PostgreSQL is an advanced object-relational database management system (DBMS).
Security Fix(es):
postgresql: PostgreSQL: Credential recovery via covert timing channel in MD5 password comparison (CVE-2026-6478)
postgresql: integer overflow can cause an undersized allocation and an out-of-bounds write (CVE-2026-6473)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
0:1.4.6-3.module+el8.10.0+1862+29bef6480:1.4.6-3.module+el8.10.0+40055+b85d5ce20:1.4.6-3.module+el8.9.0+1594+4a6adae90:1.4.6-3.module+el8.9.0+1603+444d1b540:1.4.0-7.module+el8.9.0+1735+a332307b0:0.10.0-2.module+el8.10.0+1862+29bef6480:0.10.0-2.module+el8.10.0+40055+b85d5ce20:0.10.0-2.module+el8.9.0+1594+4a6adae90:0.10.0-2.module+el8.9.0+1603+444d1b540:12.22-7.module+el8.10.0+40221+63654815Exploitability
AV:NAC:LPR:LUI:NScope
S:UImpact
C:HI:HA:HCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H