Bug 2477439 (CVE-2026-6475)
| Summary: | CVE-2026-6475 postgresql: PostgreSQL: Operating system account hijack via symlink following in pg_basebackup and pg_rewind | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | dschmidt, erezende, jlanda, kshier, rhel-process-autobot, simaishi, smcdonal, stcannon, teagle, watson-tool-maintainers, yguenane |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in PostgreSQL. This vulnerability, related to symlink following in pg_basebackup (plain format) and pg_rewind, allows an origin superuser to overwrite local files. By exploiting this, an attacker could potentially hijack the operating system account. This attack has practical implications if specific actions are taken, such as moving files to a different virtual machine (VM) or snapshotting the VM, between the execution of these commands and the server's restart.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2484509, 2484510, 2484511, 2484512 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-05-14 14:01:42 UTC
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:26203 https://access.redhat.com/errata/RHSA-2026:26203 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:26204 https://access.redhat.com/errata/RHSA-2026:26204 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions Via RHSA-2026:26524 https://access.redhat.com/errata/RHSA-2026:26524 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:26525 https://access.redhat.com/errata/RHSA-2026:26525 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:26561 https://access.redhat.com/errata/RHSA-2026:26561 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:27738 https://access.redhat.com/errata/RHSA-2026:27738 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:27743 https://access.redhat.com/errata/RHSA-2026:27743 This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:27718 https://access.redhat.com/errata/RHSA-2026:27718 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:27742 https://access.redhat.com/errata/RHSA-2026:27742 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:27741 https://access.redhat.com/errata/RHSA-2026:27741 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:28037 https://access.redhat.com/errata/RHSA-2026:28037 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:29212 https://access.redhat.com/errata/RHSA-2026:29212 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On Via RHSA-2026:29815 https://access.redhat.com/errata/RHSA-2026:29815 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions Via RHSA-2026:29904 https://access.redhat.com/errata/RHSA-2026:29904 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:29953 https://access.redhat.com/errata/RHSA-2026:29953 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:32983 https://access.redhat.com/errata/RHSA-2026:32983 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On Via RHSA-2026:32994 https://access.redhat.com/errata/RHSA-2026:32994 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions Via RHSA-2026:33441 https://access.redhat.com/errata/RHSA-2026:33441 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:33497 https://access.redhat.com/errata/RHSA-2026:33497 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:34043 https://access.redhat.com/errata/RHSA-2026:34043 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:34363 https://access.redhat.com/errata/RHSA-2026:34363 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:34362 https://access.redhat.com/errata/RHSA-2026:34362 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:35880 https://access.redhat.com/errata/RHSA-2026:35880 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:42555 https://access.redhat.com/errata/RHSA-2026:42555 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:44420 https://access.redhat.com/errata/RHSA-2026:44420 |