PostgreSQL Multiple Vulnerabilities
Release Date: 10 Aug 2026
Multiple vulnerabilities were identified in PostgreSQL. A remote attacker could exploit some of these vulnerabilities to trigger elevation of privilege, remote code execution, denial of service condition, data manipulation and sensitive information disclosure on the targeted system.
Impact
- Remote Code Execution
- Information Disclosure
- Elevation of Privilege
- Denial of Service
- Data Manipulation
System / Technologies affected
- PostgreSQL versions prior to 18.4
- PostgreSQL versions prior to 17.10
- PostgreSQL versions prior to 16.14
- PostgreSQL versions prior to 15.18
- PostgreSQL versions prior to 14.23
Solutions
Before installation of the software, please visit the software vendor web-site for more details.
- The vendor has issued fixes:
- Update to PostgreSQL version 18.4
- Update to PostgreSQL version 17.10
- Update to PostgreSQL version 16.14
- Update to PostgreSQL version 15.18
- Update to PostgreSQL version 14.23
Vulnerability Identifier
- CVE-2026-6472
- CVE-2026-6473
- CVE-2026-6474
- CVE-2026-6475
- CVE-2026-6476
- CVE-2026-6477
- CVE-2026-6478
- CVE-2026-6479
- CVE-2026-6575
- CVE-2026-6637
- CVE-2026-6638
Source
Related Link
https://www.postgresql.org/about/news/postgresql-184-1710-1614-1518-and-1423-released-3297/
沒有留言:
發佈留言