RHSA-2026:52928: Important: postgresql-jdbc security update
Important: postgresql-jdbc security update
Other sources
PostgreSQL is an advanced object-relational database management system. The postgresql-jdbc package includes the .jar files needed for Java programs to access a PostgreSQL database.Security Fix(es): jdbc.postgresql.org: pgjdbc: Client-side Denial of Service via malicious SCRAM-SHA-256 authentication (CVE-2026-42198) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/postgresql-jdbcto a version that resolves this vulnerability.Fixed in 42.7.1-7.el10_0.1
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:52928?
The severity of RHSA-2026:52928 is high, rated at 7.
What security fix does RHSA-2026:52928 address?
RHSA-2026:52928 addresses a client-side Denial of Service vulnerability in the postgresql-jdbc package.
How do I fix RHSA-2026:52928?
To fix RHSA-2026:52928, update the postgresql-jdbc package to the latest version provided by Red Hat.
What software is affected by RHSA-2026:52928?
The affected software includes the postgresql-jdbc package for various versions of Red Hat Enterprise Linux.
What type of vulnerability is related to RHSA-2026:52928?
RHSA-2026:52928 is related to a Denial of Service vulnerability that affects PostgreSQL database access.