RHSA-2026:19009HighCVSS 8.8
Red Hat Security Advisory: postgresql18 security update
🔗 CVE IDs covered (5)
📋 Description
CVE-2026-2003 — postgresql: PostgreSQL oidvector discloses a few bytes of memory CVE-2026-2004 — postgresql: PostgreSQL intarray missing validation of type of input to selectivity estimator executes arbitrary code CVE-2026-2005 — postgresql: PostgreSQL pgcrypto heap buffer overflow executes arbitrary code CVE-2026-2006 — postgresql: PostgreSQL missing validation of multibyte character length executes arbitrary code CVE-2026-2007 — postgresql: PostgreSQL pg_trgm heap buffer overflow writes pattern onto server memory
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2026:19009
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2439320
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2439322
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2439324
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2439325
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2439326
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_19009.json