Bug 2477439 (CVE-2026-6475)

Summary: CVE-2026-6475 postgresql: PostgreSQL: Operating system account hijack via symlink following in pg_basebackup and pg_rewind
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: dschmidt, erezende, jlanda, kshier, rhel-process-autobot, simaishi, smcdonal, stcannon, teagle, watson-tool-maintainers, yguenane
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in PostgreSQL. This vulnerability, related to symlink following in pg_basebackup (plain format) and pg_rewind, allows an origin superuser to overwrite local files. By exploiting this, an attacker could potentially hijack the operating system account. This attack has practical implications if specific actions are taken, such as moving files to a different virtual machine (VM) or snapshotting the VM, between the execution of these commands and the server's restart.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2484509, 2484510, 2484511, 2484512    
Bug Blocks:    

Description OSIDB Bzimport 2026-05-14 14:01:42 UTC
Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account.  It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries.  Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM.  Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

Comment 4 errata-xmlrpc 2026-06-16 11:49:41 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:26203 https://access.redhat.com/errata/RHSA-2026:26203

Comment 5 errata-xmlrpc 2026-06-16 11:49:55 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:26204 https://access.redhat.com/errata/RHSA-2026:26204

Comment 6 errata-xmlrpc 2026-06-17 07:50:40 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:26524 https://access.redhat.com/errata/RHSA-2026:26524

Comment 7 errata-xmlrpc 2026-06-17 08:40:46 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:26525 https://access.redhat.com/errata/RHSA-2026:26525

Comment 8 errata-xmlrpc 2026-06-17 11:51:48 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2026:26561 https://access.redhat.com/errata/RHSA-2026:26561

Comment 9 errata-xmlrpc 2026-06-22 05:28:03 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:27738 https://access.redhat.com/errata/RHSA-2026:27738

Comment 10 errata-xmlrpc 2026-06-22 05:44:42 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:27743 https://access.redhat.com/errata/RHSA-2026:27743

Comment 11 errata-xmlrpc 2026-06-22 05:46:02 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:27718 https://access.redhat.com/errata/RHSA-2026:27718

Comment 12 errata-xmlrpc 2026-06-22 05:48:10 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:27742 https://access.redhat.com/errata/RHSA-2026:27742

Comment 13 errata-xmlrpc 2026-06-22 06:05:50 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:27741 https://access.redhat.com/errata/RHSA-2026:27741

Comment 14 errata-xmlrpc 2026-06-22 19:50:56 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:28037 https://access.redhat.com/errata/RHSA-2026:28037

Comment 15 errata-xmlrpc 2026-06-25 02:33:20 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:29212 https://access.redhat.com/errata/RHSA-2026:29212

Comment 16 errata-xmlrpc 2026-06-25 10:29:28 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On

Via RHSA-2026:29815 https://access.redhat.com/errata/RHSA-2026:29815

Comment 17 errata-xmlrpc 2026-06-25 12:20:44 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:29904 https://access.redhat.com/errata/RHSA-2026:29904

Comment 18 errata-xmlrpc 2026-06-25 15:04:55 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:29953 https://access.redhat.com/errata/RHSA-2026:29953

Comment 19 errata-xmlrpc 2026-06-29 11:55:09 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:32983 https://access.redhat.com/errata/RHSA-2026:32983

Comment 20 errata-xmlrpc 2026-06-29 12:16:18 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On

Via RHSA-2026:32994 https://access.redhat.com/errata/RHSA-2026:32994

Comment 21 errata-xmlrpc 2026-06-30 08:52:09 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:33441 https://access.redhat.com/errata/RHSA-2026:33441

Comment 22 errata-xmlrpc 2026-06-30 12:47:12 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:33497 https://access.redhat.com/errata/RHSA-2026:33497

Comment 23 errata-xmlrpc 2026-07-01 06:32:51 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2026:34043 https://access.redhat.com/errata/RHSA-2026:34043

Comment 24 errata-xmlrpc 2026-07-01 18:15:54 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On

Via RHSA-2026:34363 https://access.redhat.com/errata/RHSA-2026:34363

Comment 25 errata-xmlrpc 2026-07-01 18:16:13 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On

Via RHSA-2026:34362 https://access.redhat.com/errata/RHSA-2026:34362

Comment 26 errata-xmlrpc 2026-07-06 09:48:31 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2026:35880 https://access.redhat.com/errata/RHSA-2026:35880

Comment 27 errata-xmlrpc 2026-07-21 06:32:55 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2026:42555 https://access.redhat.com/errata/RHSA-2026:42555

Comment 28 errata-xmlrpc 2026-07-23 11:55:54 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On

Via RHSA-2026:44420 https://access.redhat.com/errata/RHSA-2026:44420