RHSA-2026:61255: Important: postgresql:12 security update
Important: postgresql:12 security update
Other sources
PostgreSQL is an advanced object-relational database management system (DBMS).Security Fix(es): postgresql: PostgreSQL: Denial of Service via uncontrolled recursion in SSL/GSS negotiation (CVE-2026-6479) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/pgauditto a version that resolves this vulnerability.Fixed in 1.4.0-6.module+el8.4.0+11288+c193d6d7 - Upgrade
Upgrade
redhat/postgres-decoderbufsto a version that resolves this vulnerability.Fixed in 0.10.0-2.module+el8.4.0+11288+c193d6d7 - Upgrade
Upgrade
redhat/postgresqlto a version that resolves this vulnerability.Fixed in 12.22-1.module+el8.4.0+24733+2481cd1e.5 - Upgrade
Upgrade
redhat/pgaudit-debuginfoto a version that resolves this vulnerability.Fixed in 1.4.0-6.module+el8.4.0+11288+c193d6d7 - Upgrade
Upgrade
redhat/pgaudit-debugsourceto a version that resolves this vulnerability.Fixed in 1.4.0-6.module+el8.4.0+11288+c193d6d7 - Upgrade
Upgrade
redhat/postgres-decoderbufs-debuginfoto a version that resolves this vulnerability.Fixed in 0.10.0-2.module+el8.4.0+11288+c193d6d7 - Upgrade
Upgrade
redhat/postgres-decoderbufs-debugsourceto a version that resolves this vulnerability.Fixed in 0.10.0-2.module+el8.4.0+11288+c193d6d7 - Upgrade
Upgrade
redhat/postgresql-contribto a version that resolves this vulnerability.Fixed in 12.22-1.module+el8.4.0+24733+2481cd1e.5 - Upgrade
Upgrade
redhat/postgresql-contrib-debuginfoto a version that resolves this vulnerability.Fixed in 12.22-1.module+el8.4.0+24733+2481cd1e.5 - Upgrade
Upgrade
redhat/postgresql-debuginfoto a version that resolves this vulnerability.Fixed in 12.22-1.module+el8.4.0+24733+2481cd1e.5 - Upgrade
Upgrade
redhat/postgresql-debugsourceto a version that resolves this vulnerability.Fixed in 12.22-1.module+el8.4.0+24733+2481cd1e.5 - Upgrade
Upgrade
redhat/postgresql-docsto a version that resolves this vulnerability.Fixed in 12.22-1.module+el8.4.0+24733+2481cd1e.5 - Upgrade
Upgrade
redhat/postgresql-docs-debuginfoto a version that resolves this vulnerability.Fixed in 12.22-1.module+el8.4.0+24733+2481cd1e.5 - Upgrade
Upgrade
redhat/postgresql-plperlto a version that resolves this vulnerability.Fixed in 12.22-1.module+el8.4.0+24733+2481cd1e.5 - Upgrade
Upgrade
redhat/postgresql-plperl-debuginfoto a version that resolves this vulnerability.Fixed in 12.22-1.module+el8.4.0+24733+2481cd1e.5 - Upgrade
Upgrade
redhat/postgresql-plpython3to a version that resolves this vulnerability.Fixed in 12.22-1.module+el8.4.0+24733+2481cd1e.5 - Upgrade
Upgrade
redhat/postgresql-plpython3-debuginfoto a version that resolves this vulnerability.Fixed in 12.22-1.module+el8.4.0+24733+2481cd1e.5 - Upgrade
Upgrade
redhat/postgresql-pltclto a version that resolves this vulnerability.Fixed in 12.22-1.module+el8.4.0+24733+2481cd1e.5 - Upgrade
Upgrade
redhat/postgresql-pltcl-debuginfoto a version that resolves this vulnerability.Fixed in 12.22-1.module+el8.4.0+24733+2481cd1e.5 - Upgrade
Upgrade
redhat/postgresql-serverto a version that resolves this vulnerability.Fixed in 12.22-1.module+el8.4.0+24733+2481cd1e.5 - Upgrade
Upgrade
redhat/postgresql-server-debuginfoto a version that resolves this vulnerability.Fixed in 12.22-1.module+el8.4.0+24733+2481cd1e.5 - Upgrade
Upgrade
redhat/postgresql-server-develto a version that resolves this vulnerability.Fixed in 12.22-1.module+el8.4.0+24733+2481cd1e.5 - Upgrade
Upgrade
redhat/postgresql-server-devel-debuginfoto a version that resolves this vulnerability.Fixed in 12.22-1.module+el8.4.0+24733+2481cd1e.5 - Upgrade
Upgrade
redhat/postgresql-staticto a version that resolves this vulnerability.Fixed in 12.22-1.module+el8.4.0+24733+2481cd1e.5 - Upgrade
Upgrade
redhat/postgresql-testto a version that resolves this vulnerability.Fixed in 12.22-1.module+el8.4.0+24733+2481cd1e.5 - Upgrade
Upgrade
redhat/postgresql-test-debuginfoto a version that resolves this vulnerability.Fixed in 12.22-1.module+el8.4.0+24733+2481cd1e.5 - Upgrade
Upgrade
redhat/postgresql-test-rpm-macrosto a version that resolves this vulnerability.Fixed in 12.22-1.module+el8.4.0+24733+2481cd1e.5 - Upgrade
Upgrade
redhat/postgresql-upgradeto a version that resolves this vulnerability.Fixed in 12.22-1.module+el8.4.0+24733+2481cd1e.5 - Upgrade
Upgrade
redhat/postgresql-upgrade-debuginfoto a version that resolves this vulnerability.Fixed in 12.22-1.module+el8.4.0+24733+2481cd1e.5 - Upgrade
Upgrade
redhat/postgresql-upgrade-develto a version that resolves this vulnerability.Fixed in 12.22-1.module+el8.4.0+24733+2481cd1e.5 - Upgrade
Upgrade
redhat/postgresql-upgrade-devel-debuginfoto a version that resolves this vulnerability.Fixed in 12.22-1.module+el8.4.0+24733+2481cd1e.5 - Compensating control
Mitigate the PostgreSQL CVE-2026-6479 denial of service via uncontrolled recursion in SSL/GSS negotiation by applying the stated postgresql:12 security update referenced in the advisory (Red Hat access article https://access.redhat.com/articles/11258).
Event History
Frequently Asked Questions
Which Red Hat offerings and related packages are identified in this advisory?
The advisory lists Red Hat Enterprise Linux Server - AUS and Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life. It also names redhat/postgresql, redhat/pgaudit, redhat/postgres-decoderbufs, and associated debuginfo and debugsource packages.