{
  "threat_severity" : "Important",
  "public_date" : "2026-05-14T13:00:15Z",
  "bugzilla" : {
    "description" : "postgresql: PostgreSQL: Arbitrary code execution vulnerability in 'refint' module",
    "id" : "2477443",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2477443"
  },
  "cvss3" : {
    "cvss3_base_score" : "8.8",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-120",
  "details" : [ "Stack buffer overflow in PostgreSQL module \"refint\" allows an unprivileged database user to execute arbitrary code as the operating system user running the database.  A distinct attack is possible if the application declares a user-controlled column as a \"refint\" cascade primary key and facilitates user-controlled updates to that column.  In that case, a SQL injection allows a primary key update value provider to execute arbitrary SQL as the database user performing the primary key update.  Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.", "A flaw was found in PostgreSQL. A stack buffer overflow in the 'refint' module allows an unprivileged database user to execute arbitrary code as the operating system user running the database. Additionally, a separate vulnerability exists where, if an application uses a user-controlled column as a 'refint' cascade primary key and allows user-controlled updates, a SQL injection can enable an attacker to execute arbitrary SQL commands as the database user performing the update." ],
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 10",
    "release_date" : "2026-06-22T00:00:00Z",
    "advisory" : "RHSA-2026:27742",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10.2",
    "package" : "postgresql18-0:18.4-1.el10_2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 10",
    "release_date" : "2026-06-22T00:00:00Z",
    "advisory" : "RHSA-2026:27743",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10.2",
    "package" : "postgresql16-0:16.14-1.el10_2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 10.0 Extended Update Support",
    "release_date" : "2026-06-22T00:00:00Z",
    "advisory" : "RHSA-2026:27718",
    "cpe" : "cpe:/o:redhat:enterprise_linux_eus:10.0",
    "package" : "postgresql16-0:16.14-1.el10_0"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
    "release_date" : "2026-08-03T00:00:00Z",
    "advisory" : "RHSA-2026:49521",
    "cpe" : "cpe:/o:redhat:rhel_els:7",
    "package" : "postgresql-0:9.2.24-9.el7_9.6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2026-06-16T00:00:00Z",
    "advisory" : "RHSA-2026:26181",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "postgresql:15-8100020260605152259.489197e6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2026-06-23T00:00:00Z",
    "advisory" : "RHSA-2026:28143",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "postgresql:16-8100020260530205218.489197e6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2026-06-23T00:00:00Z",
    "advisory" : "RHSA-2026:28208",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "postgresql:13-8100020260605152256.489197e6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2026-06-24T00:00:00Z",
    "advisory" : "RHSA-2026:28999",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "postgresql:12-8100020260605152253.489197e6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
    "release_date" : "2026-07-01T00:00:00Z",
    "advisory" : "RHSA-2026:34362",
    "cpe" : "cpe:/a:redhat:rhel_aus:8.4",
    "package" : "postgresql:12-8040020260624104459.522a0ee4"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
    "release_date" : "2026-07-01T00:00:00Z",
    "advisory" : "RHSA-2026:34363",
    "cpe" : "cpe:/a:redhat:rhel_aus:8.4",
    "package" : "postgresql:13-8040020260630100922.522a0ee4"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
    "release_date" : "2026-07-01T00:00:00Z",
    "advisory" : "RHSA-2026:34362",
    "cpe" : "cpe:/a:redhat:rhel_eus_long_life:8.4",
    "package" : "postgresql:12-8040020260624104459.522a0ee4"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
    "release_date" : "2026-07-01T00:00:00Z",
    "advisory" : "RHSA-2026:34363",
    "cpe" : "cpe:/a:redhat:rhel_eus_long_life:8.4",
    "package" : "postgresql:13-8040020260630100922.522a0ee4"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
    "release_date" : "2026-06-25T00:00:00Z",
    "advisory" : "RHSA-2026:29815",
    "cpe" : "cpe:/a:redhat:rhel_aus:8.6",
    "package" : "postgresql:12-8060020260623094704.ad008a3a"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
    "release_date" : "2026-06-29T00:00:00Z",
    "advisory" : "RHSA-2026:32994",
    "cpe" : "cpe:/a:redhat:rhel_aus:8.6",
    "package" : "postgresql:13-8060020260625065744.ad008a3a"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
    "release_date" : "2026-06-25T00:00:00Z",
    "advisory" : "RHSA-2026:29815",
    "cpe" : "cpe:/a:redhat:rhel_eus_long_life:8.6",
    "package" : "postgresql:12-8060020260623094704.ad008a3a"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
    "release_date" : "2026-06-29T00:00:00Z",
    "advisory" : "RHSA-2026:32994",
    "cpe" : "cpe:/a:redhat:rhel_eus_long_life:8.6",
    "package" : "postgresql:13-8060020260625065744.ad008a3a"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
    "release_date" : "2026-06-17T00:00:00Z",
    "advisory" : "RHSA-2026:26561",
    "cpe" : "cpe:/a:redhat:rhel_tus:8.8",
    "package" : "postgresql:15-8080020260615085052.63b34585"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
    "release_date" : "2026-07-01T00:00:00Z",
    "advisory" : "RHSA-2026:34043",
    "cpe" : "cpe:/a:redhat:rhel_tus:8.8",
    "package" : "postgresql:12-8080020260626093604.63b34585"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
    "release_date" : "2026-07-21T00:00:00Z",
    "advisory" : "RHSA-2026:42555",
    "cpe" : "cpe:/a:redhat:rhel_tus:8.8",
    "package" : "postgresql:13-8080020260709122729.63b34585"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
    "release_date" : "2026-06-17T00:00:00Z",
    "advisory" : "RHSA-2026:26561",
    "cpe" : "cpe:/a:redhat:rhel_e4s:8.8",
    "package" : "postgresql:15-8080020260615085052.63b34585"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
    "release_date" : "2026-07-01T00:00:00Z",
    "advisory" : "RHSA-2026:34043",
    "cpe" : "cpe:/a:redhat:rhel_e4s:8.8",
    "package" : "postgresql:12-8080020260626093604.63b34585"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
    "release_date" : "2026-07-21T00:00:00Z",
    "advisory" : "RHSA-2026:42555",
    "cpe" : "cpe:/a:redhat:rhel_e4s:8.8",
    "package" : "postgresql:13-8080020260709122729.63b34585"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2026-06-16T00:00:00Z",
    "advisory" : "RHSA-2026:26203",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "postgresql:16-9080020260605131007.rhel9"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2026-06-16T00:00:00Z",
    "advisory" : "RHSA-2026:26204",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "postgresql:18-9080020260605125734.rhel9"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2026-06-22T00:00:00Z",
    "advisory" : "RHSA-2026:27741",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "postgresql-0:13.23-3.el9_8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2026-06-22T00:00:00Z",
    "advisory" : "RHSA-2026:28037",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "postgresql:15-9080020260605124405.rhel9"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
    "release_date" : "2026-06-25T00:00:00Z",
    "advisory" : "RHSA-2026:29953",
    "cpe" : "cpe:/a:redhat:rhel_e4s:9.2",
    "package" : "postgresql-0:13.23-1.el9_2.2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
    "release_date" : "2026-06-30T00:00:00Z",
    "advisory" : "RHSA-2026:33497",
    "cpe" : "cpe:/a:redhat:rhel_e4s:9.2",
    "package" : "postgresql:15-9020020260625101129.rhel9"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
    "release_date" : "2026-08-05T00:00:00Z",
    "advisory" : "RHSA-2026:50811",
    "cpe" : "cpe:/a:redhat:rhel_e4s:9.2",
    "package" : "postgresql-0:13.23-1.el9_2.3"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
    "release_date" : "2026-06-17T00:00:00Z",
    "advisory" : "RHSA-2026:26524",
    "cpe" : "cpe:/a:redhat:rhel_e4s:9.4",
    "package" : "postgresql:16-9040020260612132455.rhel9"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
    "release_date" : "2026-06-25T00:00:00Z",
    "advisory" : "RHSA-2026:29904",
    "cpe" : "cpe:/a:redhat:rhel_e4s:9.4",
    "package" : "postgresql-0:13.23-1.el9_4.2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
    "release_date" : "2026-06-30T00:00:00Z",
    "advisory" : "RHSA-2026:33441",
    "cpe" : "cpe:/a:redhat:rhel_e4s:9.4",
    "package" : "postgresql:15-9040020260616071806.rhel9"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.6 Extended Update Support",
    "release_date" : "2026-06-17T00:00:00Z",
    "advisory" : "RHSA-2026:26525",
    "cpe" : "cpe:/a:redhat:rhel_eus:9.6",
    "package" : "postgresql:16-9060020260612084605.rhel9"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.6 Extended Update Support",
    "release_date" : "2026-06-25T00:00:00Z",
    "advisory" : "RHSA-2026:29212",
    "cpe" : "cpe:/a:redhat:rhel_eus:9.6",
    "package" : "postgresql-0:13.23-1.el9_6.2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.6 Extended Update Support",
    "release_date" : "2026-06-29T00:00:00Z",
    "advisory" : "RHSA-2026:32983",
    "cpe" : "cpe:/a:redhat:rhel_eus:9.6",
    "package" : "postgresql:15-9060020260622062902.rhel9"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.6 Extended Update Support",
    "release_date" : "2026-08-04T00:00:00Z",
    "advisory" : "RHSA-2026:50119",
    "cpe" : "cpe:/a:redhat:rhel_eus:9.6",
    "package" : "postgresql-0:13.23-1.el9_6.3"
  }, {
    "product_name" : "Red Hat Hardened Images",
    "release_date" : "2026-05-26T00:00:00Z",
    "advisory" : "RHSA-2026:21182",
    "cpe" : "cpe:/a:redhat:hummingbird:1",
    "package" : "postgresql17-main-17.10-0.1.hum1"
  }, {
    "product_name" : "Red Hat Hardened Images",
    "release_date" : "2026-06-03T00:00:00Z",
    "advisory" : "RHSA-2026:22878",
    "cpe" : "cpe:/a:redhat:hummingbird:1",
    "package" : "postgresql18-main-18.4-0.1.hum1"
  }, {
    "product_name" : "Red Hat Update Infrastructure 5",
    "release_date" : "2026-07-23T00:00:00Z",
    "advisory" : "RHSA-2026:44481",
    "cpe" : "cpe:/a:redhat:rhui:5::el9",
    "package" : "rhui5/rhua-rhel9:1784795076"
  }, {
    "product_name" : "Red Hat Update Infrastructure 5",
    "release_date" : "2026-08-24T00:00:00Z",
    "advisory" : "RHSA-2026:58981",
    "cpe" : "cpe:/a:redhat:rhui:5::el9",
    "package" : "rhui5/rhua-tp-rhel9:1787241260"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 6",
    "fix_state" : "Not affected",
    "package_name" : "postgresql",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6"
  }, {
    "product_name" : "Self-service automation portal 2",
    "fix_state" : "Affected",
    "package_name" : "ansible-automation-platform/bootc-automation-portal-rhel9",
    "cpe" : "cpe:/a:redhat:ansible_portal:2"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-6637\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-6637\nhttps://www.postgresql.org/support/security/CVE-2026-6637/" ],
  "name" : "CVE-2026-6637",
  "csaw" : false
}