Details:
PostgreSQL is an advanced object-relational database management system (DBMS).
Security Fix(es):
postgresql: PostgreSQL: Operating system account hijack via symlink following in pg_basebackup and pg_rewind (CVE-2026-6475)
postgresql: PostgreSQL libpq: Buffer overflow allows server superuser to overwrite client stack memory (CVE-2026-6477)
postgresql: PostgreSQL: Credential recovery via covert timing channel in MD5 password comparison (CVE-2026-6478)
postgresql: integer overflow can cause an undersized allocation and an out-of-bounds write (CVE-2026-6473)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
0:1.4.8-2.module+el9.8.0+24091+177755050:1.4.8-2.module+el9.8.0+24091+177755050:1.4.8-2.module+el9.8.0+24091+177755050:1.7.0-1.module+el9.8.0+24091+177755050:1.7.0-1.module+el9.8.0+24091+177755050:1.7.0-1.module+el9.8.0+24091+177755050:1.9.7-1.Final.module+el9.8.0+24091+177755050:1.9.7-1.Final.module+el9.8.0+24091+177755050:1.9.7-1.Final.module+el9.8.0+24091+177755050:15.18-1.module+el9.8.0+24358+32c5830eExploitability
AV:NAC:LPR:LUI:NScope
S:UImpact
C:HI:HA:H8.8/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H