RHSA-2026:27742HighCVSS 8.8

Red Hat Security Advisory: postgresql18 security update

Published
June 22, 2026
Last Modified
July 22, 2026

🔗 CVE IDs covered (11)

📋 Description

CVE-2026-6472 — postgresql: PostgreSQL CREATE TYPE does not check multirange schema CREATE privilege CVE-2026-6473 — postgresql: integer overflow can cause an undersized allocation and an out-of-bounds write CVE-2026-6474 — postgresql: PostgreSQL: Information disclosure via externally-controlled format string in timeofday() function CVE-2026-6475 — postgresql: PostgreSQL: Operating system account hijack via symlink following in pg_basebackup and pg_rewind CVE-2026-6476 — postgresql: PostgreSQL: SQL injection in pg_createsubscriber allows arbitrary SQL execution as superuser CVE-2026-6477 — postgresql: PostgreSQL libpq: Buffer overflow allows server superuser to overwrite client stack memory CVE-2026-6478 — postgresql: PostgreSQL: Credential recovery via covert timing channel in MD5 password comparison CVE-2026-6479 — postgresql: PostgreSQL: Denial of Service via uncontrolled recursion in SSL/GSS negotiation CVE-2026-6575 — postgresql: PostgreSQL: Information disclosure via buffer over-read in pg_restore_attribute_stats() CVE-2026-6637 — postgresql: PostgreSQL: Arbitrary code execution vulnerability in 'refint' module CVE-2026-6638 — postgresql: PostgreSQL: Arbitrary SQL execution via SQL injection in logical replication

🔗 References (7)