Количество 60
Количество 60
CVE-2026-6475
Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
CVE-2026-6475
Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
CVE-2026-6475
Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
CVE-2026-6475
PostgreSQL pg_basebackup and pg_rewind can overwrite unrelated files of origin superuser choice
CVE-2026-6475
Symlink following in PostgreSQL pg_basebackup plain format and in pg_r ...
GHSA-7h2q-899j-9636
Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
RLSA-2026:28037
Important: postgresql:15 security update
RLSA-2026:27743
Important: postgresql16 security update
RLSA-2026:27742
Important: postgresql18 security update
RLSA-2026:27738
Important: libpq security update
RLSA-2026:26204
Important: postgresql:18 security update
RLSA-2026:26203
Important: postgresql:16 security update
RLSA-2026:26181
Important: postgresql:15 security update
ELSA-2026-28037
ELSA-2026-28037: postgresql:15 security update (IMPORTANT)
ELSA-2026-27743
ELSA-2026-27743: postgresql16 security update (IMPORTANT)
ELSA-2026-27741
ELSA-2026-27741: postgresql security update (IMPORTANT)
ELSA-2026-27738
ELSA-2026-27738: libpq security update (IMPORTANT)
ELSA-2026-26204
ELSA-2026-26204: postgresql:18 security update (IMPORTANT)
ELSA-2026-26203
ELSA-2026-26203: postgresql:16 security update (IMPORTANT)
RLSA-2026:27741
Important: postgresql security update
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-6475 Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected. | CVSS3: 8.8 | 0% Низкий | 4 месяца назад | |
CVE-2026-6475 Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected. | CVSS3: 6.7 | 0% Низкий | 4 месяца назад | |
CVE-2026-6475 Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected. | CVSS3: 8.8 | 0% Низкий | 4 месяца назад | |
CVE-2026-6475 PostgreSQL pg_basebackup and pg_rewind can overwrite unrelated files of origin superuser choice | CVSS3: 8.8 | 0% Низкий | 4 месяца назад | |
CVE-2026-6475 Symlink following in PostgreSQL pg_basebackup plain format and in pg_r ... | CVSS3: 8.8 | 0% Низкий | 4 месяца назад | |
GHSA-7h2q-899j-9636 Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected. | CVSS3: 8.8 | 0% Низкий | 4 месяца назад | |
RLSA-2026:28037 Important: postgresql:15 security update | 3 месяца назад | |||
RLSA-2026:27743 Important: postgresql16 security update | 3 месяца назад | |||
RLSA-2026:27742 Important: postgresql18 security update | 3 месяца назад | |||
RLSA-2026:27738 Important: libpq security update | 3 месяца назад | |||
RLSA-2026:26204 Important: postgresql:18 security update | 3 месяца назад | |||
RLSA-2026:26203 Important: postgresql:16 security update | 3 месяца назад | |||
RLSA-2026:26181 Important: postgresql:15 security update | 3 месяца назад | |||
ELSA-2026-28037 ELSA-2026-28037: postgresql:15 security update (IMPORTANT) | 3 месяца назад | |||
ELSA-2026-27743 ELSA-2026-27743: postgresql16 security update (IMPORTANT) | около 2 месяцев назад | |||
ELSA-2026-27741 ELSA-2026-27741: postgresql security update (IMPORTANT) | 3 месяца назад | |||
ELSA-2026-27738 ELSA-2026-27738: libpq security update (IMPORTANT) | 3 месяца назад | |||
ELSA-2026-26204 ELSA-2026-26204: postgresql:18 security update (IMPORTANT) | 2 месяца назад | |||
ELSA-2026-26203 ELSA-2026-26203: postgresql:16 security update (IMPORTANT) | 3 месяца назад | |||
RLSA-2026:27741 Important: postgresql security update | около 2 месяцев назад |
Уязвимостей на страницу