{
  "threat_severity" : "Important",
  "public_date" : "2026-05-14T13:00:12Z",
  "bugzilla" : {
    "description" : "postgresql: PostgreSQL libpq: Buffer overflow allows server superuser to overwrite client stack memory",
    "id" : "2477442",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2477442"
  },
  "cvss3" : {
    "cvss3_base_score" : "8.4",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-120",
  "details" : [ "Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response.  Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size.  Because both the \\lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory.  Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.", "A flaw was found in PostgreSQL libpq. A server superuser can exploit a buffer overflow vulnerability in the PQfn function, which is used by client functions such as lo_export(), lo_read(), lo_lseek64(), and lo_tell64(). This allows the superuser to send an arbitrarily large response, overwriting the client's stack memory, specifically in tools like psql and pg_dump. This could lead to arbitrary code execution on the client system." ],
  "statement" : "This IMPORTANT buffer overflow in PostgreSQL libpq allows a malicious server superuser to overwrite client stack memory via lo_* functions. Exploitation requires the victim to connect to a compromised or malicious server (UI:R). The scope is changed as the server attack affects the client system. Impact is high to confidentiality, integrity, and availability through potential client-side code execution. Affects versions before 18.4, 17.10, 16.14, 15.18, and 14.23.",
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 10",
    "release_date" : "2026-06-22T00:00:00Z",
    "advisory" : "RHSA-2026:27742",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10.2",
    "package" : "postgresql18-0:18.4-1.el10_2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 10",
    "release_date" : "2026-06-22T00:00:00Z",
    "advisory" : "RHSA-2026:27743",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10.2",
    "package" : "postgresql16-0:16.14-1.el10_2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 10",
    "release_date" : "2026-07-23T00:00:00Z",
    "advisory" : "RHSA-2026:44391",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10.2",
    "package" : "libpq-0:16.14-1.el10_2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 10.0 Extended Update Support",
    "release_date" : "2026-06-22T00:00:00Z",
    "advisory" : "RHSA-2026:27718",
    "cpe" : "cpe:/o:redhat:enterprise_linux_eus:10.0",
    "package" : "postgresql16-0:16.14-1.el10_0"
  }, {
    "product_name" : "Red Hat Enterprise Linux 10.0 Extended Update Support",
    "release_date" : "2026-08-05T00:00:00Z",
    "advisory" : "RHSA-2026:50863",
    "cpe" : "cpe:/o:redhat:enterprise_linux_eus:10.0",
    "package" : "libpq-0:16.14-0.el10_0.1"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
    "release_date" : "2026-08-03T00:00:00Z",
    "advisory" : "RHSA-2026:49521",
    "cpe" : "cpe:/o:redhat:rhel_els:7",
    "package" : "postgresql-0:9.2.24-9.el7_9.6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2026-06-16T00:00:00Z",
    "advisory" : "RHSA-2026:26181",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "postgresql:15-8100020260605152259.489197e6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2026-06-22T00:00:00Z",
    "advisory" : "RHSA-2026:27738",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "libpq-0:13.23-2.el8_10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2026-06-23T00:00:00Z",
    "advisory" : "RHSA-2026:28143",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "postgresql:16-8100020260530205218.489197e6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2026-06-23T00:00:00Z",
    "advisory" : "RHSA-2026:28208",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "postgresql:13-8100020260605152256.489197e6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2026-06-24T00:00:00Z",
    "advisory" : "RHSA-2026:28999",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "postgresql:12-8100020260605152253.489197e6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
    "release_date" : "2026-07-01T00:00:00Z",
    "advisory" : "RHSA-2026:34362",
    "cpe" : "cpe:/a:redhat:rhel_aus:8.4",
    "package" : "postgresql:12-8040020260624104459.522a0ee4"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
    "release_date" : "2026-07-01T00:00:00Z",
    "advisory" : "RHSA-2026:34363",
    "cpe" : "cpe:/a:redhat:rhel_aus:8.4",
    "package" : "postgresql:13-8040020260630100922.522a0ee4"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
    "release_date" : "2026-07-23T00:00:00Z",
    "advisory" : "RHSA-2026:44420",
    "cpe" : "cpe:/a:redhat:rhel_aus:8.4",
    "package" : "libpq-0:13.23-1.el8_4.1"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
    "release_date" : "2026-07-01T00:00:00Z",
    "advisory" : "RHSA-2026:34362",
    "cpe" : "cpe:/a:redhat:rhel_eus_long_life:8.4",
    "package" : "postgresql:12-8040020260624104459.522a0ee4"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
    "release_date" : "2026-07-01T00:00:00Z",
    "advisory" : "RHSA-2026:34363",
    "cpe" : "cpe:/a:redhat:rhel_eus_long_life:8.4",
    "package" : "postgresql:13-8040020260630100922.522a0ee4"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
    "release_date" : "2026-07-23T00:00:00Z",
    "advisory" : "RHSA-2026:44420",
    "cpe" : "cpe:/a:redhat:rhel_eus_long_life:8.4",
    "package" : "libpq-0:13.23-1.el8_4.1"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
    "release_date" : "2026-06-25T00:00:00Z",
    "advisory" : "RHSA-2026:29815",
    "cpe" : "cpe:/a:redhat:rhel_aus:8.6",
    "package" : "postgresql:12-8060020260623094704.ad008a3a"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
    "release_date" : "2026-06-29T00:00:00Z",
    "advisory" : "RHSA-2026:32994",
    "cpe" : "cpe:/a:redhat:rhel_aus:8.6",
    "package" : "postgresql:13-8060020260625065744.ad008a3a"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
    "release_date" : "2026-07-28T00:00:00Z",
    "advisory" : "RHSA-2026:47090",
    "cpe" : "cpe:/a:redhat:rhel_aus:8.6",
    "package" : "libpq-0:13.23-1.el8_6.1"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
    "release_date" : "2026-06-25T00:00:00Z",
    "advisory" : "RHSA-2026:29815",
    "cpe" : "cpe:/a:redhat:rhel_eus_long_life:8.6",
    "package" : "postgresql:12-8060020260623094704.ad008a3a"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
    "release_date" : "2026-06-29T00:00:00Z",
    "advisory" : "RHSA-2026:32994",
    "cpe" : "cpe:/a:redhat:rhel_eus_long_life:8.6",
    "package" : "postgresql:13-8060020260625065744.ad008a3a"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
    "release_date" : "2026-07-28T00:00:00Z",
    "advisory" : "RHSA-2026:47090",
    "cpe" : "cpe:/a:redhat:rhel_eus_long_life:8.6",
    "package" : "libpq-0:13.23-1.el8_6.1"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
    "release_date" : "2026-06-17T00:00:00Z",
    "advisory" : "RHSA-2026:26561",
    "cpe" : "cpe:/a:redhat:rhel_tus:8.8",
    "package" : "postgresql:15-8080020260615085052.63b34585"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
    "release_date" : "2026-07-01T00:00:00Z",
    "advisory" : "RHSA-2026:34043",
    "cpe" : "cpe:/a:redhat:rhel_tus:8.8",
    "package" : "postgresql:12-8080020260626093604.63b34585"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
    "release_date" : "2026-07-06T00:00:00Z",
    "advisory" : "RHSA-2026:35880",
    "cpe" : "cpe:/a:redhat:rhel_tus:8.8",
    "package" : "libpq-0:13.23-1.el8_8.1"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
    "release_date" : "2026-07-21T00:00:00Z",
    "advisory" : "RHSA-2026:42555",
    "cpe" : "cpe:/a:redhat:rhel_tus:8.8",
    "package" : "postgresql:13-8080020260709122729.63b34585"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
    "release_date" : "2026-06-17T00:00:00Z",
    "advisory" : "RHSA-2026:26561",
    "cpe" : "cpe:/a:redhat:rhel_e4s:8.8",
    "package" : "postgresql:15-8080020260615085052.63b34585"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
    "release_date" : "2026-07-01T00:00:00Z",
    "advisory" : "RHSA-2026:34043",
    "cpe" : "cpe:/a:redhat:rhel_e4s:8.8",
    "package" : "postgresql:12-8080020260626093604.63b34585"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
    "release_date" : "2026-07-06T00:00:00Z",
    "advisory" : "RHSA-2026:35880",
    "cpe" : "cpe:/a:redhat:rhel_e4s:8.8",
    "package" : "libpq-0:13.23-1.el8_8.1"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
    "release_date" : "2026-07-21T00:00:00Z",
    "advisory" : "RHSA-2026:42555",
    "cpe" : "cpe:/a:redhat:rhel_e4s:8.8",
    "package" : "postgresql:13-8080020260709122729.63b34585"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2026-06-16T00:00:00Z",
    "advisory" : "RHSA-2026:26203",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "postgresql:16-9080020260605131007.rhel9"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2026-06-16T00:00:00Z",
    "advisory" : "RHSA-2026:26204",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "postgresql:18-9080020260605125734.rhel9"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2026-06-22T00:00:00Z",
    "advisory" : "RHSA-2026:27741",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "postgresql-0:13.23-3.el9_8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2026-06-22T00:00:00Z",
    "advisory" : "RHSA-2026:28037",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "postgresql:15-9080020260605124405.rhel9"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2026-07-23T00:00:00Z",
    "advisory" : "RHSA-2026:44308",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "libpq-0:13.23-3.el9_8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
    "release_date" : "2026-06-25T00:00:00Z",
    "advisory" : "RHSA-2026:29953",
    "cpe" : "cpe:/a:redhat:rhel_e4s:9.2",
    "package" : "postgresql-0:13.23-1.el9_2.2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
    "release_date" : "2026-06-30T00:00:00Z",
    "advisory" : "RHSA-2026:33497",
    "cpe" : "cpe:/a:redhat:rhel_e4s:9.2",
    "package" : "postgresql:15-9020020260625101129.rhel9"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
    "release_date" : "2026-08-04T00:00:00Z",
    "advisory" : "RHSA-2026:49908",
    "cpe" : "cpe:/a:redhat:rhel_e4s:9.2",
    "package" : "libpq-0:13.23-1.el9_2.1"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
    "release_date" : "2026-06-17T00:00:00Z",
    "advisory" : "RHSA-2026:26524",
    "cpe" : "cpe:/a:redhat:rhel_e4s:9.4",
    "package" : "postgresql:16-9040020260612132455.rhel9"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
    "release_date" : "2026-06-25T00:00:00Z",
    "advisory" : "RHSA-2026:29904",
    "cpe" : "cpe:/a:redhat:rhel_e4s:9.4",
    "package" : "postgresql-0:13.23-1.el9_4.2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
    "release_date" : "2026-06-30T00:00:00Z",
    "advisory" : "RHSA-2026:33441",
    "cpe" : "cpe:/a:redhat:rhel_e4s:9.4",
    "package" : "postgresql:15-9040020260616071806.rhel9"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
    "release_date" : "2026-08-04T00:00:00Z",
    "advisory" : "RHSA-2026:49909",
    "cpe" : "cpe:/a:redhat:rhel_e4s:9.4",
    "package" : "libpq-0:13.23-1.el9_4.1"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.6 Extended Update Support",
    "release_date" : "2026-06-17T00:00:00Z",
    "advisory" : "RHSA-2026:26525",
    "cpe" : "cpe:/a:redhat:rhel_eus:9.6",
    "package" : "postgresql:16-9060020260612084605.rhel9"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.6 Extended Update Support",
    "release_date" : "2026-06-25T00:00:00Z",
    "advisory" : "RHSA-2026:29212",
    "cpe" : "cpe:/a:redhat:rhel_eus:9.6",
    "package" : "postgresql-0:13.23-1.el9_6.2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.6 Extended Update Support",
    "release_date" : "2026-06-29T00:00:00Z",
    "advisory" : "RHSA-2026:32983",
    "cpe" : "cpe:/a:redhat:rhel_eus:9.6",
    "package" : "postgresql:15-9060020260622062902.rhel9"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.6 Extended Update Support",
    "release_date" : "2026-08-05T00:00:00Z",
    "advisory" : "RHSA-2026:50779",
    "cpe" : "cpe:/a:redhat:rhel_eus:9.6",
    "package" : "libpq-0:13.23-1.el9_6.1"
  }, {
    "product_name" : "Red Hat Discovery 2",
    "release_date" : "2026-08-13T00:00:00Z",
    "advisory" : "RHSA-2026:54760",
    "cpe" : "cpe:/a:redhat:discovery:2::el9",
    "package" : "discovery/discovery-server-rhel9:1786638573"
  }, {
    "product_name" : "Red Hat Hardened Images",
    "release_date" : "2026-05-26T00:00:00Z",
    "advisory" : "RHSA-2026:21182",
    "cpe" : "cpe:/a:redhat:hummingbird:1",
    "package" : "postgresql17-main-17.10-0.1.hum1"
  }, {
    "product_name" : "Red Hat Hardened Images",
    "release_date" : "2026-06-03T00:00:00Z",
    "advisory" : "RHSA-2026:22878",
    "cpe" : "cpe:/a:redhat:hummingbird:1",
    "package" : "postgresql18-main-18.4-0.1.hum1"
  }, {
    "product_name" : "Red Hat Update Infrastructure 5",
    "release_date" : "2026-07-23T00:00:00Z",
    "advisory" : "RHSA-2026:44481",
    "cpe" : "cpe:/a:redhat:rhui:5::el9",
    "package" : "rhui5/rhua-rhel9:1784795076"
  }, {
    "product_name" : "Red Hat Update Infrastructure 5",
    "release_date" : "2026-08-24T00:00:00Z",
    "advisory" : "RHSA-2026:58981",
    "cpe" : "cpe:/a:redhat:rhui:5::el9",
    "package" : "rhui5/rhua-tp-rhel9:1787241260"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 6",
    "fix_state" : "Out of support scope",
    "package_name" : "postgresql",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "fix_state" : "Not affected",
    "package_name" : "postgresql",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "fix_state" : "Not affected",
    "package_name" : "postgresql-jdbc",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8"
  }, {
    "product_name" : "Self-service automation portal 2",
    "fix_state" : "Affected",
    "package_name" : "ansible-automation-platform/bootc-automation-portal-rhel9",
    "cpe" : "cpe:/a:redhat:ansible_portal:2"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-6477\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-6477\nhttps://www.postgresql.org/support/security/CVE-2026-6477/" ],
  "name" : "CVE-2026-6477",
  "mitigation" : {
    "value" : "Only connect to trusted PostgreSQL servers. Avoid using psql or pg_dump against untrusted or potentially compromised database servers.",
    "lang" : "en:us"
  },
  "csaw" : false
}