RHSA-2026:52396: Important: postgresql:12 security update
Important: postgresql:12 security update
Other sources
PostgreSQL is an advanced object-relational database management system (DBMS).Security Fix(es): postgresql: PostgreSQL: Denial of Service via uncontrolled recursion in SSL/GSS negotiation (CVE-2026-6479) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/pgauditto a version that resolves this vulnerability.Fixed in 1.4.0-7.module+el8.10.0+22214+9beb89d6 - Upgrade
Upgrade
redhat/postgres-decoderbufsto a version that resolves this vulnerability.Fixed in 0.10.0-2.module+el8.9.0+19330+c97ddbdf - Upgrade
Upgrade
redhat/postgresqlto a version that resolves this vulnerability.Fixed in 12.22-9.module+el8.10.0+24635+941a3cac - Upgrade
Upgrade
redhat/pgaudit-debuginfoto a version that resolves this vulnerability.Fixed in 1.4.0-7.module+el8.10.0+22214+9beb89d6 - Upgrade
Upgrade
redhat/pgaudit-debugsourceto a version that resolves this vulnerability.Fixed in 1.4.0-7.module+el8.10.0+22214+9beb89d6 - Upgrade
Upgrade
redhat/postgres-decoderbufs-debuginfoto a version that resolves this vulnerability.Fixed in 0.10.0-2.module+el8.9.0+19330+c97ddbdf - Upgrade
Upgrade
redhat/postgres-decoderbufs-debugsourceto a version that resolves this vulnerability.Fixed in 0.10.0-2.module+el8.9.0+19330+c97ddbdf - Upgrade
Upgrade
redhat/postgresql-contrib-debuginfoto a version that resolves this vulnerability.Fixed in 12.22-9.module+el8.10.0+24635+941a3cac - Upgrade
Upgrade
redhat/postgresql-debuginfoto a version that resolves this vulnerability.Fixed in 12.22-9.module+el8.10.0+24635+941a3cac - Upgrade
Upgrade
redhat/postgresql-debugsourceto a version that resolves this vulnerability.Fixed in 12.22-9.module+el8.10.0+24635+941a3cac - Upgrade
Upgrade
redhat/postgresql-docs-debuginfoto a version that resolves this vulnerability.Fixed in 12.22-9.module+el8.10.0+24635+941a3cac - Upgrade
Upgrade
redhat/postgresql-plperl-debuginfoto a version that resolves this vulnerability.Fixed in 12.22-9.module+el8.10.0+24635+941a3cac - Upgrade
Upgrade
redhat/postgresql-plpython3-debuginfoto a version that resolves this vulnerability.Fixed in 12.22-9.module+el8.10.0+24635+941a3cac - Upgrade
Upgrade
redhat/postgresql-pltcl-debuginfoto a version that resolves this vulnerability.Fixed in 12.22-9.module+el8.10.0+24635+941a3cac - Upgrade
Upgrade
redhat/postgresql-server-debuginfoto a version that resolves this vulnerability.Fixed in 12.22-9.module+el8.10.0+24635+941a3cac - Upgrade
Upgrade
redhat/postgresql-server-devel-debuginfoto a version that resolves this vulnerability.Fixed in 12.22-9.module+el8.10.0+24635+941a3cac - Upgrade
Upgrade
redhat/postgresql-test-debuginfoto a version that resolves this vulnerability.Fixed in 12.22-9.module+el8.10.0+24635+941a3cac - Upgrade
Upgrade
redhat/postgresql-upgrade-debuginfoto a version that resolves this vulnerability.Fixed in 12.22-9.module+el8.10.0+24635+941a3cac - Upgrade
Upgrade
redhat/postgresql-upgrade-devel-debuginfoto a version that resolves this vulnerability.Fixed in 12.22-9.module+el8.10.0+24635+941a3cac - Upgrade
Upgrade
redhat/postgresql-upgradeto a version that resolves this vulnerability.Fixed in 12.22-9.module+el8.10.0+24635+941a3cac - Upgrade
Upgrade
redhat/postgresql-upgrade-develto a version that resolves this vulnerability.Fixed in 12.22-9.module+el8.10.0+24635+941a3cac - Upgrade
Upgrade
redhat/pgauditto a version that resolves this vulnerability.Fixed in 1.4.0-7.module+el8.10.0+22214+9beb89d6.aa - Upgrade
Upgrade
redhat/pgaudit-debuginfoto a version that resolves this vulnerability.Fixed in 1.4.0-7.module+el8.10.0+22214+9beb89d6.aa - Upgrade
Upgrade
redhat/pgaudit-debugsourceto a version that resolves this vulnerability.Fixed in 1.4.0-7.module+el8.10.0+22214+9beb89d6.aa - Upgrade
Upgrade
redhat/postgres-decoderbufsto a version that resolves this vulnerability.Fixed in 0.10.0-2.module+el8.9.0+19330+c97ddbdf.aa - Upgrade
Upgrade
redhat/postgres-decoderbufs-debuginfoto a version that resolves this vulnerability.Fixed in 0.10.0-2.module+el8.9.0+19330+c97ddbdf.aa - Upgrade
Upgrade
redhat/postgres-decoderbufs-debugsourceto a version that resolves this vulnerability.Fixed in 0.10.0-2.module+el8.9.0+19330+c97ddbdf.aa - Upgrade
Upgrade
redhat/postgresqlto a version that resolves this vulnerability.Fixed in 12.22-9.module+el8.10.0+24635+941a3cac.aa - Upgrade
Upgrade
redhat/postgresql-contribto a version that resolves this vulnerability.Fixed in 12.22-9.module+el8.10.0+24635+941a3cac.aa - Upgrade
Upgrade
redhat/postgresql-contrib-debuginfoto a version that resolves this vulnerability.Fixed in 12.22-9.module+el8.10.0+24635+941a3cac.aa - Upgrade
Upgrade
redhat/postgresql-debuginfoto a version that resolves this vulnerability.Fixed in 12.22-9.module+el8.10.0+24635+941a3cac.aa - Upgrade
Upgrade
redhat/postgresql-debugsourceto a version that resolves this vulnerability.Fixed in 12.22-9.module+el8.10.0+24635+941a3cac.aa - Upgrade
Upgrade
redhat/postgresql-docs-debuginfoto a version that resolves this vulnerability.Fixed in 12.22-9.module+el8.10.0+24635+941a3cac.aa - Upgrade
Upgrade
redhat/postgresql-plperl-debuginfoto a version that resolves this vulnerability.Fixed in 12.22-9.module+el8.10.0+24635+941a3cac.aa - Upgrade
Upgrade
redhat/postgresql-plpython3-debuginfoto a version that resolves this vulnerability.Fixed in 12.22-9.module+el8.10.0+24635+941a3cac.aa - Upgrade
Upgrade
redhat/postgresql-pltcl-debuginfoto a version that resolves this vulnerability.Fixed in 12.22-9.module+el8.10.0+24635+941a3cac.aa - Upgrade
Upgrade
redhat/postgresql-server-debuginfoto a version that resolves this vulnerability.Fixed in 12.22-9.module+el8.10.0+24635+941a3cac.aa - Upgrade
Upgrade
redhat/postgresql-server-devel-debuginfoto a version that resolves this vulnerability.Fixed in 12.22-9.module+el8.10.0+24635+941a3cac.aa - Upgrade
Upgrade
redhat/postgresql-test-debuginfoto a version that resolves this vulnerability.Fixed in 12.22-9.module+el8.10.0+24635+941a3cac.aa - Upgrade
Upgrade
redhat/postgresql-upgrade-debuginfoto a version that resolves this vulnerability.Fixed in 12.22-9.module+el8.10.0+24635+941a3cac.aa - Upgrade
Upgrade
redhat/postgresql-upgrade-devel-debuginfoto a version that resolves this vulnerability.Fixed in 12.22-9.module+el8.10.0+24635+941a3cac.aa - Upgrade
Upgrade
redhat/postgresql-docsto a version that resolves this vulnerability.Fixed in 12.22-9.module+el8.10.0+24635+941a3cac.aa - Compensating control
Apply the postgresql:12 security update that addresses CVE-2026-6479 (Denial of Service via uncontrolled recursion in SSL/GSS negotiation) as described in the Red Hat advisory referenced in the prompt.
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:52396?
The severity of RHSA-2026:52396 is high (7).
What is the main issue addressed in RHSA-2026:52396?
RHSA-2026:52396 addresses a denial of service vulnerability via uncontrolled recursion in SSL/GSS negotiation (CVE-2026-6479).
How do I fix RHSA-2026:52396?
To fix RHSA-2026:52396, update your PostgreSQL installation to the latest patched version provided by Red Hat.
Which software packages are affected by RHSA-2026:52396?
The affected software packages include redhat/pgaudit, redhat/postgres-decoderbufs, and redhat/postgresql-contrib, among others.
When was RHSA-2026:52396 published?
RHSA-2026:52396 was published on August 10, 2026.