Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:34363 - Security Advisory
Issued:
2026-07-01
Updated:
2026-07-01

RHSA-2026:34363 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: postgresql:13 security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for the postgresql:13 module is now available for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support and Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

PostgreSQL is an advanced object-relational database management system (DBMS).

Security Fix(es):

  • postgresql: PostgreSQL: Operating system account hijack via symlink following in pg_basebackup and pg_rewind (CVE-2026-6475)
  • postgresql: PostgreSQL libpq: Buffer overflow allows server superuser to overwrite client stack memory (CVE-2026-6477)
  • postgresql: PostgreSQL: Credential recovery via covert timing channel in MD5 password comparison (CVE-2026-6478)
  • postgresql: integer overflow can cause an undersized allocation and an out-of-bounds write (CVE-2026-6473)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life 8.4 x86_64
  • Red Hat Enterprise Linux Server - AUS 8.4 x86_64

Fixes

  • BZ - 2477439 - CVE-2026-6475 postgresql: PostgreSQL: Operating system account hijack via symlink following in pg_basebackup and pg_rewind
  • BZ - 2477442 - CVE-2026-6477 postgresql: PostgreSQL libpq: Buffer overflow allows server superuser to overwrite client stack memory
  • BZ - 2477447 - CVE-2026-6478 postgresql: PostgreSQL: Credential recovery via covert timing channel in MD5 password comparison
  • BZ - 2477448 - CVE-2026-6473 postgresql: integer overflow can cause an undersized allocation and an out-of-bounds write

CVEs

  • CVE-2026-6473
  • CVE-2026-6475
  • CVE-2026-6477
  • CVE-2026-6478
  • CVE-2026-6637

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life 8.4

SRPM
pgaudit-1.5.0-1.module+el8.4.0+8873+b821c30a.src.rpm SHA-256: 69d37c6427f18ed1bd6d29cb2f54e083fb125c162fcb59a687c67528a2fb08e9
postgres-decoderbufs-0.10.0-2.module+el8.4.0+8873+b821c30a.src.rpm SHA-256: 1afa4d664011737a91d8efe7f3ba1f1f9bd6c8e7c510d867bbd1ff41832fe95a
postgresql-13.23-1.module+el8.4.0+24476+2b5ce087.2.src.rpm SHA-256: 13c5a4fcfd43bda12c14f122c1241c5b51ecddddc81fb3a09e77884bf11f265e
x86_64
pgaudit-1.5.0-1.module+el8.4.0+8873+b821c30a.x86_64.rpm SHA-256: 0ee2cdf7b40988a40a70294764149d58ef44f12b69ac85752465444a5b011340
pgaudit-debuginfo-1.5.0-1.module+el8.4.0+8873+b821c30a.x86_64.rpm SHA-256: ed444ce541962f85a37cae58466a203788f69a184d7dbeec159d7b424ab0ff8c
pgaudit-debugsource-1.5.0-1.module+el8.4.0+8873+b821c30a.x86_64.rpm SHA-256: 3092f6f3bd32f8b30489fed2aad9d9884f77da6872a53d6b183a49b0224e7d91
postgres-decoderbufs-0.10.0-2.module+el8.4.0+8873+b821c30a.x86_64.rpm SHA-256: c2d5f6f1d41fd29098090d75b4927696fc01450d42ae75311c14056e574645c0
postgres-decoderbufs-debuginfo-0.10.0-2.module+el8.4.0+8873+b821c30a.x86_64.rpm SHA-256: 7275a1229edefdcf0df138ea35e317fb9143461c6122cb4c8a3ec2821f5e1b65
postgres-decoderbufs-debugsource-0.10.0-2.module+el8.4.0+8873+b821c30a.x86_64.rpm SHA-256: c7145f0c47def50c037cd2694d408fa03627e7581a1303e8d7ccfb5cf47918e6
postgresql-13.23-1.module+el8.4.0+24476+2b5ce087.2.x86_64.rpm SHA-256: beff71df42d417e6f93cee58202061db1e1cbe5760e8e9f5d921ba205e0ba8b1
postgresql-contrib-13.23-1.module+el8.4.0+24476+2b5ce087.2.x86_64.rpm SHA-256: 4097f07474e98dee8b7d70d7f5a1ff4107cf13bec90fff85595489a02a26f5e3
postgresql-contrib-debuginfo-13.23-1.module+el8.4.0+24476+2b5ce087.2.x86_64.rpm SHA-256: e3bd8a625cb88a2726bc10524308e6452f2afdcb3c8b368a0408a79cec2a0696
postgresql-debuginfo-13.23-1.module+el8.4.0+24476+2b5ce087.2.x86_64.rpm SHA-256: 9f8c347a1219afc75c5f3842e227241e5bc2187c50648b03b48cebe06d9d54a4
postgresql-debugsource-13.23-1.module+el8.4.0+24476+2b5ce087.2.x86_64.rpm SHA-256: df8a9c7744fab1f3ffc2532816a70a6777857bd05da3127e6ef5ebc8c597c9a0
postgresql-docs-13.23-1.module+el8.4.0+24476+2b5ce087.2.x86_64.rpm SHA-256: 10592eccc735eced1279351dcf1c384e88722d0d634d7ee3f84b95e0c0bc270a
postgresql-docs-debuginfo-13.23-1.module+el8.4.0+24476+2b5ce087.2.x86_64.rpm SHA-256: 209b41074b7d3870cecf32ceb67f2e4d7c3fdbe0f2e82b3c982d961471e247f3
postgresql-plperl-13.23-1.module+el8.4.0+24476+2b5ce087.2.x86_64.rpm SHA-256: 97666475c1c5a605b7128e8b7f2f1c685e3305635313b8c5bbbe42023f7cb484
postgresql-plperl-debuginfo-13.23-1.module+el8.4.0+24476+2b5ce087.2.x86_64.rpm SHA-256: 7ccd55cfc1156ac8743ae90f1b41f304d5d7eec41d6f98ee2b853f41e9cf2c69
postgresql-plpython3-13.23-1.module+el8.4.0+24476+2b5ce087.2.x86_64.rpm SHA-256: d145bfdb21cc525df032948f7a7445b88c73d67910f2a0445861ebd69f09c4da
postgresql-plpython3-debuginfo-13.23-1.module+el8.4.0+24476+2b5ce087.2.x86_64.rpm SHA-256: ea9a52387e99c92dfb3008e65d888006980c8e6054a09e1f70fcdfc358bd5ab5
postgresql-pltcl-13.23-1.module+el8.4.0+24476+2b5ce087.2.x86_64.rpm SHA-256: 538426480784ad7a7f4b1c728bc23196fb1cca0e979ebc2081a31511f277f9a0
postgresql-pltcl-debuginfo-13.23-1.module+el8.4.0+24476+2b5ce087.2.x86_64.rpm SHA-256: 8831a90b3c868f4c213ff8a1bff555bf0e1540c2f0969cbca2ae2039d4621711
postgresql-server-13.23-1.module+el8.4.0+24476+2b5ce087.2.x86_64.rpm SHA-256: 3c7c23f060bac6a1359276babd7250253578b503ca326471e68b1dc2581b6725
postgresql-server-debuginfo-13.23-1.module+el8.4.0+24476+2b5ce087.2.x86_64.rpm SHA-256: 075cc5f6dda8c61ae0705e7609430fb78f853fc7686b36b14f99637bcf3c6ee1
postgresql-server-devel-13.23-1.module+el8.4.0+24476+2b5ce087.2.x86_64.rpm SHA-256: 4f82c5a0872a98840ec2044a78be014a297e871433e782c73f011e3caaf62c67
postgresql-server-devel-debuginfo-13.23-1.module+el8.4.0+24476+2b5ce087.2.x86_64.rpm SHA-256: a1626e0c72753822fbf1b6130b387d98062274dbf3b49d8808346e1342a253c1
postgresql-static-13.23-1.module+el8.4.0+24476+2b5ce087.2.x86_64.rpm SHA-256: 178d65462944c2e385222e7d72a1ac2bca398be2d8c9dba723b82dd87d47aec6
postgresql-test-13.23-1.module+el8.4.0+24476+2b5ce087.2.x86_64.rpm SHA-256: 002baf1957ca62c09047c5bf6664e754756815c3ea9517fde763c44eee7ab2d4
postgresql-test-debuginfo-13.23-1.module+el8.4.0+24476+2b5ce087.2.x86_64.rpm SHA-256: 1651263adf64ca2e2576197cfbef5d6f3a985a17dba14e52892bd21f94a021f8
postgresql-test-rpm-macros-13.23-1.module+el8.4.0+24476+2b5ce087.2.noarch.rpm SHA-256: 4a677e2dd7d4dcad17fd769d4d968d72c27cfa732cbe8f20ba352fbe4cac0dd7
postgresql-upgrade-13.23-1.module+el8.4.0+24476+2b5ce087.2.x86_64.rpm SHA-256: 27bc0a80302f5dce1b3ac2499b2f6c457b7d74f6d1e5e449a32175485dc16263
postgresql-upgrade-debuginfo-13.23-1.module+el8.4.0+24476+2b5ce087.2.x86_64.rpm SHA-256: c3c0cce7b16fb1242933b94104e8ea555354cf93c6c48ff0e5aab2121f65330a
postgresql-upgrade-devel-13.23-1.module+el8.4.0+24476+2b5ce087.2.x86_64.rpm SHA-256: 1469780603367087c78b7e55105f9928ef19f49220ac118447d20635bb5c5c2f
postgresql-upgrade-devel-debuginfo-13.23-1.module+el8.4.0+24476+2b5ce087.2.x86_64.rpm SHA-256: 1125d54097c29621814fc20517f4d7f760eaae2bcbbf6f970f29d146b2224405

Red Hat Enterprise Linux Server - AUS 8.4

SRPM
pgaudit-1.5.0-1.module+el8.4.0+8873+b821c30a.src.rpm SHA-256: 69d37c6427f18ed1bd6d29cb2f54e083fb125c162fcb59a687c67528a2fb08e9
postgres-decoderbufs-0.10.0-2.module+el8.4.0+8873+b821c30a.src.rpm SHA-256: 1afa4d664011737a91d8efe7f3ba1f1f9bd6c8e7c510d867bbd1ff41832fe95a
postgresql-13.23-1.module+el8.4.0+24476+2b5ce087.2.src.rpm SHA-256: 13c5a4fcfd43bda12c14f122c1241c5b51ecddddc81fb3a09e77884bf11f265e
x86_64
pgaudit-1.5.0-1.module+el8.4.0+8873+b821c30a.x86_64.rpm SHA-256: 0ee2cdf7b40988a40a70294764149d58ef44f12b69ac85752465444a5b011340
pgaudit-debuginfo-1.5.0-1.module+el8.4.0+8873+b821c30a.x86_64.rpm SHA-256: ed444ce541962f85a37cae58466a203788f69a184d7dbeec159d7b424ab0ff8c
pgaudit-debugsource-1.5.0-1.module+el8.4.0+8873+b821c30a.x86_64.rpm SHA-256: 3092f6f3bd32f8b30489fed2aad9d9884f77da6872a53d6b183a49b0224e7d91
postgres-decoderbufs-0.10.0-2.module+el8.4.0+8873+b821c30a.x86_64.rpm SHA-256: c2d5f6f1d41fd29098090d75b4927696fc01450d42ae75311c14056e574645c0
postgres-decoderbufs-debuginfo-0.10.0-2.module+el8.4.0+8873+b821c30a.x86_64.rpm SHA-256: 7275a1229edefdcf0df138ea35e317fb9143461c6122cb4c8a3ec2821f5e1b65
postgres-decoderbufs-debugsource-0.10.0-2.module+el8.4.0+8873+b821c30a.x86_64.rpm SHA-256: c7145f0c47def50c037cd2694d408fa03627e7581a1303e8d7ccfb5cf47918e6
postgresql-13.23-1.module+el8.4.0+24476+2b5ce087.2.x86_64.rpm SHA-256: beff71df42d417e6f93cee58202061db1e1cbe5760e8e9f5d921ba205e0ba8b1
postgresql-contrib-13.23-1.module+el8.4.0+24476+2b5ce087.2.x86_64.rpm SHA-256: 4097f07474e98dee8b7d70d7f5a1ff4107cf13bec90fff85595489a02a26f5e3
postgresql-contrib-debuginfo-13.23-1.module+el8.4.0+24476+2b5ce087.2.x86_64.rpm SHA-256: e3bd8a625cb88a2726bc10524308e6452f2afdcb3c8b368a0408a79cec2a0696
postgresql-debuginfo-13.23-1.module+el8.4.0+24476+2b5ce087.2.x86_64.rpm SHA-256: 9f8c347a1219afc75c5f3842e227241e5bc2187c50648b03b48cebe06d9d54a4
postgresql-debugsource-13.23-1.module+el8.4.0+24476+2b5ce087.2.x86_64.rpm SHA-256: df8a9c7744fab1f3ffc2532816a70a6777857bd05da3127e6ef5ebc8c597c9a0
postgresql-docs-13.23-1.module+el8.4.0+24476+2b5ce087.2.x86_64.rpm SHA-256: 10592eccc735eced1279351dcf1c384e88722d0d634d7ee3f84b95e0c0bc270a
postgresql-docs-debuginfo-13.23-1.module+el8.4.0+24476+2b5ce087.2.x86_64.rpm SHA-256: 209b41074b7d3870cecf32ceb67f2e4d7c3fdbe0f2e82b3c982d961471e247f3
postgresql-plperl-13.23-1.module+el8.4.0+24476+2b5ce087.2.x86_64.rpm SHA-256: 97666475c1c5a605b7128e8b7f2f1c685e3305635313b8c5bbbe42023f7cb484
postgresql-plperl-debuginfo-13.23-1.module+el8.4.0+24476+2b5ce087.2.x86_64.rpm SHA-256: 7ccd55cfc1156ac8743ae90f1b41f304d5d7eec41d6f98ee2b853f41e9cf2c69
postgresql-plpython3-13.23-1.module+el8.4.0+24476+2b5ce087.2.x86_64.rpm SHA-256: d145bfdb21cc525df032948f7a7445b88c73d67910f2a0445861ebd69f09c4da
postgresql-plpython3-debuginfo-13.23-1.module+el8.4.0+24476+2b5ce087.2.x86_64.rpm SHA-256: ea9a52387e99c92dfb3008e65d888006980c8e6054a09e1f70fcdfc358bd5ab5
postgresql-pltcl-13.23-1.module+el8.4.0+24476+2b5ce087.2.x86_64.rpm SHA-256: 538426480784ad7a7f4b1c728bc23196fb1cca0e979ebc2081a31511f277f9a0
postgresql-pltcl-debuginfo-13.23-1.module+el8.4.0+24476+2b5ce087.2.x86_64.rpm SHA-256: 8831a90b3c868f4c213ff8a1bff555bf0e1540c2f0969cbca2ae2039d4621711
postgresql-server-13.23-1.module+el8.4.0+24476+2b5ce087.2.x86_64.rpm SHA-256: 3c7c23f060bac6a1359276babd7250253578b503ca326471e68b1dc2581b6725
postgresql-server-debuginfo-13.23-1.module+el8.4.0+24476+2b5ce087.2.x86_64.rpm SHA-256: 075cc5f6dda8c61ae0705e7609430fb78f853fc7686b36b14f99637bcf3c6ee1
postgresql-server-devel-13.23-1.module+el8.4.0+24476+2b5ce087.2.x86_64.rpm SHA-256: 4f82c5a0872a98840ec2044a78be014a297e871433e782c73f011e3caaf62c67
postgresql-server-devel-debuginfo-13.23-1.module+el8.4.0+24476+2b5ce087.2.x86_64.rpm SHA-256: a1626e0c72753822fbf1b6130b387d98062274dbf3b49d8808346e1342a253c1
postgresql-static-13.23-1.module+el8.4.0+24476+2b5ce087.2.x86_64.rpm SHA-256: 178d65462944c2e385222e7d72a1ac2bca398be2d8c9dba723b82dd87d47aec6
postgresql-test-13.23-1.module+el8.4.0+24476+2b5ce087.2.x86_64.rpm SHA-256: 002baf1957ca62c09047c5bf6664e754756815c3ea9517fde763c44eee7ab2d4
postgresql-test-debuginfo-13.23-1.module+el8.4.0+24476+2b5ce087.2.x86_64.rpm SHA-256: 1651263adf64ca2e2576197cfbef5d6f3a985a17dba14e52892bd21f94a021f8
postgresql-test-rpm-macros-13.23-1.module+el8.4.0+24476+2b5ce087.2.noarch.rpm SHA-256: 4a677e2dd7d4dcad17fd769d4d968d72c27cfa732cbe8f20ba352fbe4cac0dd7
postgresql-upgrade-13.23-1.module+el8.4.0+24476+2b5ce087.2.x86_64.rpm SHA-256: 27bc0a80302f5dce1b3ac2499b2f6c457b7d74f6d1e5e449a32175485dc16263
postgresql-upgrade-debuginfo-13.23-1.module+el8.4.0+24476+2b5ce087.2.x86_64.rpm SHA-256: c3c0cce7b16fb1242933b94104e8ea555354cf93c6c48ff0e5aab2121f65330a
postgresql-upgrade-devel-13.23-1.module+el8.4.0+24476+2b5ce087.2.x86_64.rpm SHA-256: 1469780603367087c78b7e55105f9928ef19f49220ac118447d20635bb5c5c2f
postgresql-upgrade-devel-debuginfo-13.23-1.module+el8.4.0+24476+2b5ce087.2.x86_64.rpm SHA-256: 1125d54097c29621814fc20517f4d7f760eaae2bcbbf6f970f29d146b2224405

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility