CVE.RADIO
FREN

CVE-2026-6474

postgresql-15VulnerabilityCVSS 4.3Patched

No public exploitation has been reported so far. A fixed version is available (see the table below).

Recommended action: Update to the fixed version listed for your distribution using the native package manager.

Severity metrics

CVSS 3.1 : 4.3 MEDIUM

Attack vectorNetwork (remote)
Attack complexityLow
Privileges requiredLow
User interactionNone
ScopeUnchanged
Confidentiality impactLow
Integrity impactNone
Availability impactNone

Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Affected & fixed versions by distribution

Versions are the native distribution strings (backport-aware): RHEL/Debian/SUSE backport fixes, so compare with the distro version comparator (dpkg / rpm / vercmp), not the upstream version.

DistributionPackageAffectedFixed versionStatus
Debian:12postgresql-15-15.18-0+deb12u1fixed
Ubuntu:24.04:LTSpostgresql-16-16.14-0ubuntu0.24.04.1fixed
SUSE:Linux Enterprise Server 16.0postgresql15-15.18-160000.1.1fixed
SUSE:Linux Enterprise Server for SAP applications 16.0postgresql15-15.18-160000.1.1fixed
SUSE:Linux Enterprise Server 16.0postgresql16-16.14-160000.1.1fixed
SUSE:Linux Enterprise Server for SAP applications 16.0postgresql16-16.14-160000.1.1fixed
openSUSE:Tumbleweedpostgresql15-15.18-1.1fixed
openSUSE:Leap 16.0postgresql15-15.18-160000.1.1fixed
openSUSE:Tumbleweedpostgresql16-16.14-1.1fixed
openSUSE:Leap 16.0postgresql16-16.14-160000.1.1fixed
Red Hat:hummingbird:1postgresql-0:18.4-0.1.hum1fixed
Red Hat:enterprise_linux:8::appstreampostgresql-0:15.18-1.module+el8.10.0+24361+29e043a0fixed
Red Hat:enterprise_linux:9::appstreampostgresql-0:16.14-1.module+el9.8.0+24360+ff98e86afixed
Red Hat:enterprise_linux:9::appstreampostgresql-0:18.4-2.module+el9.8.0+24359+da7fad50fixed
Red Hat:rhel_e4s:9.4::appstreampostgresql-0:16.14-1.module+el9.4.0+24391+f6914bcdfixed
Red Hat:rhel_eus:9.6::appstreampostgresql-0:16.14-1.module+el9.6.0+24387+67b4079afixed
Red Hat:rhel_e4s:8.8::appstreampostgresql-0:15.18-1.module+el8.8.0+24395+e7b9b4b6fixed
Red Hat:rhel_tus:8.8::appstreampostgresql-0:15.18-1.module+el8.8.0+24395+e7b9b4b6fixed
Red Hat:enterprise_linux_eus:10.0postgresql-0:16.14-1.el10_0fixed
Red Hat:enterprise_linux:10.2postgresql-0:16.14-1.el10_2fixed
Red Hat:enterprise_linux:9::appstreampostgresql-0:15.18-1.module+el9.8.0+24358+32c5830efixed
Red Hat:enterprise_linux:8::appstreampostgresql-0:16.14-1.module+el8.10.0+24339+d919fb58fixed
Red Hat:rhel_eus:9.6::appstreampostgresql-0:15.18-1.module+el9.6.0+24427+6664975efixed
Red Hat:rhel_e4s:9.4::appstreampostgresql-0:15.18-1.module+el9.4.0+24401+d70df5dcfixed
Red Hat:rhel_e4s:9.2::appstreampostgresql-0:15.18-1.module+el9.2.0+24451+e803ec54fixed
Red Hat:enterprise_linux_eus:10.0postgresql16-0:16.14-1.el10_0fixed
Red Hat:enterprise_linux:10.2postgresql16-0:16.14-1.el10_2fixed

Sources