[ALSA-2026:28037] Important: postgresql:15 security update
Type:
security
Severity:
important
Release date:
2026-07-02
Description:
PostgreSQL is an advanced object-relational database management system (DBMS). Security Fix(es): * postgresql: PostgreSQL: Operating system account hijack via symlink following in pg_basebackup and pg_rewind (CVE-2026-6475) * postgresql: PostgreSQL libpq: Buffer overflow allows server superuser to overwrite client stack memory (CVE-2026-6477) * postgresql: PostgreSQL: Credential recovery via covert timing channel in MD5 password comparison (CVE-2026-6478) * postgresql: integer overflow can cause an undersized allocation and an out-of-bounds write (CVE-2026-6473) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 pg_repack-1.4.8-2.module_el9.5.0+119+18833d03.aarch64.rpm 19553c3fc3bd024a194094278ed7a9ffedac41a85e58d03273bd757cfe8687e3
aarch64 postgresql-upgrade-devel-15.18-1.module_el9.8.0+267+7c71b4a4.aarch64.rpm 38a33dbf29fe503c316645d70201c0bd1e744ab03f2326ef5d53c75f4bb792fd
aarch64 postgresql-test-15.18-1.module_el9.8.0+267+7c71b4a4.aarch64.rpm 4ebf117fefa06c997de0870f0c96614e18fd7df7fbd09a9562869f76febdd3dc
aarch64 postgresql-private-libs-15.18-1.module_el9.8.0+267+7c71b4a4.aarch64.rpm 5ae16a0f36a303186f028e7bc1c6214007a3199320f28f5884e77d5a50ee2c82
aarch64 postgresql-pltcl-15.18-1.module_el9.8.0+267+7c71b4a4.aarch64.rpm 5edf5220e0338ec990c656a8ee7a9e2b46c54de3b57361313283023fceda7164
aarch64 postgresql-upgrade-15.18-1.module_el9.8.0+267+7c71b4a4.aarch64.rpm 6c9fd3596f6485c72c0853b387e22a89b6636ffac14b63b3885a2aeaba424cc1
aarch64 postgresql-plperl-15.18-1.module_el9.8.0+267+7c71b4a4.aarch64.rpm 6ebe22336fd413689f62dd616c82d764463e4b82f70ededf0bfd6a0111d2023a
aarch64 postgresql-15.18-1.module_el9.8.0+267+7c71b4a4.aarch64.rpm 7093fc0468f9bbd85d8f7086ed99c169ce79d58728104e2e7c19e78ad37bb43f
aarch64 postgres-decoderbufs-1.9.7-1.Final.module_el9.3.0+52+21733919.aarch64.rpm 70c3cc4d5f24674cf5e9caf97e7c16b4898e6c3f6c976f6e2d4cc4f64967816e
aarch64 postgresql-static-15.18-1.module_el9.8.0+267+7c71b4a4.aarch64.rpm 8a89069f2c5c6b7e59bf0fedf3f5745e15ffcd86deb5b2543bce6a9c07398719
aarch64 postgresql-plpython3-15.18-1.module_el9.8.0+267+7c71b4a4.aarch64.rpm 8cd718359308be776c1d3312f2c7984ce70383cfa3bf224c4e729c67e6041e83
aarch64 postgresql-contrib-15.18-1.module_el9.8.0+267+7c71b4a4.aarch64.rpm ab0ef578c88637f4f85deec29ac25eeeeb7997190ffef27466e04d52f2adde21
aarch64 postgresql-private-devel-15.18-1.module_el9.8.0+267+7c71b4a4.aarch64.rpm c40aa5d6cce20ff50deceb5e7193b4763af0f5810f14aa27fc14162e23cbfded
aarch64 postgresql-docs-15.18-1.module_el9.8.0+267+7c71b4a4.aarch64.rpm d9cb4389d1716b6c7afbcd6403776bb3682e1e5b5ce4b4187512b13098740196
aarch64 postgresql-server-devel-15.18-1.module_el9.8.0+267+7c71b4a4.aarch64.rpm df905cb94a9ac1362ab7b788ed4d8e9f6a96a70e78bf69fafb8970395be2a844
aarch64 pgaudit-1.7.0-1.module_el9.3.0+52+21733919.aarch64.rpm e5cbbf39e62321f182fe209827434bddb26d3b29d3be7609370a3edfc17ad5a8
aarch64 postgresql-server-15.18-1.module_el9.8.0+267+7c71b4a4.aarch64.rpm fe7fa30fb1f53577f04b48c8153054aeb0e8fb71aec538785efa8e557da0d3f5
noarch postgresql-test-rpm-macros-15.18-1.module_el9.8.0+267+7c71b4a4.noarch.rpm c5e814edfdda4b6654b63f7ba294dfb634e345de80c9943d701a6a312008ad84
ppc64le postgresql-15.18-1.module_el9.8.0+267+7c71b4a4.ppc64le.rpm 069136f9d242a01c91ae1c8785fef2e3edb2872b7ddef9359508e4a46f1cd69f
ppc64le postgresql-pltcl-15.18-1.module_el9.8.0+267+7c71b4a4.ppc64le.rpm 0d1c38d1741f345acc64b3c50430dfcd69aee4ceeb6c55767fdf09f35d81eb83
ppc64le postgresql-static-15.18-1.module_el9.8.0+267+7c71b4a4.ppc64le.rpm 220f628a09fa36c3484e4be54788514ad8a8c9efa0139445f5e2641d0991d863
ppc64le postgresql-server-devel-15.18-1.module_el9.8.0+267+7c71b4a4.ppc64le.rpm 23b342e11fc541ae3b315a6d5430e24c65e4a1ab99e28751c2f80162d9e89cee
ppc64le postgresql-private-devel-15.18-1.module_el9.8.0+267+7c71b4a4.ppc64le.rpm 5ae4ebab29482e471b193f75bf9fe58ab93da1f2e986be884eeaeabdf433488d
ppc64le postgresql-plpython3-15.18-1.module_el9.8.0+267+7c71b4a4.ppc64le.rpm 722070a19f17fb9ee6db03fd5e2b68f7d3f36482384cf1b6b5d46c39de2fba28
ppc64le postgresql-docs-15.18-1.module_el9.8.0+267+7c71b4a4.ppc64le.rpm 821a01e3c72507ea4d63667fe315d11d160d3cff5e16bec8bb874204e43c0c90
ppc64le pg_repack-1.4.8-2.module_el9.5.0+119+18833d03.ppc64le.rpm 82d2754d3b326611d5b3004036c42b46d61f22a9308e0d571d96ac778b105831
ppc64le postgres-decoderbufs-1.9.7-1.Final.module_el9.3.0+52+21733919.ppc64le.rpm 8f4180654b363231c09fb0ba05b49fc47e2d138ab584ccf2c1b6b4c8effdd1c6
ppc64le postgresql-upgrade-devel-15.18-1.module_el9.8.0+267+7c71b4a4.ppc64le.rpm 9318a293186cebcea1cd9e68488acb33172e9a51ef55fc3baa669cfcbd40b168
ppc64le postgresql-private-libs-15.18-1.module_el9.8.0+267+7c71b4a4.ppc64le.rpm 9651ac1607f65bf279a4506e42f77f2a48157de0dff5b5eb8a5a5930caf76592
ppc64le postgresql-server-15.18-1.module_el9.8.0+267+7c71b4a4.ppc64le.rpm 9813c036164955b25f66a04c022d9b03f114d561d06c767d1a3548dd13f56edc
ppc64le postgresql-contrib-15.18-1.module_el9.8.0+267+7c71b4a4.ppc64le.rpm a2b4d79a5d7f69c0a34442ed185a555c64b6627989b96599f3fa454cff0e41d9
ppc64le postgresql-plperl-15.18-1.module_el9.8.0+267+7c71b4a4.ppc64le.rpm c00c65bf05aa58697bfacf7951346a36b6a365365d1879a81a5c022d122fb901
ppc64le pgaudit-1.7.0-1.module_el9.3.0+52+21733919.ppc64le.rpm c5aca9e9d5f3e300dff4c8dd29559054a0f9298a7d58b4b6c3d16f0a3013940f
ppc64le postgresql-upgrade-15.18-1.module_el9.8.0+267+7c71b4a4.ppc64le.rpm dc68447d2a7e53c97e43b9e53fef58c316874f48dba735573eeb3459c40d2247
ppc64le postgresql-test-15.18-1.module_el9.8.0+267+7c71b4a4.ppc64le.rpm f5adf54987fdca99f0f6c497b8e00e28746679a95b571fd7ef870b3e08092003
s390x pgaudit-1.7.0-1.module_el9.3.0+52+21733919.s390x.rpm 1343275a4269cc54eb35ffbbd2710b8a3db986516e38ed6661d709a84ab1da89
s390x postgresql-private-devel-15.18-1.module_el9.8.0+267+7c71b4a4.s390x.rpm 1aef0309f74a76075003150e3d813ebb9c631d63f92920a40e0a4ae461fd449d
s390x postgres-decoderbufs-1.9.7-1.Final.module_el9.3.0+52+21733919.s390x.rpm 35fb71a2d998b883ee8e0970101b90bf9d464f7b5a3fdba59b4f76d6318dd445
s390x postgresql-server-15.18-1.module_el9.8.0+267+7c71b4a4.s390x.rpm 3834d96c09cc591ccc4501b4e4b84c4fc57d271677b23966949759d72757ff54
s390x postgresql-upgrade-15.18-1.module_el9.8.0+267+7c71b4a4.s390x.rpm 4839c398ea32b4812467336f041bce8c816d76c6170e90eddd33eead5c1fa421
s390x pg_repack-1.4.8-2.module_el9.5.0+119+18833d03.s390x.rpm 565b4d4edc782cf6df048e990f78d9a96ef21d4a91af2800aa9a0d66ac77ae8f
s390x postgresql-pltcl-15.18-1.module_el9.8.0+267+7c71b4a4.s390x.rpm 57fd815851732ae4bb4fa9e6542eb1acf15ee617aa0f0b5a3b767782640bee2b
s390x postgresql-docs-15.18-1.module_el9.8.0+267+7c71b4a4.s390x.rpm 5aee73369d04565090622f18e8cc977808ff08cbba5562783860881e4f91f06c
s390x postgresql-static-15.18-1.module_el9.8.0+267+7c71b4a4.s390x.rpm 5fa638e909c15898bf79b7545bf7d04560ff83297a10012c1908b7cc4746ccfe
s390x postgresql-contrib-15.18-1.module_el9.8.0+267+7c71b4a4.s390x.rpm 6030209f65c6da98cb1565cdf3605bfe73625ce2276b261bb9673bd632b69eea
s390x postgresql-test-15.18-1.module_el9.8.0+267+7c71b4a4.s390x.rpm 6720b87f11f12b7935fd81a816bdc2385de7f98493e03c7e4ee5f90bd652958c
s390x postgresql-plpython3-15.18-1.module_el9.8.0+267+7c71b4a4.s390x.rpm 886f6be4e207ebe0c5e1e7c9daf32c245384c09c8ee6972077bc0597d7fd1fe3
s390x postgresql-15.18-1.module_el9.8.0+267+7c71b4a4.s390x.rpm 909bced1d6fe7df25a934b6e466afd1eb9b310fe169715c43d57b6750bed3b84
s390x postgresql-upgrade-devel-15.18-1.module_el9.8.0+267+7c71b4a4.s390x.rpm 9692d4d15a9071737c5ec47af531632a0a82e3f7b88f89894c43ce5d666e172e
s390x postgresql-plperl-15.18-1.module_el9.8.0+267+7c71b4a4.s390x.rpm bd56c157eba9dc2850cdd39e2be2654fb3f2b3cf75a1816aea57068425fb5256
s390x postgresql-server-devel-15.18-1.module_el9.8.0+267+7c71b4a4.s390x.rpm c9ee2852ff8e765482a7ce3f4bf1a28529b139d1b9d4d0702386e7aa68947df5
s390x postgresql-private-libs-15.18-1.module_el9.8.0+267+7c71b4a4.s390x.rpm d9e853630833537b4a03d40cf66ba27818aa12e643961cb0882712acc11242fa
x86_64 postgresql-contrib-15.18-1.module_el9.8.0+267+7c71b4a4.x86_64.rpm 118baa2e9ddb8ed4a69a048a476587e0d737c8d1fb9f4f07cbc62850aabe357c
x86_64 pg_repack-1.4.8-2.module_el9.5.0+119+18833d03.x86_64.rpm 1c17fe11db244a9e23cf757cfe3615a7256f34ef84e836c69f08b5d37efc9ea0
x86_64 pgaudit-1.7.0-1.module_el9.3.0+52+21733919.x86_64.rpm 1e7dcca31912928f8f81927e2ee52575148e6f737824c95c15b2f94d0d426bde
x86_64 postgresql-upgrade-devel-15.18-1.module_el9.8.0+267+7c71b4a4.x86_64.rpm 28ad2292afd94164f91fad2954468c9b968a8f6838bfbbdaee8cdc223344bc80
x86_64 postgresql-private-devel-15.18-1.module_el9.8.0+267+7c71b4a4.x86_64.rpm 34b45e7e26003608d7c36bf4fadda181aae9ec98a083fdc6f69bae070e546fa4
x86_64 postgresql-test-15.18-1.module_el9.8.0+267+7c71b4a4.x86_64.rpm 429b6bce664cd97e1dfa89025434a24c844295bb6cd21bb9f4f7268b7881f686
x86_64 postgres-decoderbufs-1.9.7-1.Final.module_el9.3.0+52+21733919.x86_64.rpm 444045e97d9babf7b4e33fb62d3d2c649646ff143597832c1d6548aa49dd24ba
x86_64 postgresql-upgrade-15.18-1.module_el9.8.0+267+7c71b4a4.x86_64.rpm 54162973650da76f1edb632dcadfb495fabd210674f445d5eb20fbc36f493d06
x86_64 postgresql-static-15.18-1.module_el9.8.0+267+7c71b4a4.x86_64.rpm 5b7547a8fcde484878ffca2602989b5e7de9156f889901d4551f010d9ffb9b02
x86_64 postgresql-docs-15.18-1.module_el9.8.0+267+7c71b4a4.x86_64.rpm 70f86c26e2b50136f587e3367f3a7217a13e9e11fa8db6ef59d540bc85efa94a
x86_64 postgresql-plpython3-15.18-1.module_el9.8.0+267+7c71b4a4.x86_64.rpm 72180c9c524012c8493eab2428bfce2dda7a8164326df858936e85601a947be0
x86_64 postgresql-server-devel-15.18-1.module_el9.8.0+267+7c71b4a4.x86_64.rpm 85c69004471aab7545b3162f51d6e5214c2df2a23538e06c7236a917b0708e52
x86_64 postgresql-plperl-15.18-1.module_el9.8.0+267+7c71b4a4.x86_64.rpm aa110234bf50657a4013612ef49942d8264e66de9c836ddf48ba953b56b9b8e0
x86_64 postgresql-private-libs-15.18-1.module_el9.8.0+267+7c71b4a4.x86_64.rpm b4526f6d053979e6dbd68f1d088734d1ae3c27c938dee967808e46e263b717ea
x86_64 postgresql-pltcl-15.18-1.module_el9.8.0+267+7c71b4a4.x86_64.rpm de7a9b73b5fbc4281c18551a931487a1c6c3de23774335bb89c8e1dfdc8f9b20
x86_64 postgresql-15.18-1.module_el9.8.0+267+7c71b4a4.x86_64.rpm f2ae2bea240feb614056a39a7109b7c4afb672a627634471e1bfecbbe9b1a627
x86_64 postgresql-server-15.18-1.module_el9.8.0+267+7c71b4a4.x86_64.rpm f6bea994e69331f58a6bdd2023c3e1cde2df7441ac16605534e9cc845385c82a
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.