RHSA-2026:62117: Important: postgresql security update
Important: postgresql security update
Other sources
PostgreSQL is an advanced object-relational database management system (DBMS).Security Fix(es): postgresql: PostgreSQL: Denial of Service via uncontrolled recursion in SSL/GSS negotiation (CVE-2026-6479) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/postgresqlto a version that resolves this vulnerability.Fixed in 13.23-1.el9_4.3 - Upgrade
Upgrade
redhat/postgresql-contribto a version that resolves this vulnerability.Fixed in 13.23-1.el9_4.3 - Upgrade
Upgrade
redhat/postgresql-contrib-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_4.3 - Upgrade
Upgrade
redhat/postgresql-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_4.3 - Upgrade
Upgrade
redhat/postgresql-debugsourceto a version that resolves this vulnerability.Fixed in 13.23-1.el9_4.3 - Upgrade
Upgrade
redhat/postgresql-docs-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_4.3 - Upgrade
Upgrade
redhat/postgresql-plperlto a version that resolves this vulnerability.Fixed in 13.23-1.el9_4.3 - Upgrade
Upgrade
redhat/postgresql-plperl-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_4.3 - Upgrade
Upgrade
redhat/postgresql-plpython3to a version that resolves this vulnerability.Fixed in 13.23-1.el9_4.3 - Upgrade
Upgrade
redhat/postgresql-plpython3-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_4.3 - Upgrade
Upgrade
redhat/postgresql-pltclto a version that resolves this vulnerability.Fixed in 13.23-1.el9_4.3 - Upgrade
Upgrade
redhat/postgresql-pltcl-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_4.3 - Upgrade
Upgrade
redhat/postgresql-private-libsto a version that resolves this vulnerability.Fixed in 13.23-1.el9_4.3 - Upgrade
Upgrade
redhat/postgresql-private-libs-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_4.3 - Upgrade
Upgrade
redhat/postgresql-serverto a version that resolves this vulnerability.Fixed in 13.23-1.el9_4.3 - Upgrade
Upgrade
redhat/postgresql-server-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_4.3 - Upgrade
Upgrade
redhat/postgresql-server-devel-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_4.3 - Upgrade
Upgrade
redhat/postgresql-test-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_4.3 - Upgrade
Upgrade
redhat/postgresql-upgradeto a version that resolves this vulnerability.Fixed in 13.23-1.el9_4.3 - Upgrade
Upgrade
redhat/postgresql-upgrade-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_4.3 - Upgrade
Upgrade
redhat/postgresql-upgrade-devel-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_4.3 - Upgrade
Upgrade
redhat/postgresqlto a version that resolves this vulnerability.Fixed in 13.23-1.el9_4.3.aa - Upgrade
Upgrade
redhat/postgresql-contribto a version that resolves this vulnerability.Fixed in 13.23-1.el9_4.3.aa - Upgrade
Upgrade
redhat/postgresql-contrib-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_4.3.aa - Upgrade
Upgrade
redhat/postgresql-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_4.3.aa - Upgrade
Upgrade
redhat/postgresql-debugsourceto a version that resolves this vulnerability.Fixed in 13.23-1.el9_4.3.aa - Upgrade
Upgrade
redhat/postgresql-docs-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_4.3.aa - Upgrade
Upgrade
redhat/postgresql-plperlto a version that resolves this vulnerability.Fixed in 13.23-1.el9_4.3.aa - Upgrade
Upgrade
redhat/postgresql-plperl-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_4.3.aa - Upgrade
Upgrade
redhat/postgresql-plpython3to a version that resolves this vulnerability.Fixed in 13.23-1.el9_4.3.aa - Upgrade
Upgrade
redhat/postgresql-plpython3-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_4.3.aa - Upgrade
Upgrade
redhat/postgresql-pltclto a version that resolves this vulnerability.Fixed in 13.23-1.el9_4.3.aa - Upgrade
Upgrade
redhat/postgresql-pltcl-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_4.3.aa - Upgrade
Upgrade
redhat/postgresql-private-libsto a version that resolves this vulnerability.Fixed in 13.23-1.el9_4.3.aa - Upgrade
Upgrade
redhat/postgresql-private-libs-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_4.3.aa - Upgrade
Upgrade
redhat/postgresql-serverto a version that resolves this vulnerability.Fixed in 13.23-1.el9_4.3.aa - Upgrade
Upgrade
redhat/postgresql-server-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_4.3.aa - Upgrade
Upgrade
redhat/postgresql-server-devel-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_4.3.aa - Upgrade
Upgrade
redhat/postgresql-test-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_4.3.aa - Upgrade
Upgrade
redhat/postgresql-upgradeto a version that resolves this vulnerability.Fixed in 13.23-1.el9_4.3.aa - Upgrade
Upgrade
redhat/postgresql-upgrade-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_4.3.aa - Upgrade
Upgrade
redhat/postgresql-upgrade-devel-debuginfoto a version that resolves this vulnerability.Fixed in 13.23-1.el9_4.3.aa
Event History
Frequently Asked Questions
What systems are exposed to this issue?
Systems running the affected Red Hat PostgreSQL packages are in scope, including postgresql and postgresql-contrib, along with the listed related subpackages. The provided advisory does not identify specific affected package versions or configurations.
What is the impact of successful exploitation?
The issue is identified as CVE-2026-6479 and can cause a denial of service through uncontrolled recursion during SSL/GSS negotiation. The advisory classifies the update as Important and rates the severity as high.
What should be done to remediate the issue?
Apply the RHSA-2026:62117 PostgreSQL security update for the relevant installed Red Hat PostgreSQL packages. The supplied information does not provide an alternative mitigation for environments where patching must be delayed.