The vendor explicitly identifies these products as affected by this CVE.
- postgresql as a component of Red Hat Enterprise Linux 6
- postgresql-contrib as a component of Red Hat Enterprise Linux 6
- postgresql-devel as a component of Red Hat Enterprise Linux 6
- postgresql-docs as a component of Red Hat Enterprise Linux 6
- postgresql-libs as a component of Red Hat Enterprise Linux 6
- postgresql-plperl as a component of Red Hat Enterprise Linux 6
- postgresql-plpython as a component of Red Hat Enterprise Linux 6
- postgresql-pltcl as a component of Red Hat Enterprise Linux 6
- postgresql-server as a component of Red Hat Enterprise Linux 6
- postgresql-test as a component of Red Hat Enterprise Linux 6
- postgresql.src as a component of Red Hat Enterprise Linux 6
- ansible-automation-platform/bootc-automation-portal-rhel9 as a component of Self-service automation portal 2
- Summary
- A flaw was found in PostgreSQL. This vulnerability, related to symlink following in pg_basebackup (plain format) and pg_rewind, allows an origin superuser to overwrite local files. By exploiting this, an attacker could potentially hijack the operating system account. This attack has practical implications if specific actions are taken, such as moving files to a different virtual machine (VM) or snapshotting the VM, between the execution of these commands and the server's restart.
- Remediation
- For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
