Fedora Account System
Red Hat Associate
Red Hat Customer
Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:26203 https://access.redhat.com/errata/RHSA-2026:26203
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:26204 https://access.redhat.com/errata/RHSA-2026:26204
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions Via RHSA-2026:26524 https://access.redhat.com/errata/RHSA-2026:26524
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:26525 https://access.redhat.com/errata/RHSA-2026:26525
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:26561 https://access.redhat.com/errata/RHSA-2026:26561
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:27738 https://access.redhat.com/errata/RHSA-2026:27738
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:27743 https://access.redhat.com/errata/RHSA-2026:27743
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:27718 https://access.redhat.com/errata/RHSA-2026:27718
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:27742 https://access.redhat.com/errata/RHSA-2026:27742
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:27741 https://access.redhat.com/errata/RHSA-2026:27741
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:28037 https://access.redhat.com/errata/RHSA-2026:28037
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:29212 https://access.redhat.com/errata/RHSA-2026:29212
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On Via RHSA-2026:29815 https://access.redhat.com/errata/RHSA-2026:29815
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions Via RHSA-2026:29904 https://access.redhat.com/errata/RHSA-2026:29904
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:29953 https://access.redhat.com/errata/RHSA-2026:29953
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:32983 https://access.redhat.com/errata/RHSA-2026:32983
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On Via RHSA-2026:32994 https://access.redhat.com/errata/RHSA-2026:32994
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions Via RHSA-2026:33441 https://access.redhat.com/errata/RHSA-2026:33441
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:33497 https://access.redhat.com/errata/RHSA-2026:33497
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:34043 https://access.redhat.com/errata/RHSA-2026:34043
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:34363 https://access.redhat.com/errata/RHSA-2026:34363
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:34362 https://access.redhat.com/errata/RHSA-2026:34362
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:35880 https://access.redhat.com/errata/RHSA-2026:35880
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:42555 https://access.redhat.com/errata/RHSA-2026:42555
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:44420 https://access.redhat.com/errata/RHSA-2026:44420