Bug 2477442 (CVE-2026-6477) - CVE-2026-6477 postgresql: PostgreSQL libpq: Buffer overflow allows server superuser to overwrite client stack memory
Summary: CVE-2026-6477 postgresql: PostgreSQL libpq: Buffer overflow allows server sup...
Keywords:
Status: NEW
Alias: CVE-2026-6477
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2484513 2484514 2484515 2484516 2496905
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-05-14 14:01 UTC by OSIDB Bzimport
Modified: 2026-07-23 08:54 UTC (History)
11 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:26203 0 None None None 2026-06-16 11:49:43 UTC
Red Hat Product Errata RHSA-2026:26204 0 None None None 2026-06-16 11:49:58 UTC
Red Hat Product Errata RHSA-2026:26524 0 None None None 2026-06-17 07:50:42 UTC
Red Hat Product Errata RHSA-2026:26525 0 None None None 2026-06-17 08:40:50 UTC
Red Hat Product Errata RHSA-2026:26561 0 None None None 2026-06-17 11:51:49 UTC
Red Hat Product Errata RHSA-2026:27718 0 None None None 2026-06-22 05:46:04 UTC
Red Hat Product Errata RHSA-2026:27738 0 None None None 2026-06-22 05:28:05 UTC
Red Hat Product Errata RHSA-2026:27741 0 None None None 2026-06-22 06:05:55 UTC
Red Hat Product Errata RHSA-2026:27742 0 None None None 2026-06-22 05:48:12 UTC
Red Hat Product Errata RHSA-2026:27743 0 None None None 2026-06-22 05:44:45 UTC
Red Hat Product Errata RHSA-2026:28037 0 None None None 2026-06-22 19:50:58 UTC
Red Hat Product Errata RHSA-2026:29212 0 None None None 2026-06-25 02:33:22 UTC
Red Hat Product Errata RHSA-2026:29815 0 None None None 2026-06-25 10:29:29 UTC
Red Hat Product Errata RHSA-2026:29904 0 None None None 2026-06-25 12:20:45 UTC
Red Hat Product Errata RHSA-2026:29953 0 None None None 2026-06-25 15:04:57 UTC
Red Hat Product Errata RHSA-2026:32983 0 None None None 2026-06-29 11:55:11 UTC
Red Hat Product Errata RHSA-2026:32994 0 None None None 2026-06-29 12:16:17 UTC
Red Hat Product Errata RHSA-2026:33441 0 None None None 2026-06-30 08:52:12 UTC
Red Hat Product Errata RHSA-2026:33497 0 None None None 2026-06-30 12:47:14 UTC
Red Hat Product Errata RHSA-2026:34043 0 None None None 2026-07-01 06:32:52 UTC
Red Hat Product Errata RHSA-2026:34362 0 None None None 2026-07-01 18:16:15 UTC
Red Hat Product Errata RHSA-2026:34363 0 None None None 2026-07-01 18:15:55 UTC
Red Hat Product Errata RHSA-2026:35880 0 None None None 2026-07-06 09:48:40 UTC
Red Hat Product Errata RHSA-2026:42555 0 None None None 2026-07-21 06:32:56 UTC
Red Hat Product Errata RHSA-2026:44308 0 None None None 2026-07-23 08:54:55 UTC

Description OSIDB Bzimport 2026-05-14 14:01:54 UTC
Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response.  Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size.  Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory.  Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

Comment 3 errata-xmlrpc 2026-06-16 11:49:41 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:26203 https://access.redhat.com/errata/RHSA-2026:26203

Comment 4 errata-xmlrpc 2026-06-16 11:49:57 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:26204 https://access.redhat.com/errata/RHSA-2026:26204

Comment 5 errata-xmlrpc 2026-06-17 07:50:41 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:26524 https://access.redhat.com/errata/RHSA-2026:26524

Comment 6 errata-xmlrpc 2026-06-17 08:40:49 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:26525 https://access.redhat.com/errata/RHSA-2026:26525

Comment 7 errata-xmlrpc 2026-06-17 11:51:48 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2026:26561 https://access.redhat.com/errata/RHSA-2026:26561

Comment 8 errata-xmlrpc 2026-06-22 05:28:03 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:27738 https://access.redhat.com/errata/RHSA-2026:27738

Comment 9 errata-xmlrpc 2026-06-22 05:28:04 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:27738 https://access.redhat.com/errata/RHSA-2026:27738

Comment 10 errata-xmlrpc 2026-06-22 05:44:44 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:27743 https://access.redhat.com/errata/RHSA-2026:27743

Comment 11 errata-xmlrpc 2026-06-22 05:46:02 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:27718 https://access.redhat.com/errata/RHSA-2026:27718

Comment 12 errata-xmlrpc 2026-06-22 05:48:10 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:27742 https://access.redhat.com/errata/RHSA-2026:27742

Comment 13 errata-xmlrpc 2026-06-22 06:05:54 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:27741 https://access.redhat.com/errata/RHSA-2026:27741

Comment 14 errata-xmlrpc 2026-06-22 19:50:57 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:28037 https://access.redhat.com/errata/RHSA-2026:28037

Comment 15 errata-xmlrpc 2026-06-25 02:33:21 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:29212 https://access.redhat.com/errata/RHSA-2026:29212

Comment 16 errata-xmlrpc 2026-06-25 10:29:28 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On

Via RHSA-2026:29815 https://access.redhat.com/errata/RHSA-2026:29815

Comment 17 errata-xmlrpc 2026-06-25 12:20:44 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:29904 https://access.redhat.com/errata/RHSA-2026:29904

Comment 18 errata-xmlrpc 2026-06-25 15:04:55 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:29953 https://access.redhat.com/errata/RHSA-2026:29953

Comment 19 errata-xmlrpc 2026-06-29 11:55:10 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:32983 https://access.redhat.com/errata/RHSA-2026:32983

Comment 20 errata-xmlrpc 2026-06-29 12:16:16 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On

Via RHSA-2026:32994 https://access.redhat.com/errata/RHSA-2026:32994

Comment 21 errata-xmlrpc 2026-06-30 08:52:10 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:33441 https://access.redhat.com/errata/RHSA-2026:33441

Comment 22 errata-xmlrpc 2026-06-30 12:47:12 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:33497 https://access.redhat.com/errata/RHSA-2026:33497

Comment 23 errata-xmlrpc 2026-07-01 06:32:51 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2026:34043 https://access.redhat.com/errata/RHSA-2026:34043

Comment 24 errata-xmlrpc 2026-07-01 18:15:54 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On

Via RHSA-2026:34363 https://access.redhat.com/errata/RHSA-2026:34363

Comment 25 errata-xmlrpc 2026-07-01 18:16:13 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On

Via RHSA-2026:34362 https://access.redhat.com/errata/RHSA-2026:34362

Comment 27 errata-xmlrpc 2026-07-06 09:48:38 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2026:35880 https://access.redhat.com/errata/RHSA-2026:35880

Comment 28 errata-xmlrpc 2026-07-21 06:32:55 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2026:42555 https://access.redhat.com/errata/RHSA-2026:42555

Comment 29 errata-xmlrpc 2026-07-23 08:54:54 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:44308 https://access.redhat.com/errata/RHSA-2026:44308


Note You need to log in before you can comment on or make changes to this bug.