RHSA-2026:54532: Important: postgresql-jdbc security update
Important: postgresql-jdbc security update
Other sources
PostgreSQL is an advanced object-relational database management system. The postgresql-jdbc package includes the .jar files needed for Java programs to access a PostgreSQL database.Security Fix(es): jdbc.postgresql.org: pgjdbc: Client-side Denial of Service via malicious SCRAM-SHA-256 authentication (CVE-2026-42198) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/postgresql-jdbcto a version that resolves this vulnerability.Fixed in 42.2.28-1.el9_2.1
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:54532?
The severity of RHSA-2026:54532 is classified as high with a score of 7.
What vulnerabilities are addressed in RHSA-2026:54532?
RHSA-2026:54532 addresses a client-side Denial of Service vulnerability in the postgresql-jdbc package.
How do I fix RHSA-2026:54532?
To fix RHSA-2026:54532, update the postgresql-jdbc package to the latest version provided by Red Hat.
Which software is affected by RHSA-2026:54532?
The affected software includes the postgresql-jdbc package on various Red Hat Enterprise Linux platforms.
When was RHSA-2026:54532 published?
RHSA-2026:54532 was published on August 13, 2026.