Bug 2515307 (CVE-2026-6471)

Summary: CVE-2026-6471 postgresql: PostgreSQL: Arbitrary code execution via logical decoding plugin
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: dschmidt, jlanda, kshier, rhel-process-autobot, simaishi, stcannon, teagle, watson-tool-maintainers, yguenane
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in PostgreSQL. Missing authorization in PostgreSQL's logical decoding feature allows a non-superuser with REPLICATION privilege to load arbitrary files. This can lead to arbitrary code execution as the operating system account running the server.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2524905, 2524906    
Bug Blocks:    

Description OSIDB Bzimport 2026-08-13 13:27:34 UTC
Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice of logical decoding plugin.  This in turn runs arbitrary code as that account.  Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.

Comment 2 Jon Orris 2026-09-14 13:32:01 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:67280 https://access.redhat.com/errata/RHSA-2026:67280

Comment 3 Jon Orris 2026-09-15 08:14:55 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:67491 https://access.redhat.com/errata/RHSA-2026:67491

Comment 4 Jon Orris 2026-09-16 08:53:50 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:67848 https://access.redhat.com/errata/RHSA-2026:67848

Comment 6 Jon Orris 2026-09-21 22:12:40 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:69698 https://access.redhat.com/errata/RHSA-2026:69698

Comment 7 Jon Orris 2026-09-22 02:39:37 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:69607 https://access.redhat.com/errata/RHSA-2026:69607

Comment 8 Jon Orris 2026-09-22 08:34:31 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:69876 https://access.redhat.com/errata/RHSA-2026:69876

Comment 9 Jon Orris 2026-09-22 10:27:11 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:69923 https://access.redhat.com/errata/RHSA-2026:69923

Comment 10 Jon Orris 2026-09-22 11:39:12 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:69914 https://access.redhat.com/errata/RHSA-2026:69914

Comment 11 Jon Orris 2026-09-22 12:42:52 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:70186 https://access.redhat.com/errata/RHSA-2026:70186

Comment 12 Jon Orris 2026-09-23 06:29:01 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:70559 https://access.redhat.com/errata/RHSA-2026:70559

Comment 13 Jon Orris 2026-09-23 07:34:24 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2026:70602 https://access.redhat.com/errata/RHSA-2026:70602

Comment 14 Jon Orris 2026-09-23 13:22:37 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:70762 https://access.redhat.com/errata/RHSA-2026:70762

Comment 15 Jon Orris 2026-09-23 15:55:02 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:69924 https://access.redhat.com/errata/RHSA-2026:69924

Comment 16 Jon Orris 2026-09-23 16:15:22 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:70856 https://access.redhat.com/errata/RHSA-2026:70856

Comment 17 Jon Orris 2026-09-23 20:28:56 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:70763 https://access.redhat.com/errata/RHSA-2026:70763