{
  "threat_severity" : "Moderate",
  "public_date" : "2026-05-14T13:00:10Z",
  "bugzilla" : {
    "description" : "postgresql: PostgreSQL: Information disclosure via externally-controlled format string in timeofday() function",
    "id" : "2477441",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2477441"
  },
  "cvss3" : {
    "cvss3_base_score" : "4.3",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
    "status" : "verified"
  },
  "cwe" : "CWE-134",
  "details" : [ "Externally-controlled format string in PostgreSQL timeofday() function allows an attacker to retrieve portions of server memory, via crafted timezone zones.  Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.", "A flaw was found in PostgreSQL. This vulnerability, an externally-controlled format string in the `timeofday()` function, allows a remote attacker to craft specific timezone zones. Successful exploitation can lead to the retrieval of sensitive portions of server memory, potentially disclosing confidential information." ],
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 10",
    "release_date" : "2026-06-22T00:00:00Z",
    "advisory" : "RHSA-2026:27742",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10.2",
    "package" : "postgresql18-0:18.4-1.el10_2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 10",
    "release_date" : "2026-06-22T00:00:00Z",
    "advisory" : "RHSA-2026:27743",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10.2",
    "package" : "postgresql16-0:16.14-1.el10_2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 10.0 Extended Update Support",
    "release_date" : "2026-06-22T00:00:00Z",
    "advisory" : "RHSA-2026:27718",
    "cpe" : "cpe:/o:redhat:enterprise_linux_eus:10.0",
    "package" : "postgresql16-0:16.14-1.el10_0"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2026-06-16T00:00:00Z",
    "advisory" : "RHSA-2026:26181",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "postgresql:15-8100020260605152259.489197e6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2026-06-23T00:00:00Z",
    "advisory" : "RHSA-2026:28143",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "postgresql:16-8100020260530205218.489197e6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
    "release_date" : "2026-06-17T00:00:00Z",
    "advisory" : "RHSA-2026:26561",
    "cpe" : "cpe:/a:redhat:rhel_tus:8.8",
    "package" : "postgresql:15-8080020260615085052.63b34585"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
    "release_date" : "2026-06-17T00:00:00Z",
    "advisory" : "RHSA-2026:26561",
    "cpe" : "cpe:/a:redhat:rhel_e4s:8.8",
    "package" : "postgresql:15-8080020260615085052.63b34585"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2026-06-16T00:00:00Z",
    "advisory" : "RHSA-2026:26203",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "postgresql:16-9080020260605131007.rhel9"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2026-06-16T00:00:00Z",
    "advisory" : "RHSA-2026:26204",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "postgresql:18-9080020260605125734.rhel9"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2026-06-22T00:00:00Z",
    "advisory" : "RHSA-2026:28037",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "postgresql:15-9080020260605124405.rhel9"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
    "release_date" : "2026-06-30T00:00:00Z",
    "advisory" : "RHSA-2026:33497",
    "cpe" : "cpe:/a:redhat:rhel_e4s:9.2",
    "package" : "postgresql:15-9020020260625101129.rhel9"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
    "release_date" : "2026-06-17T00:00:00Z",
    "advisory" : "RHSA-2026:26524",
    "cpe" : "cpe:/a:redhat:rhel_e4s:9.4",
    "package" : "postgresql:16-9040020260612132455.rhel9"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
    "release_date" : "2026-06-30T00:00:00Z",
    "advisory" : "RHSA-2026:33441",
    "cpe" : "cpe:/a:redhat:rhel_e4s:9.4",
    "package" : "postgresql:15-9040020260616071806.rhel9"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.6 Extended Update Support",
    "release_date" : "2026-06-17T00:00:00Z",
    "advisory" : "RHSA-2026:26525",
    "cpe" : "cpe:/a:redhat:rhel_eus:9.6",
    "package" : "postgresql:16-9060020260612084605.rhel9"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.6 Extended Update Support",
    "release_date" : "2026-06-29T00:00:00Z",
    "advisory" : "RHSA-2026:32983",
    "cpe" : "cpe:/a:redhat:rhel_eus:9.6",
    "package" : "postgresql:15-9060020260622062902.rhel9"
  }, {
    "product_name" : "Red Hat Hardened Images",
    "release_date" : "2026-06-03T00:00:00Z",
    "advisory" : "RHSA-2026:22878",
    "cpe" : "cpe:/a:redhat:hummingbird:1",
    "package" : "postgresql18-main-18.4-0.1.hum1"
  }, {
    "product_name" : "Red Hat Update Infrastructure 5",
    "release_date" : "2026-07-23T00:00:00Z",
    "advisory" : "RHSA-2026:44481",
    "cpe" : "cpe:/a:redhat:rhui:5::el9",
    "package" : "rhui5/rhua-rhel9:1784795076"
  }, {
    "product_name" : "Red Hat Update Infrastructure 5",
    "release_date" : "2026-08-24T00:00:00Z",
    "advisory" : "RHSA-2026:58981",
    "cpe" : "cpe:/a:redhat:rhui:5::el9",
    "package" : "rhui5/rhua-tp-rhel9:1787241260"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 6",
    "fix_state" : "Fix deferred",
    "package_name" : "postgresql",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "fix_state" : "Fix deferred",
    "package_name" : "postgresql",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "fix_state" : "Fix deferred",
    "package_name" : "postgresql:12/postgresql",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "fix_state" : "Will not fix",
    "package_name" : "postgresql:13/postgresql",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "fix_state" : "Fix deferred",
    "package_name" : "postgresql",
    "cpe" : "cpe:/o:redhat:enterprise_linux:9"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-6474\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-6474\nhttps://www.postgresql.org/support/security/CVE-2026-6474/" ],
  "name" : "CVE-2026-6474",
  "mitigation" : {
    "value" : "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
    "lang" : "en:us"
  },
  "csaw" : false
}