RHSA-2026:49908: Important: libpq security update
Important: libpq security update
Other sources
The libpq package provides the PostgreSQL client library, which allows client programs to connect to PostgreSQL servers. Security Fix(es): postgresql: PostgreSQL libpq: Buffer overflow allows server superuser to overwrite client stack memory (CVE-2026-6477) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/libpqto a version that resolves this vulnerability.Fixed in 13.23-1.el9_2.1 - Upgrade
Upgrade
redhat/libpq-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_2.1 - Upgrade
Upgrade
redhat/libpq-debugsourceto a version that resolves this vulnerability.Fixed in 13.23-1.el9_2.1 - Upgrade
Upgrade
redhat/libpq-develto a version that resolves this vulnerability.Fixed in 13.23-1.el9_2.1 - Upgrade
Upgrade
redhat/libpq-devel-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_2.1 - Upgrade
Upgrade
redhat/libpqto a version that resolves this vulnerability.Fixed in 13.23-1.el9_2.1.aa - Upgrade
Upgrade
redhat/libpq-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_2.1.aa - Upgrade
Upgrade
redhat/libpq-debugsourceto a version that resolves this vulnerability.Fixed in 13.23-1.el9_2.1.aa - Upgrade
Upgrade
redhat/libpq-develto a version that resolves this vulnerability.Fixed in 13.23-1.el9_2.1.aa - Upgrade
Upgrade
redhat/libpq-devel-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_2.1.aa - Upgrade
Upgrade
postgresql/libpqto a version that resolves this vulnerability.Patch CVE-2026-6477
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:49908?
The severity of RHSA-2026:49908 is classified as high with a score of 7.
What security issue does RHSA-2026:49908 address?
RHSA-2026:49908 addresses a buffer overflow vulnerability in the PostgreSQL libpq that allows a server superuser to overwrite client stack memory.
How do I fix RHSA-2026:49908?
To resolve RHSA-2026:49908, ensure that you update the affected libpq packages to the latest version provided by Red Hat.
Which systems are affected by RHSA-2026:49908?
Affected systems include Red Hat Enterprise Linux for x86_64, including Update Services for SAP Solutions and Extended Life Cycle.
Is this vulnerability, RHSA-2026:49908, exploitable remotely?
Yes, the buffer overflow in RHSA-2026:49908 can potentially be exploited remotely by malicious actors with superuser access.