CVE-2026-6638
postgresql-16VulnerabilityPatched
No public exploitation has been reported so far. A fixed version is available (see the table below).
Recommended action: Update to the fixed version listed for your distribution using the native package manager.
Affected & fixed versions by distribution
Versions are the native distribution strings (backport-aware): RHEL/Debian/SUSE backport fixes, so compare with the distro version comparator (dpkg / rpm / vercmp), not the upstream version.
| Distribution | Package | Affected | Fixed version | Status |
|---|---|---|---|---|
| Ubuntu:24.04:LTS | postgresql-16 | - | 16.14-0ubuntu0.24.04.1 | fixed |
| SUSE:Linux Enterprise Server 16.0 | postgresql16 | - | 16.14-160000.1.1 | fixed |
| SUSE:Linux Enterprise Server for SAP applications 16.0 | postgresql16 | - | 16.14-160000.1.1 | fixed |
| openSUSE:Tumbleweed | postgresql16 | - | 16.14-1.1 | fixed |
| openSUSE:Leap 16.0 | postgresql16 | - | 16.14-160000.1.1 | fixed |
| Red Hat:hummingbird:1 | postgresql | - | 0:18.4-0.1.hum1 | fixed |
| Red Hat:enterprise_linux:9::appstream | postgresql | - | 0:16.14-1.module+el9.8.0+24360+ff98e86a | fixed |
| Red Hat:enterprise_linux:9::appstream | postgresql | - | 0:18.4-2.module+el9.8.0+24359+da7fad50 | fixed |
| Red Hat:rhel_e4s:9.4::appstream | postgresql | - | 0:16.14-1.module+el9.4.0+24391+f6914bcd | fixed |
| Red Hat:rhel_eus:9.6::appstream | postgresql | - | 0:16.14-1.module+el9.6.0+24387+67b4079a | fixed |
| Red Hat:enterprise_linux_eus:10.0 | postgresql | - | 0:16.14-1.el10_0 | fixed |
| Red Hat:enterprise_linux:10.2 | postgresql | - | 0:16.14-1.el10_2 | fixed |
| Red Hat:enterprise_linux:8::appstream | postgresql | - | 0:16.14-1.module+el8.10.0+24339+d919fb58 | fixed |
| Red Hat:enterprise_linux_eus:10.0 | postgresql16 | - | 0:16.14-1.el10_0 | fixed |
| Red Hat:enterprise_linux:10.2 | postgresql16 | - | 0:16.14-1.el10_2 | fixed |