Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:4518 - Security Advisory
Issued:
2026-03-12
Updated:
2026-03-12

RHSA-2026:4518 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: postgresql security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for postgresql is now available for Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

PostgreSQL is an advanced object-relational database management system (DBMS).

Security Fix(es):

  • postgresql: PostgreSQL missing validation of multibyte character length executes arbitrary code (CVE-2026-2006)
  • postgresql: PostgreSQL intarray missing validation of type of input to selectivity estimator executes arbitrary code (CVE-2026-2004)
  • postgresql: PostgreSQL pgcrypto heap buffer overflow executes arbitrary code (CVE-2026-2005)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.0 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0 x86_64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.0 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.0 s390x

Fixes

  • BZ - 2439324 - CVE-2026-2006 postgresql: PostgreSQL missing validation of multibyte character length executes arbitrary code
  • BZ - 2439325 - CVE-2026-2004 postgresql: PostgreSQL intarray missing validation of type of input to selectivity estimator executes arbitrary code
  • BZ - 2439326 - CVE-2026-2005 postgresql: PostgreSQL pgcrypto heap buffer overflow executes arbitrary code

CVEs

  • CVE-2026-2004
  • CVE-2026-2005
  • CVE-2026-2006

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.0

SRPM
postgresql-13.23-1.el9_0.1.src.rpm SHA-256: 2300069d6e823961985436899ce53ec4db2881784644a41db10fcd403e72a3f5
ppc64le
postgresql-13.23-1.el9_0.1.ppc64le.rpm SHA-256: 3e93d6be9f298b550b4a9b359907bfc51d28716c818bcb1c3d16e6477da22b9e
postgresql-contrib-13.23-1.el9_0.1.ppc64le.rpm SHA-256: f89da20b6fe0ccc8f4d32aa5fdfec997805d23f7feff7b707713dd2ef5379e2f
postgresql-contrib-debuginfo-13.23-1.el9_0.1.ppc64le.rpm SHA-256: dfc9215a34e3c78dc231aced7faa6679e6990d724b74114c530ceccc5cd8729a
postgresql-debuginfo-13.23-1.el9_0.1.ppc64le.rpm SHA-256: c3be48aef279a11db7472cff09073d8a4c5aea762c65da821508de4e45facb17
postgresql-debugsource-13.23-1.el9_0.1.ppc64le.rpm SHA-256: 3d53ea141e14b70f20ca1b7dae5f3c98a0562a085e1e759f598ad9c0ae37d80c
postgresql-docs-debuginfo-13.23-1.el9_0.1.ppc64le.rpm SHA-256: d8bd2951ab93820e41d13e99bd1d827229cbd590ad9c55b746c69094f27a6ecc
postgresql-plperl-13.23-1.el9_0.1.ppc64le.rpm SHA-256: 6323ba655e09885dfb191f0ae172934d8bd27180267c3a1571fa5569392d344e
postgresql-plperl-debuginfo-13.23-1.el9_0.1.ppc64le.rpm SHA-256: 8d344a2397e1676f6b781291d12634681095b7a811d58adf09d30a16a3cf4ca2
postgresql-plpython3-13.23-1.el9_0.1.ppc64le.rpm SHA-256: 6f26e727de6cb7e0e53cec40923ab8ede9cb3f0fe62dec22a557595df8efaf45
postgresql-plpython3-debuginfo-13.23-1.el9_0.1.ppc64le.rpm SHA-256: 1e76347b43905227871f41120034827441e2130efd0aacf1cfcc6f520c9667df
postgresql-pltcl-13.23-1.el9_0.1.ppc64le.rpm SHA-256: 6d9ab2857c399ae4706a05f5fcc749fe4b059c598abe33bad5060991f83644d1
postgresql-pltcl-debuginfo-13.23-1.el9_0.1.ppc64le.rpm SHA-256: 88e77553a28ad13304f82641e4f02474a459b8f5683dd1366c208c4921f8251e
postgresql-private-libs-13.23-1.el9_0.1.ppc64le.rpm SHA-256: 6d6bce9f5ef4297fa02aead9a68807a73e5fa7b06256d3cbb0f2750ed617bcae
postgresql-private-libs-debuginfo-13.23-1.el9_0.1.ppc64le.rpm SHA-256: 3eaa25cdfc3d0e2c9235715ba1513148579ed94c3895ef6ccc048fbafa0b158c
postgresql-server-13.23-1.el9_0.1.ppc64le.rpm SHA-256: d9825e2e072461513fb4c3ad60d53ca06b5c62b141dfd3444dad1825b07030de
postgresql-server-debuginfo-13.23-1.el9_0.1.ppc64le.rpm SHA-256: 0ca299e04dc2f3b9f2f3402e58d1fcf1561755291504e3b3b04fed95c739d57c
postgresql-server-devel-debuginfo-13.23-1.el9_0.1.ppc64le.rpm SHA-256: 1667c476659ba84129167a96710e196cd464bb887cf8d2ec41d08da51ddc15f8
postgresql-test-debuginfo-13.23-1.el9_0.1.ppc64le.rpm SHA-256: dae92fd16b47b29f9323913768012e4c1fb2c588f52d421b1ebd02c5610ea0a3
postgresql-upgrade-13.23-1.el9_0.1.ppc64le.rpm SHA-256: 62ac5e78a438f03caca33072a1e38833fdae7c8da4f84bdc01c878cf38f1b8b6
postgresql-upgrade-debuginfo-13.23-1.el9_0.1.ppc64le.rpm SHA-256: ffb2b83cb2422f7fd844c9919f3bf6b810d0b012d4890b8f4af2b69dd6ce0ac0
postgresql-upgrade-devel-debuginfo-13.23-1.el9_0.1.ppc64le.rpm SHA-256: 187fed817b92ed38bd6ef7b0f02730dc02278d63f5f4f1424aa8b7d550813c52

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0

SRPM
postgresql-13.23-1.el9_0.1.src.rpm SHA-256: 2300069d6e823961985436899ce53ec4db2881784644a41db10fcd403e72a3f5
x86_64
postgresql-13.23-1.el9_0.1.x86_64.rpm SHA-256: 6117531034d855e6841e8b4e7ae7a342287f2047da9e5aa4fd9cd3173729e5b7
postgresql-contrib-13.23-1.el9_0.1.x86_64.rpm SHA-256: c40e6f7be6fd30abd6bc40aa7c34fae2ec617e740d8010cd2d01b75b4e06e2ce
postgresql-contrib-debuginfo-13.23-1.el9_0.1.x86_64.rpm SHA-256: 8d5123bcdd14bb674f137d4715240cb08a8750626474b292e43d6fa3a32e6bbd
postgresql-debuginfo-13.23-1.el9_0.1.x86_64.rpm SHA-256: 1684c7e6e2727d2b65b4e0bff0199b7ea60cb7b8702170991c076bdc314dbee9
postgresql-debugsource-13.23-1.el9_0.1.x86_64.rpm SHA-256: f153b6fe18c3ddfaf59f5502ebf573e0936d301fe4aa99a05457c9a36004225f
postgresql-docs-debuginfo-13.23-1.el9_0.1.x86_64.rpm SHA-256: dba7b64d104c313d903d398f15982198365da30f3755fbd0dd4df4156d501482
postgresql-plperl-13.23-1.el9_0.1.x86_64.rpm SHA-256: a14dc335b54700508e314ab4b4875cc942e5b7e2d0b18ec15bd8ed2b65136043
postgresql-plperl-debuginfo-13.23-1.el9_0.1.x86_64.rpm SHA-256: 29249d825a148254844852b2514e3a376a65f4bb6b86b435445ec182b5a5c1cb
postgresql-plpython3-13.23-1.el9_0.1.x86_64.rpm SHA-256: 3975cc779b7e2aa3e91883e0796524f1a9288233ab903aeb8e0af09811339e97
postgresql-plpython3-debuginfo-13.23-1.el9_0.1.x86_64.rpm SHA-256: a6d345e4adc1f1a51ee4cc8943cd9df6d7c8eab000bfa683f0e230d309ac6da2
postgresql-pltcl-13.23-1.el9_0.1.x86_64.rpm SHA-256: fd3fe82af18dd89e07c66b69a349715fb07cc021ca83b3d8fc042aab69aeb627
postgresql-pltcl-debuginfo-13.23-1.el9_0.1.x86_64.rpm SHA-256: 8bb4fd98fd8777ce6929d19777f409453c112868311b0e6113ad5bc508684186
postgresql-private-libs-13.23-1.el9_0.1.x86_64.rpm SHA-256: daa5fcf7f61252a0b803df1a35ac9060be7cceff400ee58e2529f41d42a17f54
postgresql-private-libs-debuginfo-13.23-1.el9_0.1.x86_64.rpm SHA-256: dee58e8e84d61d5e700377d732124d2379b97d8d6e49f0a52e617b8b38399558
postgresql-server-13.23-1.el9_0.1.x86_64.rpm SHA-256: 08abe73e965d6505f54c5efdd2188996165f37803435bfdd788ff4deba99abe6
postgresql-server-debuginfo-13.23-1.el9_0.1.x86_64.rpm SHA-256: 6a1d6fe268e762e8bc60831c1839e7ca41ad3a4679d1ba1ba56f9116e8a0f94d
postgresql-server-devel-debuginfo-13.23-1.el9_0.1.x86_64.rpm SHA-256: fb31c51d059da33727a0f3b35c5bf669f7b271f83602a0e5633b526b8c47dba1
postgresql-test-debuginfo-13.23-1.el9_0.1.x86_64.rpm SHA-256: d50ab6a5b5e5a36a6adc65b4c67b1ffba3679d6440cd4ba068ce1d5d9fb972f2
postgresql-upgrade-13.23-1.el9_0.1.x86_64.rpm SHA-256: 4313fecf9db218f50d0243cf36a35402ffdae1bc39af6d482c98c043518e0e6d
postgresql-upgrade-debuginfo-13.23-1.el9_0.1.x86_64.rpm SHA-256: a9346d146184872aee00caead08cc6531f60867ff60e5b338fc1aca1006e305b
postgresql-upgrade-devel-debuginfo-13.23-1.el9_0.1.x86_64.rpm SHA-256: f7c315a12b4541c5f7590943467f3afa309ef048ee5db29312aafb6bca809330

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.0

SRPM
postgresql-13.23-1.el9_0.1.src.rpm SHA-256: 2300069d6e823961985436899ce53ec4db2881784644a41db10fcd403e72a3f5
aarch64
postgresql-13.23-1.el9_0.1.aarch64.rpm SHA-256: 9c2a02ee105b888b21d143637fe62d8c85b151fb6e1a902c2a15a877048534f9
postgresql-contrib-13.23-1.el9_0.1.aarch64.rpm SHA-256: deaa402de73ae3ad0c0e212f4aa74dbc4bb39dc75a0a420cda691451d49cf8e9
postgresql-contrib-debuginfo-13.23-1.el9_0.1.aarch64.rpm SHA-256: 887503c3a23c7cdef6c595dabd0b45ce9eaefd6481e574794795f67764ea0e40
postgresql-debuginfo-13.23-1.el9_0.1.aarch64.rpm SHA-256: c13fbba7190ac25e6d47f548941a964cf7a1b67bf3bf4e87303e36a16713e822
postgresql-debugsource-13.23-1.el9_0.1.aarch64.rpm SHA-256: 478753595ea74533850305d2a2673033021c54cc6cd1cbd9c738a56f983ea087
postgresql-docs-debuginfo-13.23-1.el9_0.1.aarch64.rpm SHA-256: 221ccbf8feb1a09b7f4b770b7c790ad161e79867f58bb40e833c1ab8379e896e
postgresql-plperl-13.23-1.el9_0.1.aarch64.rpm SHA-256: d1813894730d42413f017b4c415effa6bbc8404c3d8020bc7d31bdac4e09885e
postgresql-plperl-debuginfo-13.23-1.el9_0.1.aarch64.rpm SHA-256: 448521bb1f8d9f6f9c9ba6b24dc6aa50d3863536acda96527c688fcb0899927a
postgresql-plpython3-13.23-1.el9_0.1.aarch64.rpm SHA-256: e374d597d61e3c8f51665f671c3f2d2b916d51af0f62a77ec575048ec2d2e541
postgresql-plpython3-debuginfo-13.23-1.el9_0.1.aarch64.rpm SHA-256: 1acb508ac449f9522376a7ccea0a6abe21e101af4220629ce24b515a704cc95e
postgresql-pltcl-13.23-1.el9_0.1.aarch64.rpm SHA-256: e41ca2568c182ec6ee94a57151f74494cd14458fbacb94da98bdb57dc2337a0e
postgresql-pltcl-debuginfo-13.23-1.el9_0.1.aarch64.rpm SHA-256: d87cb8a78d2efb8f165daf3d940ffdced9e2c764108ef9e381a16c2eac02711c
postgresql-private-libs-13.23-1.el9_0.1.aarch64.rpm SHA-256: 008a70d96415e05505e797128da49c309ef263816ac938f644b69cf74e292123
postgresql-private-libs-debuginfo-13.23-1.el9_0.1.aarch64.rpm SHA-256: 9aeb9382648d3343e78514420efa22f918a4e539b4a663d2875843ea7a927663
postgresql-server-13.23-1.el9_0.1.aarch64.rpm SHA-256: 9ae46039244d14864a12b9f2efe31d50b85ab6707797d50def2a40e0f472c80a
postgresql-server-debuginfo-13.23-1.el9_0.1.aarch64.rpm SHA-256: ed2095a42abf9878d17b573714fdc933e7a867e568dc30323edab54ba2d522c0
postgresql-server-devel-debuginfo-13.23-1.el9_0.1.aarch64.rpm SHA-256: 6681b5038380fc8c2cba48da56528df3f969b16def5a2bcd2dc12d57a12274a2
postgresql-test-debuginfo-13.23-1.el9_0.1.aarch64.rpm SHA-256: 01e2db90726bddc24cc1bd6ccd89122273e5e6cfc01b7b4050bb164f690fce12
postgresql-upgrade-13.23-1.el9_0.1.aarch64.rpm SHA-256: b2722cdf1b756330f7bb162e18e5424be469226279aef3557e60a9fd9ac7dc9c
postgresql-upgrade-debuginfo-13.23-1.el9_0.1.aarch64.rpm SHA-256: 17b2ec779c18a813e84a977ee7509689f45f5048b7558c608f0372368f36271c
postgresql-upgrade-devel-debuginfo-13.23-1.el9_0.1.aarch64.rpm SHA-256: f70d7c25dc8101965ed4a90cd1f520d09a6341f3608b2fd8a55b272ddbce0a92

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.0

SRPM
postgresql-13.23-1.el9_0.1.src.rpm SHA-256: 2300069d6e823961985436899ce53ec4db2881784644a41db10fcd403e72a3f5
s390x
postgresql-13.23-1.el9_0.1.s390x.rpm SHA-256: 9a68224e5f9f83bbd378e8a965c66da2460f0deb1d11ee1ce9a0614a2b2f51e8
postgresql-contrib-13.23-1.el9_0.1.s390x.rpm SHA-256: 6f604e9208c4128928975799cc466c85e65476af3d7c878e9a1371f5663fb92a
postgresql-contrib-debuginfo-13.23-1.el9_0.1.s390x.rpm SHA-256: 7f08205d4945f3f3c82f42f666c1a557addce0a6c12f2bd87cff6a9884551d6d
postgresql-debuginfo-13.23-1.el9_0.1.s390x.rpm SHA-256: 0d6cb3a1dfd37f0c0625ba60efcbb56fd40059ffeaae30c23d8b470c320702da
postgresql-debugsource-13.23-1.el9_0.1.s390x.rpm SHA-256: 883284461cfb1e461ad6bf5ada18594bac709665b2944c8505b8c4ea7a7d2e3e
postgresql-docs-debuginfo-13.23-1.el9_0.1.s390x.rpm SHA-256: 02e78b1fb1fde1f26b82c24a19fff78f74ee11c823c7db614920fd13d0c3357b
postgresql-plperl-13.23-1.el9_0.1.s390x.rpm SHA-256: 51535d727bcf7574ea61c6bb97c9a3552a0d294e6a3873a904bd260c7009c2d8
postgresql-plperl-debuginfo-13.23-1.el9_0.1.s390x.rpm SHA-256: 81f881ffdb5376c8f2d86dbb16908ce82b559611b75849a75e5b6dbac9c22a3e
postgresql-plpython3-13.23-1.el9_0.1.s390x.rpm SHA-256: 53afda4adf46ff2d459e7b18617b9132bf363b6663e3a42fa1c562c9ca8e5cbe
postgresql-plpython3-debuginfo-13.23-1.el9_0.1.s390x.rpm SHA-256: b9c56c2b539da17e0e73c3b8cd881772e3c128a72571b36d7a7b3fd248aa0107
postgresql-pltcl-13.23-1.el9_0.1.s390x.rpm SHA-256: 896a20359f9580d424ac180bd89f89f4c9a93ee63cceae1d05bc9d36e4f3b678
postgresql-pltcl-debuginfo-13.23-1.el9_0.1.s390x.rpm SHA-256: 7790cfdc09cdd81a435b77377aae514abbbc6d9366db70051c81abf4d9f3d6c6
postgresql-private-libs-13.23-1.el9_0.1.s390x.rpm SHA-256: 016892a899bdc52fdf27afd27ebdf08587bc387addad5a38dc1f531252b08f8c
postgresql-private-libs-debuginfo-13.23-1.el9_0.1.s390x.rpm SHA-256: 6a52a81b47ca33822843d11a68dc5062bc42b8180466b23ed2110184c134393d
postgresql-server-13.23-1.el9_0.1.s390x.rpm SHA-256: cb45432258f70a379174ad7dd64d2ace0afb4e73c394476e31557fcb1f2af536
postgresql-server-debuginfo-13.23-1.el9_0.1.s390x.rpm SHA-256: 7545c69e6036ca4ebe2276350eef0726f87ef9ff8bb874d4e080b064dd47a4cf
postgresql-server-devel-debuginfo-13.23-1.el9_0.1.s390x.rpm SHA-256: 903f4812f9ac59ef1f5b6bf404c6d2113c024e885c56ec0e484a76367e3aa772
postgresql-test-debuginfo-13.23-1.el9_0.1.s390x.rpm SHA-256: b13c31a2412ffff6c7cea4b742305d34819f478e340eff0579e4f0b7a3dbaf00
postgresql-upgrade-13.23-1.el9_0.1.s390x.rpm SHA-256: e539cf6e373022d445494e43114d6c05b501520a358938f999ef892209bcdef2
postgresql-upgrade-debuginfo-13.23-1.el9_0.1.s390x.rpm SHA-256: 4ddcd9c0c4af6842c15d4b02a9c7843f3b25df595c10784f8487ac3b742affac
postgresql-upgrade-devel-debuginfo-13.23-1.el9_0.1.s390x.rpm SHA-256: e7ca6c5306f3d0827d78136d081cd18aaa94cc27885d74d13817be0df5cf0ebe

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility