Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.2 security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2026-6473 — postgresql: integer overflow can cause an undersized allocation and an out-of-bounds write CVE-2026-6479 — postgresql: PostgreSQL: Denial of Service via uncontrolled recursion in SSL/GSS negotiation
🎯 Affected products2
- Red Hat Ansible Automation Platform 2.2
- registry.redhat.io/ansible-automation-platform/bootc-automation-portal-rhel9@sha256:f431dddfcb88b3d90db1607423bc451993dd39e7e182b047cf673594d39bc186_amd64 as a component of Red Hat Ansible Automation Platform 2.2
✅ Remediation
For more about Ansible Portal Installer Bootc, see References links Workaround: To mitigate this vulnerability, validate the length of data and the size of objects on all client APIs and web interfaces. Also, block, drop, or truncate oversized string, array, or binary objects before they are passed into backend SQL queries. Workaround: Upgrade to PostgreSQL 18.4, 17.10, 16.14, 15.18, or 14.23 (matching your major version) or later. Restricting network/socket access to trusted clients reduces exposure but does not eliminate the vulnerability.
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2026:44568
- externalhttps://access.redhat.com/security/cve/CVE-2026-6473
- externalhttps://access.redhat.com/security/cve/CVE-2026-6479
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_44568.json