RHSA-2026:52929: Important: postgresql-jdbc security update
Important: postgresql-jdbc security update
Other sources
PostgreSQL is an advanced object-relational database management system. The postgresql-jdbc package includes the .jar files needed for Java programs to access a PostgreSQL database.Security Fix(es): jdbc.postgresql.org: pgjdbc: Client-side Denial of Service via malicious SCRAM-SHA-256 authentication (CVE-2026-42198) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/postgresql-jdbcto a version that resolves this vulnerability.Fixed in 42.2.28-1.el9_4.1
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:52929?
The severity of RHSA-2026:52929 is high with a rating of 7.
What does RHSA-2026:52929 address?
RHSA-2026:52929 addresses a client-side Denial of Service vulnerability in the postgresql-jdbc package.
How do I fix RHSA-2026:52929?
To fix RHSA-2026:52929, you should update the postgresql-jdbc package to the latest version provided by Red Hat.
Which systems are affected by RHSA-2026:52929?
Affected systems include Red Hat Enterprise Linux on x86_64, ARM 64, Power LE, and IBM z Systems.
What is the significance of the postgresql-jdbc update in RHSA-2026:52929?
The postgresql-jdbc update in RHSA-2026:52929 is important for mitigating potential Denial of Service attacks on PostgreSQL databases.