RHSA-2026:34043: Important: postgresql:12 security update
Important: postgresql:12 security update
Other sources
PostgreSQL is an advanced object-relational database management system (DBMS).Security Fix(es): postgresql: PostgreSQL: Operating system account hijack via symlink following in pgbasebackup and pgrewind (CVE-2026-6475) postgresql: PostgreSQL libpq: Buffer overflow allows server superuser to overwrite client stack memory (CVE-2026-6477) postgresql: PostgreSQL: Credential recovery via covert timing channel in MD5 password comparison (CVE-2026-6478) postgresql: integer overflow can cause an undersized allocation and an out-of-bounds write (CVE-2026-6473) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/pgauditto a version that resolves this vulnerability.Fixed in 1.4.0-5.module+el8.5.0+11354+78b3c9c5 - Upgrade
Upgrade
redhat/postgres-decoderbufsto a version that resolves this vulnerability.Fixed in 0.10.0-2.module+el8.5.0+11354+78b3c9c5 - Upgrade
Upgrade
redhat/postgresqlto a version that resolves this vulnerability.Fixed in 12.22-1.module+el8.8.0+24458+21f81c54.4 - Upgrade
Upgrade
redhat/pgaudit-debuginfoto a version that resolves this vulnerability.Fixed in 1.4.0-5.module+el8.5.0+11354+78b3c9c5 - Upgrade
Upgrade
redhat/pgaudit-debugsourceto a version that resolves this vulnerability.Fixed in 1.4.0-5.module+el8.5.0+11354+78b3c9c5 - Upgrade
Upgrade
redhat/postgres-decoderbufs-debuginfoto a version that resolves this vulnerability.Fixed in 0.10.0-2.module+el8.5.0+11354+78b3c9c5 - Upgrade
Upgrade
redhat/postgres-decoderbufs-debugsourceto a version that resolves this vulnerability.Fixed in 0.10.0-2.module+el8.5.0+11354+78b3c9c5 - Upgrade
Upgrade
redhat/postgresql-contribto a version that resolves this vulnerability.Fixed in 12.22-1.module+el8.8.0+24458+21f81c54.4 - Upgrade
Upgrade
redhat/postgresql-contrib-debuginfoto a version that resolves this vulnerability.Fixed in 12.22-1.module+el8.8.0+24458+21f81c54.4 - Upgrade
Upgrade
redhat/postgresql-debuginfoto a version that resolves this vulnerability.Fixed in 12.22-1.module+el8.8.0+24458+21f81c54.4 - Upgrade
Upgrade
redhat/postgresql-debugsourceto a version that resolves this vulnerability.Fixed in 12.22-1.module+el8.8.0+24458+21f81c54.4 - Upgrade
Upgrade
redhat/postgresql-docsto a version that resolves this vulnerability.Fixed in 12.22-1.module+el8.8.0+24458+21f81c54.4 - Upgrade
Upgrade
redhat/postgresql-docs-debuginfoto a version that resolves this vulnerability.Fixed in 12.22-1.module+el8.8.0+24458+21f81c54.4 - Upgrade
Upgrade
redhat/postgresql-plperlto a version that resolves this vulnerability.Fixed in 12.22-1.module+el8.8.0+24458+21f81c54.4 - Upgrade
Upgrade
redhat/postgresql-plperl-debuginfoto a version that resolves this vulnerability.Fixed in 12.22-1.module+el8.8.0+24458+21f81c54.4 - Upgrade
Upgrade
redhat/postgresql-plpython3to a version that resolves this vulnerability.Fixed in 12.22-1.module+el8.8.0+24458+21f81c54.4 - Upgrade
Upgrade
redhat/postgresql-plpython3-debuginfoto a version that resolves this vulnerability.Fixed in 12.22-1.module+el8.8.0+24458+21f81c54.4 - Upgrade
Upgrade
redhat/postgresql-pltclto a version that resolves this vulnerability.Fixed in 12.22-1.module+el8.8.0+24458+21f81c54.4 - Upgrade
Upgrade
redhat/postgresql-pltcl-debuginfoto a version that resolves this vulnerability.Fixed in 12.22-1.module+el8.8.0+24458+21f81c54.4 - Upgrade
Upgrade
redhat/postgresql-serverto a version that resolves this vulnerability.Fixed in 12.22-1.module+el8.8.0+24458+21f81c54.4 - Upgrade
Upgrade
redhat/postgresql-server-debuginfoto a version that resolves this vulnerability.Fixed in 12.22-1.module+el8.8.0+24458+21f81c54.4 - Upgrade
Upgrade
redhat/postgresql-server-develto a version that resolves this vulnerability.Fixed in 12.22-1.module+el8.8.0+24458+21f81c54.4 - Upgrade
Upgrade
redhat/postgresql-server-devel-debuginfoto a version that resolves this vulnerability.Fixed in 12.22-1.module+el8.8.0+24458+21f81c54.4 - Upgrade
Upgrade
redhat/postgresql-staticto a version that resolves this vulnerability.Fixed in 12.22-1.module+el8.8.0+24458+21f81c54.4 - Upgrade
Upgrade
redhat/postgresql-testto a version that resolves this vulnerability.Fixed in 12.22-1.module+el8.8.0+24458+21f81c54.4 - Upgrade
Upgrade
redhat/postgresql-test-debuginfoto a version that resolves this vulnerability.Fixed in 12.22-1.module+el8.8.0+24458+21f81c54.4 - Upgrade
Upgrade
redhat/postgresql-test-rpm-macrosto a version that resolves this vulnerability.Fixed in 12.22-1.module+el8.8.0+24458+21f81c54.4 - Upgrade
Upgrade
redhat/postgresql-upgradeto a version that resolves this vulnerability.Fixed in 12.22-1.module+el8.8.0+24458+21f81c54.4 - Upgrade
Upgrade
redhat/postgresql-upgrade-debuginfoto a version that resolves this vulnerability.Fixed in 12.22-1.module+el8.8.0+24458+21f81c54.4 - Upgrade
Upgrade
redhat/postgresql-upgrade-develto a version that resolves this vulnerability.Fixed in 12.22-1.module+el8.8.0+24458+21f81c54.4 - Upgrade
Upgrade
redhat/postgresql-upgrade-devel-debuginfoto a version that resolves this vulnerability.Fixed in 12.22-1.module+el8.8.0+24458+21f81c54.4 - Compensating control
Update PostgreSQL 12 per the referenced Red Hat advisory/apply-this-update guidance (includes fixes for CVE-2026-6477, CVE-2026-6478, CVE-2026-6473, and CVE-2026-6475).
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:34043?
The severity of RHSA-2026:34043 is classified as high, with a CVSS score of 7.
What vulnerabilities are addressed in RHSA-2026:34043?
RHSA-2026:34043 addresses an operating system account hijacking vulnerability via symlink in pg_basebackup and pg_rewind, among others.
How do I fix RHSA-2026:34043?
To resolve RHSA-2026:34043, you need to apply the latest security update for PostgreSQL 12 as provided by Red Hat.
What are the consequences of not patching RHSA-2026:34043?
Failing to patch RHSA-2026:34043 can lead to potential exploitation of the hijacking vulnerability, compromising system security.
Which Red Hat packages are affected by RHSA-2026:34043?
Affected packages include redhat/postgresql, redhat/pgaudit, redhat/postgres-decoderbufs, and their respective debug info packages.