RHSA-2026:57633: Important: postgresql security update
Important: postgresql security update
Other sources
PostgreSQL is an advanced object-relational database management system (DBMS).Security Fix(es): postgresql: PostgreSQL: Denial of Service via uncontrolled recursion in SSL/GSS negotiation (CVE-2026-6479) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/postgresqlto a version that resolves this vulnerability.Fixed in 13.23-1.el9_2.4 - Upgrade
Upgrade
redhat/postgresql-contribto a version that resolves this vulnerability.Fixed in 13.23-1.el9_2.4 - Upgrade
Upgrade
redhat/postgresql-contrib-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_2.4 - Upgrade
Upgrade
redhat/postgresql-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_2.4 - Upgrade
Upgrade
redhat/postgresql-debugsourceto a version that resolves this vulnerability.Fixed in 13.23-1.el9_2.4 - Upgrade
Upgrade
redhat/postgresql-docs-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_2.4 - Upgrade
Upgrade
redhat/postgresql-plperlto a version that resolves this vulnerability.Fixed in 13.23-1.el9_2.4 - Upgrade
Upgrade
redhat/postgresql-plperl-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_2.4 - Upgrade
Upgrade
redhat/postgresql-plpython3to a version that resolves this vulnerability.Fixed in 13.23-1.el9_2.4 - Upgrade
Upgrade
redhat/postgresql-plpython3-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_2.4 - Upgrade
Upgrade
redhat/postgresql-pltclto a version that resolves this vulnerability.Fixed in 13.23-1.el9_2.4 - Upgrade
Upgrade
redhat/postgresql-pltcl-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_2.4 - Upgrade
Upgrade
redhat/postgresql-private-libsto a version that resolves this vulnerability.Fixed in 13.23-1.el9_2.4 - Upgrade
Upgrade
redhat/postgresql-private-libs-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_2.4 - Upgrade
Upgrade
redhat/postgresql-serverto a version that resolves this vulnerability.Fixed in 13.23-1.el9_2.4 - Upgrade
Upgrade
redhat/postgresql-server-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_2.4 - Upgrade
Upgrade
redhat/postgresql-server-devel-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_2.4 - Upgrade
Upgrade
redhat/postgresql-test-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_2.4 - Upgrade
Upgrade
redhat/postgresql-upgradeto a version that resolves this vulnerability.Fixed in 13.23-1.el9_2.4 - Upgrade
Upgrade
redhat/postgresql-upgrade-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_2.4 - Upgrade
Upgrade
redhat/postgresql-upgrade-devel-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_2.4 - Upgrade
Upgrade
redhat/postgresqlto a version that resolves this vulnerability.Fixed in 13.23-1.el9_2.4.aa - Upgrade
Upgrade
redhat/postgresql-contribto a version that resolves this vulnerability.Fixed in 13.23-1.el9_2.4.aa - Upgrade
Upgrade
redhat/postgresql-contrib-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_2.4.aa - Upgrade
Upgrade
redhat/postgresql-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_2.4.aa - Upgrade
Upgrade
redhat/postgresql-debugsourceto a version that resolves this vulnerability.Fixed in 13.23-1.el9_2.4.aa - Upgrade
Upgrade
redhat/postgresql-docs-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_2.4.aa - Upgrade
Upgrade
redhat/postgresql-plperlto a version that resolves this vulnerability.Fixed in 13.23-1.el9_2.4.aa - Upgrade
Upgrade
redhat/postgresql-plperl-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_2.4.aa - Upgrade
Upgrade
redhat/postgresql-plpython3to a version that resolves this vulnerability.Fixed in 13.23-1.el9_2.4.aa - Upgrade
Upgrade
redhat/postgresql-plpython3-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_2.4.aa - Upgrade
Upgrade
redhat/postgresql-pltclto a version that resolves this vulnerability.Fixed in 13.23-1.el9_2.4.aa - Upgrade
Upgrade
redhat/postgresql-pltcl-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_2.4.aa - Upgrade
Upgrade
redhat/postgresql-private-libsto a version that resolves this vulnerability.Fixed in 13.23-1.el9_2.4.aa - Upgrade
Upgrade
redhat/postgresql-private-libs-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_2.4.aa - Upgrade
Upgrade
redhat/postgresql-serverto a version that resolves this vulnerability.Fixed in 13.23-1.el9_2.4.aa - Upgrade
Upgrade
redhat/postgresql-server-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_2.4.aa - Upgrade
Upgrade
redhat/postgresql-server-devel-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_2.4.aa - Upgrade
Upgrade
redhat/postgresql-test-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_2.4.aa - Upgrade
Upgrade
redhat/postgresql-upgradeto a version that resolves this vulnerability.Fixed in 13.23-1.el9_2.4.aa - Upgrade
Upgrade
redhat/postgresql-upgrade-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_2.4.aa - Upgrade
Upgrade
redhat/postgresql-upgrade-devel-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_2.4.aa - Compensating control
Apply the postgresql security update referenced by the advisory (PostgreSQL: Denial of Service via uncontrolled recursion in SSL/GSS negotiation, CVE-2026-6479).
Event History
Frequently Asked Questions
What kind of impact can exploitation cause?
The issue can cause a denial of service through uncontrolled recursion during SSL/GSS negotiation. The provided information does not describe data exposure, privilege escalation, or code execution.
Which installed packages are covered by this update?
The advisory lists redhat/postgresql and related packages including postgresql-contrib, debuginfo, debugsource, docs-debuginfo, plperl, and plperl-debuginfo.
What mitigation is provided if patching cannot be completed immediately?
No temporary mitigation or workaround is provided in the advisory data. The listed remediation is the PostgreSQL security update.