RHSA-2026:50863: Important: libpq security update
Important: libpq security update
Other sources
The libpq package provides the PostgreSQL client library, which allows client programs to connect to PostgreSQL servers. Security Fix(es): postgresql: PostgreSQL libpq: Buffer overflow allows server superuser to overwrite client stack memory (CVE-2026-6477) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/libpqto a version that resolves this vulnerability.Fixed in 16.14-0.el10_0.1 - Upgrade
Upgrade
redhat/libpq-debuginfoto a version that resolves this vulnerability.Fixed in 16.14-0.el10_0.1 - Upgrade
Upgrade
redhat/libpq-debugsourceto a version that resolves this vulnerability.Fixed in 16.14-0.el10_0.1 - Upgrade
Upgrade
redhat/libpq-develto a version that resolves this vulnerability.Fixed in 16.14-0.el10_0.1 - Upgrade
Upgrade
redhat/libpq-devel-debuginfoto a version that resolves this vulnerability.Fixed in 16.14-0.el10_0.1 - Upgrade
Upgrade
redhat/libpqto a version that resolves this vulnerability.Fixed in 16.14-0.el10_0.1.aa - Upgrade
Upgrade
redhat/libpq-debuginfoto a version that resolves this vulnerability.Fixed in 16.14-0.el10_0.1.aa - Upgrade
Upgrade
redhat/libpq-debugsourceto a version that resolves this vulnerability.Fixed in 16.14-0.el10_0.1.aa - Upgrade
Upgrade
redhat/libpq-develto a version that resolves this vulnerability.Fixed in 16.14-0.el10_0.1.aa - Upgrade
Upgrade
redhat/libpq-devel-debuginfoto a version that resolves this vulnerability.Fixed in 16.14-0.el10_0.1.aa - Compensating control
Because this is a libpq (PostgreSQL client library) buffer overflow (CVE-2026-6477) that can allow server superuser to overwrite client stack memory, limit exposure of applications using the libpq package: restrict who can trigger server-side superuser actions that interact with vulnerable client code paths.
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:50863?
The severity of RHSA-2026:50863 is classified as high with a score of 7.
What does RHSA-2026:50863 address?
RHSA-2026:50863 addresses a security update for the libpq library in Red Hat Enterprise Linux.
How do I fix RHSA-2026:50863?
To fix RHSA-2026:50863, you should apply the latest security update provided for the affected Red Hat Enterprise Linux versions.
Which systems are affected by RHSA-2026:50863?
RHSA-2026:50863 affects various architectures of Red Hat Enterprise Linux including x86_64, ARM 64, IBM z Systems, and Power little endian.
When was RHSA-2026:50863 published?
RHSA-2026:50863 was published on August 5, 2026.