module+el8.9.0+1603+444d1b54postgres-decoderbufs-0.10.0-2.module+el8.9.0+1603+444d1b54.aarch64.rpm
postgres-decoderbufsaarch642.module+el8.9.0+1594+4a6adae9postgres-decoderbufs-0.10.0-2.module+el8.9.0+1594+4a6adae9.aarch64.rpm
postgres-decoderbufsaarch642.module+el8.10.0+40055+b85d5ce2postgres-decoderbufs-0.10.0-2.module+el8.10.0+40055+b85d5ce2.aarch64.rpm
postgresqlaarch649.module+el8.10.0+40272+1a01806bpostgresql-12.22-9.module+el8.10.0+40272+1a01806b.aarch64.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL AF_UNIX socket to achieve sustained denial of service. If SSL and GSS are both disabled, an attacker can do the same via access to a PostgreSQL TCP socket. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 7.5
redhat
4 месяца назад

Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL AF_UNIX socket to achieve sustained denial of service. If SSL and GSS are both disabled, an attacker can do the same via access to a PostgreSQL TCP socket. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 7.5
nvd
4 месяца назад

Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL AF_UNIX socket to achieve sustained denial of service. If SSL and GSS are both disabled, an attacker can do the same via access to a PostgreSQL TCP socket. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 7.5
msrc
4 месяца назад

PostgreSQL SSL/GSS init causes denial of service, via uncontrolled recursion

CVSS3: 7.5
debian
4 месяца назад

Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an ...