RHSA-2026:59278: Important: postgresql-jdbc security update
Important: postgresql-jdbc security update
Other sources
PostgreSQL is an advanced object-relational database management system. The postgresql-jdbc package includes the .jar files needed for Java programs to access a PostgreSQL database.Security Fix(es): jdbc.postgresql.org: pgjdbc: Client-side Denial of Service via malicious SCRAM-SHA-256 authentication (CVE-2026-42198) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/postgresql-jdbcto a version that resolves this vulnerability.Fixed in 42.2.3-7.el8_4.1 - Upgrade
Upgrade
redhat/postgresql-jdbc-javadocto a version that resolves this vulnerability.Fixed in 42.2.3-7.el8_4.1 - Upgrade
Upgrade
postgresql-jdbcto a version that resolves this vulnerability.Patch CVE-2026-42198
Event History
Frequently Asked Questions
Which Red Hat offerings are listed as affected by this update?
The update is listed for Red Hat Enterprise Linux Server - AUS and Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life.
How is this update rated?
It is rated High severity with a severity value of 7 and a risk value of 33.