Bug 2463857 (CVE-2026-42198)
| Summary: | CVE-2026-42198 jdbc.postgresql.org: pgjdbc: Client-side Denial of Service via malicious SCRAM-SHA-256 authentication | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | ant, avibelli, bgeorges, cescoffi, dandread, dkreling, gsmet, jmartisk, lthon, manderse, mosmerov, olubyans, pesilva, pgallagh, pjindal, probinso, rguimara, rhel-process-autobot, rruss, rsvoboda, sbiarozk, tqvarnst, watson-tool-maintainers |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in pgjdbc, an open-source PostgreSQL JDBC Driver. A malicious server can exploit this vulnerability by instructing the driver to perform SCRAM-SHA-256 (Salted Challenge Response Authentication Mechanism Secure Hash Algorithm 256) authentication with an excessively large iteration count. This causes the client to spend an unbounded amount of CPU time performing PBKDF2 (Password-Based Key Derivation Function 2) computations, leading to a client-side Denial of Service (DoS). This can exhaust client CPU resources and wedge connection pools.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2466758 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-04-29 17:01:22 UTC
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:22304 https://access.redhat.com/errata/RHSA-2026:22304 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:24348 https://access.redhat.com/errata/RHSA-2026:24348 |