RHSA-2026:59277: Important: postgresql-jdbc security update
Important: postgresql-jdbc security update
Other sources
PostgreSQL is an advanced object-relational database management system. The postgresql-jdbc package includes the .jar files needed for Java programs to access a PostgreSQL database.Security Fix(es): jdbc.postgresql.org: pgjdbc: Client-side Denial of Service via malicious SCRAM-SHA-256 authentication (CVE-2026-42198) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/postgresql-jdbcto a version that resolves this vulnerability.Fixed in 42.2.3-5.el8_6.1 - Upgrade
Upgrade
redhat/postgresql-jdbc-javadocto a version that resolves this vulnerability.Fixed in 42.2.3-5.el8_6.1 - Compensating control
Because the advisory describes a client-side Denial of Service issue via malicious SCRAM-SHA-256 authentication (CVE-2026-42198), restrict or closely control which clients can authenticate to PostgreSQL using SCRAM-SHA-256 (e.g., limit client access to trusted application hosts/users) until the postgresql-jdbc security update is applied.
Event History
Frequently Asked Questions
Which Red Hat offerings are listed for this update?
The update is listed for Red Hat Enterprise Linux Server - AUS and Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life.
What severity is assigned to this advisory?
The advisory is rated high severity, with a severity value of 7.