RHSA-2026:49909: Important: libpq security update
Important: libpq security update
Other sources
The libpq package provides the PostgreSQL client library, which allows client programs to connect to PostgreSQL servers. Security Fix(es): postgresql: PostgreSQL libpq: Buffer overflow allows server superuser to overwrite client stack memory (CVE-2026-6477) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/libpqto a version that resolves this vulnerability.Fixed in 13.23-1.el9_4.1 - Upgrade
Upgrade
redhat/libpq-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_4.1 - Upgrade
Upgrade
redhat/libpq-debugsourceto a version that resolves this vulnerability.Fixed in 13.23-1.el9_4.1 - Upgrade
Upgrade
redhat/libpq-develto a version that resolves this vulnerability.Fixed in 13.23-1.el9_4.1 - Upgrade
Upgrade
redhat/libpq-devel-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_4.1 - Upgrade
Upgrade
redhat/libpqto a version that resolves this vulnerability.Fixed in 13.23-1.el9_4.1.aa - Upgrade
Upgrade
redhat/libpq-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_4.1.aa - Upgrade
Upgrade
redhat/libpq-debugsourceto a version that resolves this vulnerability.Fixed in 13.23-1.el9_4.1.aa - Upgrade
Upgrade
redhat/libpq-develto a version that resolves this vulnerability.Fixed in 13.23-1.el9_4.1.aa - Upgrade
Upgrade
redhat/libpq-devel-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_4.1.aa - Upgrade
Upgrade
postgresql/libpqto a version that resolves this vulnerability.Patch CVE-2026-6477
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:49909?
The severity of RHSA-2026:49909 is rated as high, specifically a score of 7.
What vulnerabilities are addressed in RHSA-2026:49909?
RHSA-2026:49909 addresses a buffer overflow vulnerability in the libpq package that could allow a server superuser to overwrite client stack memory.
How do I fix RHSA-2026:49909?
To fix RHSA-2026:49909, you should update the libpq package to the latest version provided by Red Hat.
Which systems are affected by RHSA-2026:49909?
RHSA-2026:49909 affects multiple versions of Red Hat Enterprise Linux including ARM 64 and IBM z Systems.
What is the impact of the vulnerability in RHSA-2026:49909?
The impact of the vulnerability in RHSA-2026:49909 could lead to unauthorized access or manipulation of client stack memory if exploited.