RHSA-2026:62116: Important: postgresql security update
PostgreSQL is an advanced object-relational database management system (DBMS).Security Fix(es): postgresql: PostgreSQL: Denial of Service via uncontrolled recursion in SSL/GSS negotiation (CVE-2026-6479) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/postgresqlto a version that resolves this vulnerability.Fixed in 13.23-1.el9_6.4 - Upgrade
Upgrade
redhat/postgresql-contribto a version that resolves this vulnerability.Fixed in 13.23-1.el9_6.4 - Upgrade
Upgrade
redhat/postgresql-contrib-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_6.4 - Upgrade
Upgrade
redhat/postgresql-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_6.4 - Upgrade
Upgrade
redhat/postgresql-debugsourceto a version that resolves this vulnerability.Fixed in 13.23-1.el9_6.4 - Upgrade
Upgrade
redhat/postgresql-docs-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_6.4 - Upgrade
Upgrade
redhat/postgresql-plperlto a version that resolves this vulnerability.Fixed in 13.23-1.el9_6.4 - Upgrade
Upgrade
redhat/postgresql-plperl-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_6.4 - Upgrade
Upgrade
redhat/postgresql-plpython3to a version that resolves this vulnerability.Fixed in 13.23-1.el9_6.4 - Upgrade
Upgrade
redhat/postgresql-plpython3-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_6.4 - Upgrade
Upgrade
redhat/postgresql-pltclto a version that resolves this vulnerability.Fixed in 13.23-1.el9_6.4 - Upgrade
Upgrade
redhat/postgresql-pltcl-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_6.4 - Upgrade
Upgrade
redhat/postgresql-private-libsto a version that resolves this vulnerability.Fixed in 13.23-1.el9_6.4 - Upgrade
Upgrade
redhat/postgresql-private-libs-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_6.4 - Upgrade
Upgrade
redhat/postgresql-serverto a version that resolves this vulnerability.Fixed in 13.23-1.el9_6.4 - Upgrade
Upgrade
redhat/postgresql-server-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_6.4 - Upgrade
Upgrade
redhat/postgresql-server-devel-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_6.4 - Upgrade
Upgrade
redhat/postgresql-test-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_6.4 - Upgrade
Upgrade
redhat/postgresql-upgradeto a version that resolves this vulnerability.Fixed in 13.23-1.el9_6.4 - Upgrade
Upgrade
redhat/postgresql-upgrade-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_6.4 - Upgrade
Upgrade
redhat/postgresql-upgrade-devel-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_6.4 - Upgrade
Upgrade
redhat/postgresqlto a version that resolves this vulnerability.Fixed in 13.23-1.el9_6.4.aa - Upgrade
Upgrade
redhat/postgresql-contribto a version that resolves this vulnerability.Fixed in 13.23-1.el9_6.4.aa - Upgrade
Upgrade
redhat/postgresql-contrib-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_6.4.aa - Upgrade
Upgrade
redhat/postgresql-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_6.4.aa - Upgrade
Upgrade
redhat/postgresql-debugsourceto a version that resolves this vulnerability.Fixed in 13.23-1.el9_6.4.aa - Upgrade
Upgrade
redhat/postgresql-docs-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_6.4.aa - Upgrade
Upgrade
redhat/postgresql-plperlto a version that resolves this vulnerability.Fixed in 13.23-1.el9_6.4.aa - Upgrade
Upgrade
redhat/postgresql-plperl-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_6.4.aa - Upgrade
Upgrade
redhat/postgresql-plpython3to a version that resolves this vulnerability.Fixed in 13.23-1.el9_6.4.aa - Upgrade
Upgrade
redhat/postgresql-plpython3-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_6.4.aa - Upgrade
Upgrade
redhat/postgresql-pltclto a version that resolves this vulnerability.Fixed in 13.23-1.el9_6.4.aa - Upgrade
Upgrade
redhat/postgresql-pltcl-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_6.4.aa - Upgrade
Upgrade
redhat/postgresql-private-libsto a version that resolves this vulnerability.Fixed in 13.23-1.el9_6.4.aa - Upgrade
Upgrade
redhat/postgresql-private-libs-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_6.4.aa - Upgrade
Upgrade
redhat/postgresql-serverto a version that resolves this vulnerability.Fixed in 13.23-1.el9_6.4.aa - Upgrade
Upgrade
redhat/postgresql-server-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_6.4.aa - Upgrade
Upgrade
redhat/postgresql-server-devel-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_6.4.aa - Upgrade
Upgrade
redhat/postgresql-test-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_6.4.aa - Upgrade
Upgrade
redhat/postgresql-upgradeto a version that resolves this vulnerability.Fixed in 13.23-1.el9_6.4.aa - Upgrade
Upgrade
redhat/postgresql-upgrade-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_6.4.aa - Upgrade
Upgrade
redhat/postgresql-upgrade-devel-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_6.4.aa - Upgrade
Upgrade
redhat/postgresql-docsto a version that resolves this vulnerability.Fixed in 13.23-1.el9_6.4 - Upgrade
Upgrade
redhat/postgresql-private-develto a version that resolves this vulnerability.Fixed in 13.23-1.el9_6.4 - Upgrade
Upgrade
redhat/postgresql-server-develto a version that resolves this vulnerability.Fixed in 13.23-1.el9_6.4 - Upgrade
Upgrade
redhat/postgresql-staticto a version that resolves this vulnerability.Fixed in 13.23-1.el9_6.4 - Upgrade
Upgrade
redhat/postgresql-testto a version that resolves this vulnerability.Fixed in 13.23-1.el9_6.4 - Upgrade
Upgrade
redhat/postgresql-test-rpm-macrosto a version that resolves this vulnerability.Fixed in 13.23-1.el9_6.4 - Upgrade
Upgrade
redhat/postgresql-upgrade-develto a version that resolves this vulnerability.Fixed in 13.23-1.el9_6.4 - Upgrade
Upgrade
redhat/postgresql-docsto a version that resolves this vulnerability.Fixed in 13.23-1.el9_6.4.aa - Upgrade
Upgrade
redhat/postgresql-private-develto a version that resolves this vulnerability.Fixed in 13.23-1.el9_6.4.aa - Upgrade
Upgrade
redhat/postgresql-server-develto a version that resolves this vulnerability.Fixed in 13.23-1.el9_6.4.aa - Upgrade
Upgrade
redhat/postgresql-staticto a version that resolves this vulnerability.Fixed in 13.23-1.el9_6.4.aa - Upgrade
Upgrade
redhat/postgresql-testto a version that resolves this vulnerability.Fixed in 13.23-1.el9_6.4.aa - Upgrade
Upgrade
redhat/postgresql-upgrade-develto a version that resolves this vulnerability.Fixed in 13.23-1.el9_6.4.aa
Event History
Frequently Asked Questions
Which PostgreSQL package variants are covered by this advisory?
The advisory covers redhat/postgresql and redhat/postgresql-contrib, along with the debuginfo, debugsource, documentation debuginfo, PL/Perl, and PL/Perl debuginfo package variants listed in the advisory.
What identifier should be used to track the underlying security issue?
Track the issue as CVE-2026-6479. The advisory identifies it as a denial-of-service issue involving uncontrolled recursion during SSL/GSS negotiation.