PostgreSQL pg_basebackup and pg_rewind can overwrite unrelated files of origin superuser choice (CVE-2026-6475)
Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
AI Analysis
Technical Summary
This Red Hat security advisory covers a bug fix and enhancement update for Red Hat Hardened Images RPMs, specifically including PostgreSQL 17.10-0.1.hum1 packages for aarch64 and x86_64 architectures. Among the fixed issues is CVE-2026-6478, a vulnerability in PostgreSQL where a covert timing channel exists in the comparison of MD5-hashed passwords during authentication. This flaw could allow a remote attacker to recover user credentials and gain unauthorized database access. The vulnerability affects databases retaining MD5-hashed passwords from upgrades of PostgreSQL 13 or earlier. The advisory recommends migrating user passwords to stronger hashing algorithms such as scram-sha-256 by altering user passwords, which updates the stored hash. The update includes multiple related RPM packages and is available from Red Hat's public repositories. No exploits in the wild are currently known. The advisory references multiple CVEs and CWE identifiers related to the vulnerabilities addressed.
Potential Impact
The primary impact is unauthorized access to PostgreSQL databases through credential recovery via a covert timing channel in MD5 password comparison. Confidentiality is highly impacted as attackers could recover user credentials remotely without authentication. Integrity impact is low and availability is not affected. The vulnerability specifically affects PostgreSQL instances that still use MD5-hashed passwords from legacy upgrades. Other vulnerabilities addressed in the update are not detailed in the provided data. No active exploitation has been reported.
Mitigation Recommendations
A fix is available via the updated Red Hat Hardened Images RPM packages, including PostgreSQL 17.10-0.1.hum1 and related components. Users should apply this update promptly. To mitigate CVE-2026-6478, users must ensure PostgreSQL user passwords are not hashed using MD5 by migrating to stronger algorithms such as scram-sha-256. This is done by altering user passwords (e.g., using ALTER USER commands), which updates the password hash. Services relying on these credentials may require a restart to apply changes. Follow Red Hat's official advisory and update instructions at https://access.redhat.com/errata/RHSA-2026:21182 for detailed guidance.
PostgreSQL pg_basebackup and pg_rewind can overwrite unrelated files of origin superuser choice (CVE-2026-6475)
Description
Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Affected software
pkg:rpm/redhat/postgresql17Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This Red Hat security advisory covers a bug fix and enhancement update for Red Hat Hardened Images RPMs, specifically including PostgreSQL 17.10-0.1.hum1 packages for aarch64 and x86_64 architectures. Among the fixed issues is CVE-2026-6478, a vulnerability in PostgreSQL where a covert timing channel exists in the comparison of MD5-hashed passwords during authentication. This flaw could allow a remote attacker to recover user credentials and gain unauthorized database access. The vulnerability affects databases retaining MD5-hashed passwords from upgrades of PostgreSQL 13 or earlier. The advisory recommends migrating user passwords to stronger hashing algorithms such as scram-sha-256 by altering user passwords, which updates the stored hash. The update includes multiple related RPM packages and is available from Red Hat's public repositories. No exploits in the wild are currently known. The advisory references multiple CVEs and CWE identifiers related to the vulnerabilities addressed.
Potential Impact
The primary impact is unauthorized access to PostgreSQL databases through credential recovery via a covert timing channel in MD5 password comparison. Confidentiality is highly impacted as attackers could recover user credentials remotely without authentication. Integrity impact is low and availability is not affected. The vulnerability specifically affects PostgreSQL instances that still use MD5-hashed passwords from legacy upgrades. Other vulnerabilities addressed in the update are not detailed in the provided data. No active exploitation has been reported.
Mitigation Recommendations
A fix is available via the updated Red Hat Hardened Images RPM packages, including PostgreSQL 17.10-0.1.hum1 and related components. Users should apply this update promptly. To mitigate CVE-2026-6478, users must ensure PostgreSQL user passwords are not hashed using MD5 by migrating to stronger algorithms such as scram-sha-256. This is done by altering user passwords (e.g., using ALTER USER commands), which updates the password hash. Services relying on these credentials may require a restart to apply changes. Follow Red Hat's official advisory and update instructions at https://access.redhat.com/errata/RHSA-2026:21182 for detailed guidance.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:21182
- Cve Count
- 4
- Additional Cves
- ["CVE-2026-6477","CVE-2026-6478","CVE-2026-6575"]
- State
- PUBLISHED
Threat ID: 6a297639c9170919df2afabf
Added to database: 06/10/2026, 14:35:37 UTC
Last enriched: 08/10/2026, 19:33:47 UTC
Last updated: 09/12/2026, 04:46:43 UTC
Views: 265
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.