Bug 2539546 (CVE-2026-6669)
| Summary: | CVE-2026-6669 pgbouncer: PgBouncer: Denial of Service via unbounded SCRAM iteration count | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | Keywords: | Security |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in PgBouncer. A malicious or compromised PostgreSQL backend can exploit a missing upper bound on the key derivation iteration count during SCRAM (Salted Challenge Response Authentication Mechanism) authentication. This can lead to uncontrolled CPU consumption in PgBouncer, effectively stopping it from serving traffic for all other databases and clients it manages. This results in a Denial of Service (DoS) for all connected services.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2539634, 2539635 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-09-23 17:03:14 UTC
|