[CLSA-2026:1785227558] libpq: Fix of CVE-2026-6477
Type:
security
Severity:
Important
Release date:
2026-07-28 08:32:48 UTC
Description:
- CVE-2026-6477: bound the PQfn() result copy so a malicious server cannot overwrite client stack buffers via lo_read/lo_lseek64/lo_tell64/lo_export
CVEs fixed:
Updated packages:
  • libpq-13.23-1.el9.tuxcare.els2.i686.rpm
    sha:8a4bf7a5d5700c3887f28937b4d43acf86a7c995617e96e9b6bec4dc99ed46b9
  • libpq-13.23-1.el9.tuxcare.els2.x86_64.rpm
    sha:5415673a471cea2f7d51e6ca3d21731f3189599bcbfcf755cd9d5556fa7e060b
  • libpq-devel-13.23-1.el9.tuxcare.els2.i686.rpm
    sha:4f557d06f4c35fc57f776ee095cfd6e1f0fe8b9f9a2737fb86473dfce7996994
  • libpq-devel-13.23-1.el9.tuxcare.els2.x86_64.rpm
    sha:abe473d36ca3ccbd6ae589704e138cac4adcf88dd29030d2bd01be350b2b8010
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.