CVE-2026-6472
PostgreSQLVulnerabilityCVSS 5.4Patched
De multiples vulnérabilités ont été découvertes dans PostgreSQL. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire, un déni de service à distance et une atteinte à la confidentialité des données.
No public exploitation has been reported so far. A fixed version is available (see the table below).
Recommended action: Update to the fixed version listed for your distribution using the native package manager.
Severity metrics
CVSS 3.1 : 5.4 MEDIUM
Attack vectorNetwork (remote)
Attack complexityLow
Privileges requiredLow
User interactionNone
ScopeUnchanged
Confidentiality impactLow
Integrity impactLow
Availability impactNone
Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Key points
- CVE : CVE-2026-6472, CVE-2026-6473, CVE-2026-6474, CVE-2026-6475...
Affected & fixed versions by distribution
Versions are the native distribution strings (backport-aware): RHEL/Debian/SUSE backport fixes, so compare with the distro version comparator (dpkg / rpm / vercmp), not the upstream version.
| Distribution | Package | Affected | Fixed version | Status |
|---|---|---|---|---|
| Debian:12 | postgresql-15 | - | 15.18-0+deb12u1 | fixed |
| Ubuntu:24.04:LTS | postgresql-16 | - | 16.14-0ubuntu0.24.04.1 | fixed |
| SUSE:Linux Enterprise Server 16.0 | postgresql15 | - | 15.18-160000.1.1 | fixed |
| SUSE:Linux Enterprise Server for SAP applications 16.0 | postgresql15 | - | 15.18-160000.1.1 | fixed |
| SUSE:Linux Enterprise Server 16.0 | postgresql16 | - | 16.14-160000.1.1 | fixed |
| SUSE:Linux Enterprise Server for SAP applications 16.0 | postgresql16 | - | 16.14-160000.1.1 | fixed |
| openSUSE:Tumbleweed | postgresql15 | - | 15.18-1.1 | fixed |
| openSUSE:Leap 16.0 | postgresql15 | - | 15.18-160000.1.1 | fixed |
| openSUSE:Tumbleweed | postgresql16 | - | 16.14-1.1 | fixed |
| openSUSE:Leap 16.0 | postgresql16 | - | 16.14-160000.1.1 | fixed |
| Red Hat:hummingbird:1 | postgresql | - | 0:18.4-0.1.hum1 | fixed |
| Red Hat:enterprise_linux:8::appstream | postgresql | - | 0:15.18-1.module+el8.10.0+24361+29e043a0 | fixed |
| Red Hat:enterprise_linux:9::appstream | postgresql | - | 0:16.14-1.module+el9.8.0+24360+ff98e86a | fixed |
| Red Hat:enterprise_linux:9::appstream | postgresql | - | 0:18.4-2.module+el9.8.0+24359+da7fad50 | fixed |
| Red Hat:rhel_e4s:9.4::appstream | postgresql | - | 0:16.14-1.module+el9.4.0+24391+f6914bcd | fixed |
| Red Hat:rhel_eus:9.6::appstream | postgresql | - | 0:16.14-1.module+el9.6.0+24387+67b4079a | fixed |
| Red Hat:rhel_e4s:8.8::appstream | postgresql | - | 0:15.18-1.module+el8.8.0+24395+e7b9b4b6 | fixed |
| Red Hat:rhel_tus:8.8::appstream | postgresql | - | 0:15.18-1.module+el8.8.0+24395+e7b9b4b6 | fixed |
| Red Hat:enterprise_linux_eus:10.0 | postgresql | - | 0:16.14-1.el10_0 | fixed |
| Red Hat:enterprise_linux:10.2 | postgresql | - | 0:16.14-1.el10_2 | fixed |
| Red Hat:enterprise_linux:9::appstream | postgresql | - | 0:15.18-1.module+el9.8.0+24358+32c5830e | fixed |
| Red Hat:enterprise_linux:8::appstream | postgresql | - | 0:16.14-1.module+el8.10.0+24339+d919fb58 | fixed |
| Red Hat:rhel_eus:9.6::appstream | postgresql | - | 0:15.18-1.module+el9.6.0+24427+6664975e | fixed |
| Red Hat:rhel_e4s:9.4::appstream | postgresql | - | 0:15.18-1.module+el9.4.0+24401+d70df5dc | fixed |
| Red Hat:rhel_e4s:9.2::appstream | postgresql | - | 0:15.18-1.module+el9.2.0+24451+e803ec54 | fixed |
| Red Hat:enterprise_linux_eus:10.0 | postgresql16 | - | 0:16.14-1.el10_0 | fixed |
| Red Hat:enterprise_linux:10.2 | postgresql16 | - | 0:16.14-1.el10_2 | fixed |