Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
🔗 CVE IDs covered (8)
📋 Description
CVE-2026-6472 — postgresql: PostgreSQL CREATE TYPE does not check multirange schema CREATE privilege CVE-2026-6475 — postgresql: PostgreSQL: Operating system account hijack via symlink following in pg_basebackup and pg_rewind CVE-2026-6477 — postgresql: PostgreSQL libpq: Buffer overflow allows server superuser to overwrite client stack memory CVE-2026-6478 — postgresql: PostgreSQL: Credential recovery via covert timing channel in MD5 password comparison CVE-2026-6479 — postgresql: PostgreSQL: Denial of Service via uncontrolled recursion in SSL/GSS negotiation CVE-2026-6575 — postgresql: PostgreSQL: Information disclosure via buffer over-read in pg_restore_attribute_stats() CVE-2026-6637 — postgresql: PostgreSQL: Arbitrary code execution vulnerability in 'refint' module CVE-2026-6638 — postgresql: PostgreSQL: Arbitrary SQL execution via SQL injection in logical replication
🔗 References (12)
- selfhttps://access.redhat.com/errata/RHSA-2026:21182
- externalhttps://images.redhat.com/
- externalhttps://access.redhat.com/security/cve/CVE-2026-6478
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://access.redhat.com/security/cve/CVE-2026-6477
- externalhttps://access.redhat.com/security/cve/CVE-2026-6475
- externalhttps://access.redhat.com/security/cve/CVE-2026-6575
- externalhttps://access.redhat.com/security/cve/CVE-2026-6472
- externalhttps://access.redhat.com/security/cve/CVE-2026-6479
- externalhttps://access.redhat.com/security/cve/CVE-2026-6637
- externalhttps://access.redhat.com/security/cve/CVE-2026-6638
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_21182.json