Bug 2439325 (CVE-2026-2004)
| Summary: | CVE-2026-2004 postgresql: PostgreSQL intarray missing validation of type of input to selectivity estimator executes arbitrary code | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | Keywords: | Security |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A type validation flaw has been discovered in PostgreSQL. Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the operating system user running the database.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2439462, 2439463, 2439464, 2439465, 2439459, 2439460, 2439461 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-02-12 14:01:53 UTC
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:3730 https://access.redhat.com/errata/RHSA-2026:3730 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:3887 https://access.redhat.com/errata/RHSA-2026:3887 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:3896 https://access.redhat.com/errata/RHSA-2026:3896 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:4024 https://access.redhat.com/errata/RHSA-2026:4024 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:4059 https://access.redhat.com/errata/RHSA-2026:4059 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:4063 https://access.redhat.com/errata/RHSA-2026:4063 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:4064 https://access.redhat.com/errata/RHSA-2026:4064 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:4074 https://access.redhat.com/errata/RHSA-2026:4074 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:4075 https://access.redhat.com/errata/RHSA-2026:4075 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:4110 https://access.redhat.com/errata/RHSA-2026:4110 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:4254 https://access.redhat.com/errata/RHSA-2026:4254 This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:4441 https://access.redhat.com/errata/RHSA-2026:4441 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:4475 https://access.redhat.com/errata/RHSA-2026:4475 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Advanced Update Support Via RHSA-2026:4506 https://access.redhat.com/errata/RHSA-2026:4506 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:4504 https://access.redhat.com/errata/RHSA-2026:4504 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2026:4505 https://access.redhat.com/errata/RHSA-2026:4505 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:4509 https://access.redhat.com/errata/RHSA-2026:4509 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2026:4516 https://access.redhat.com/errata/RHSA-2026:4516 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2026:4518 https://access.redhat.com/errata/RHSA-2026:4518 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Via RHSA-2026:4515 https://access.redhat.com/errata/RHSA-2026:4515 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2026:4524 https://access.redhat.com/errata/RHSA-2026:4524 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:4528 https://access.redhat.com/errata/RHSA-2026:4528 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:4546 https://access.redhat.com/errata/RHSA-2026:4546 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2026:4544 https://access.redhat.com/errata/RHSA-2026:4544 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:4547 https://access.redhat.com/errata/RHSA-2026:4547 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2026:4548 https://access.redhat.com/errata/RHSA-2026:4548 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:19009 https://access.redhat.com/errata/RHSA-2026:19009 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:19010 https://access.redhat.com/errata/RHSA-2026:19010 |