Fedora Account System
Red Hat Associate
Red Hat Customer
Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice of logical decoding plugin. This in turn runs arbitrary code as that account. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:67280 https://access.redhat.com/errata/RHSA-2026:67280
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:67491 https://access.redhat.com/errata/RHSA-2026:67491
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:67848 https://access.redhat.com/errata/RHSA-2026:67848