ALSA-2026:27738

See a problem?
Import Source
https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2026:27738.json
JSON Data
https://api.osv.dev/v1/vulns/ALSA-2026:27738
Related
  • CVE-2026-6473
  • CVE-2026-6475
  • CVE-2026-6477
  • CVE-2026-6478
Published
2026-06-22T00:00:00Z
Modified
2026-06-23T15:29:23.833612387Z
Summary
Important: libpq security update
Details

The libpq package provides the PostgreSQL client library, which allows client programs to connect to PostgreSQL servers.

Security Fix(es):

  • postgresql: PostgreSQL: Operating system account hijack via symlink following in pgbasebackup and pgrewind (CVE-2026-6475)
  • postgresql: PostgreSQL libpq: Buffer overflow allows server superuser to overwrite client stack memory (CVE-2026-6477)
  • postgresql: PostgreSQL: Credential recovery via covert timing channel in MD5 password comparison (CVE-2026-6478)
  • postgresql: integer overflow can cause an undersized allocation and an out-of-bounds write (CVE-2026-6473)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

References

Affected packages

AlmaLinux:8 / libpq

Package

Name
libpq
Purl
pkg:rpm/almalinux/libpq

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
13.23-2.el8_10

Database specific

source
"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2026:27738.json"

AlmaLinux:8 / libpq-devel

Package

Name
libpq-devel
Purl
pkg:rpm/almalinux/libpq-devel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
13.23-2.el8_10

Database specific

source
"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2026:27738.json"