Skip to main content
EPSS 0.1%top 99%

Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update

0
High
Published: 08/20/2026 (08/20/2026, 00:00:18 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Red Hat has issued a security advisory for Red Hat Hardened Images RPMs, including multiple PostgreSQL 17 packages. The update addresses several vulnerabilities identified by CVE-2026-14663 and others. This advisory provides updated RPM packages for various PostgreSQL components across aarch64 and x86_64 architectures. The update is classified as a high severity security advisory and includes bug fixes and enhancements. A patch is available and should be applied to affected systems to mitigate the vulnerabilities.

Affected software

Postgresqlmore threats →ai
postgresql/postgresql
pkg:deb/postgresql/postgresql
Affected versions
<18.5<17.11<16.15<15.19<14.24

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/24/2026, 08:32:48 UTC

Technical Analysis

This Red Hat security advisory (RHSA-2026:57198) addresses vulnerabilities in Red Hat Hardened Images RPMs, specifically PostgreSQL 17 packages. The update includes new versions of postgresql17 and related packages (e.g., postgresql17-contrib, postgresql17-plperl, postgresql17-server) for aarch64 and x86_64 architectures. The advisory references CVE-2026-14663 among others and provides updated RPMs to fix these issues. The advisory does not detail the specific nature of the vulnerabilities but lists relevant CWEs such as CWE-313, CWE-345, CWE-312, CWE-426, and CWE-122, indicating issues related to information exposure, improper validation, and memory management. The vendor confirms a patch is available and recommends applying the update.

Potential Impact

The vulnerabilities addressed in this advisory are rated high severity, indicating a significant security risk if left unpatched. The issues involve multiple CWEs related to information exposure and memory handling, which could potentially lead to unauthorized information disclosure or other security breaches. However, there are no known exploits in the wild at the time of this advisory. Systems running affected versions of PostgreSQL 17 packages in Red Hat Hardened Images are vulnerable until updated.

Mitigation Recommendations

A patch is available for the affected PostgreSQL 17 RPM packages as part of the Red Hat Hardened Images update. Users should apply the updated packages (version 17.11-1.hum1) for all relevant PostgreSQL 17 components on supported architectures (aarch64, x86_64) as soon as possible. Refer to the official Red Hat advisory RHSA-2026:57198 and the Red Hat images portal (https://images.redhat.com/) for detailed update instructions. No additional mitigation steps are indicated by the vendor.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-6hh9-353p-vfvp
Osv Schema Version
1.4.0
Aliases
["CVE-2026-14663"]
Database Specific Severity
MODERATE
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6a7e0368bf8831d5398f8845

Added to database: 08/13/2026, 17:48:24 UTC

Last enriched: 09/24/2026, 08:32:48 UTC

Last updated: 09/28/2026, 18:25:59 UTC

Views: 51

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses