Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Low: libpq security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2023:7016", "synopsis": "Low: libpq security update", "severity": "SEVERITY_LOW", "topic": "An update is available for libpq.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The libpq package provides the PostgreSQL client library, which allows client programs to connect to PostgreSQL servers. \n\nSecurity Fix(es):\n\n* postgresql: Client memory disclosure when connecting with Kerberos to modified server (CVE-2022-41862)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n\nAdditional Changes:\n\nFor detailed information on changes in this release, see the Rocky Linux 8.9 Release Notes linked from the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2165722", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2165722", "description": ""}], "cves": [{"name": "CVE-2022-41862", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41862", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N", "cvss3BaseScore": "3.7", "cwe": "CWE-200"}], "references": [], "publishedAt": "2026-06-28T00:01:03.878968Z", "rpms": {"Rocky Linux 8": {"nvras": ["libpq-0:13.11-1.el8.src.rpm", "libpq-debuginfo-0:13.11-1.el8.aarch64.rpm", "libpq-debugsource-0:13.11-1.el8.aarch64.rpm", "libpq-devel-debuginfo-0:13.11-1.el8.aarch64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Libpq security update for Rocky Linux addresses low severity issues, ensuring better protection against memory disclosure vulnerabilities.. Rocky Linux security updates, libpq security fix, PostgreSQL client library, memory disclosure vulnerability.. Severity: Low. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-27738 http://linux.oracle.com/errata/ELSA-2026-27738.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: libpq-13.23-2.el8_10.i686.rpm libpq-13.23-2.el8_10.x86_64.rpm libpq-devel-13.23-2.el8_10.i686.rpm libpq-devel-13.23-2.el8_10.x86_64.rpm aarch64: libpq-13.23-2.el8_10.aarch64.rpm libpq-devel-13.23-2.el8_10.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates/libpq-13.23-2.el8_10.src.rpm Related CVEs: CVE-2026-6473 CVE-2026-6475 CVE-2026-6477 CVE-2026-6478 Description of changes: [13.23-2] - Backport fixes for CVE-2026-6478, CVE-2026-6637, CVE-2026-6477, CVE-2026-6475, CVE-2026-6473 from PostgreSQL 14.23 - Resolves: RHEL-179806 _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-0695 http://linux.oracle.com/errata/ELSA-2026-0695.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: libpq-13.23-1.el8_10.i686.rpm libpq-13.23-1.el8_10.x86_64.rpm libpq-devel-13.23-1.el8_10.i686.rpm libpq-devel-13.23-1.el8_10.x86_64.rpm aarch64: libpq-13.23-1.el8_10.aarch64.rpm libpq-devel-13.23-1.el8_10.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates/libpq-13.23-1.el8_10.src.rpm Related CVEs: CVE-2025-12818 Description of changes: [13.23-1] - Rebase to upstream release 13.23 - Resolves: RHEL-131269 (CVE-2025-12818) _______________________________________________ El-errata mailing list
Moderate: libpq security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:0695", "synopsis": "Moderate: libpq security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for libpq.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The libpq package provides the PostgreSQL client library, which allows client programs to connect to PostgreSQL servers. \n\nSecurity Fix(es):\n\n* postgresql: libpq undersizes allocations, via integer wraparound (CVE-2025-12818)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2414826", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2414826", "description": ""}], "cves": [{"name": "CVE-2025-12818", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-12818", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-190"}], "references": [], "publishedAt": "2026-01-17T09:03:06.173307Z", "rpms": {"Rocky Linux 8": {"nvras": ["libpq-0:13.23-1.el8_10.aarch64.rpm", "libpq-0:13.23-1.el8_10.i686.rpm", "libpq-0:13.23-1.el8_10.src.rpm", "libpq-0:13.23-1.el8_10.x86_64.rpm", "libpq-debuginfo-0:13.23-1.el8_10.aarch64.rpm", "libpq-debuginfo-0:13.23-1.el8_10.i686.rpm", "libpq-debuginfo-0:13.23-1.el8_10.x86_64.rpm", "libpq-debugsource-0:13.23-1.el8_10.aarch64.rpm", "libpq-debugsource-0:13.23-1.el8_10.i686.rpm", "libpq-debugsource-0:13.23-1.el8_10.x86_64.rpm", "libpq-devel-0:13.23-1.el8_10.aarch64.rpm", "libpq-devel-0:13.23-1.el8_10.i686.rpm", "libpq-devel-0:13.23-1.el8_10.x86_64.rpm", "libpq-devel-debuginfo-0:13.23-1.el8_10.aarch64.rpm","libpq-devel-debuginfo-0:13.23-1.el8_10.i686.rpm", "libpq-devel-debuginfo-0:13.23-1.el8_10.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Security update for libpq on Rocky Linux addresses a moderate severity issue with potential risks from integer wraparound.. libpq security update, Rocky Linux vulnerabilities, PostgreSQL client security, integer wraparound issue. . Severity: moderate. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-0594 http://linux.oracle.com/errata/ELSA-2026-0594.html The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network: x86_64: libpq-16.11-3.el10_1.x86_64.rpm libpq-devel-16.11-3.el10_1.x86_64.rpm aarch64: libpq-16.11-3.el10_1.aarch64.rpm libpq-devel-16.11-3.el10_1.aarch64.rpm SRPMS: http://oss.oracle.com/ol10/SRPMS-updates/libpq-16.11-3.el10_1.src.rpm Related CVEs: CVE-2025-12818 Description of changes: [16.11-3] - Release bump [16.11-1] - Rebase to upstream release 16.11 _______________________________________________ El-errata mailing list
Moderate: libpq security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:0594", "synopsis": "Moderate: libpq security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for libpq.\nThis update affects Rocky Linux 10.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The libpq package provides the PostgreSQL client library, which allows client programs to connect to PostgreSQL servers. \n\nSecurity Fix(es):\n\n* postgresql: libpq undersizes allocations, via integer wraparound (CVE-2025-12818)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 10"], "fixes": [{"ticket": "2414826", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2414826", "description": ""}], "cves": [{"name": "CVE-2025-12818", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-12818", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-190"}], "references": [], "publishedAt": "2026-01-15T09:16:30.973636Z", "rpms": {"Rocky Linux 10": {"nvras": ["libpq-0:16.11-3.el10_1.src.rpm", "libpq-debugsource-0:16.11-3.el10_1.s390x.rpm", "libpq-devel-0:16.11-3.el10_1.ppc64le.rpm", "libpq-0:16.11-3.el10_1.ppc64le.rpm", "libpq-devel-debuginfo-0:16.11-3.el10_1.ppc64le.rpm", "libpq-devel-debuginfo-0:16.11-3.el10_1.s390x.rpm", "libpq-debugsource-0:16.11-3.el10_1.x86_64.rpm", "libpq-devel-0:16.11-3.el10_1.s390x.rpm", "libpq-0:16.11-3.el10_1.s390x.rpm", "libpq-devel-debuginfo-0:16.11-3.el10_1.aarch64.rpm", "libpq-0:16.11-3.el10_1.x86_64.rpm", "libpq-devel-0:16.11-3.el10_1.aarch64.rpm", "libpq-devel-0:16.11-3.el10_1.x86_64.rpm", "libpq-0:16.11-3.el10_1.aarch64.rpm","libpq-debuginfo-0:16.11-3.el10_1.aarch64.rpm", "libpq-debuginfo-0:16.11-3.el10_1.x86_64.rpm", "libpq-debugsource-0:16.11-3.el10_1.ppc64le.rpm", "libpq-devel-debuginfo-0:16.11-3.el10_1.x86_64.rpm", "libpq-debuginfo-0:16.11-3.el10_1.ppc64le.rpm", "libpq-debugsource-0:16.11-3.el10_1.aarch64.rpm", "libpq-debuginfo-0:16.11-3.el10_1.s390x.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. A moderate security update is available for libpq on Rocky Linux 10 addressing an integer wraparound issue.. libpq security update, integer wraparound, Rocky Linux 10, PostgreSQL update, CVE-2025-12818. . Severity: moderate. LinuxSecurity.com Team
Moderate: libpq security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:0458", "synopsis": "Moderate: libpq security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for libpq.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The libpq package provides the PostgreSQL client library, which allows client programs to connect to PostgreSQL servers. \n\nSecurity Fix(es):\n\n* postgresql: libpq undersizes allocations, via integer wraparound (CVE-2025-12818)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2414826", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2414826", "description": ""}], "cves": [{"name": "CVE-2025-12818", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-12818", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-190"}], "references": [], "publishedAt": "2026-01-14T09:11:53.425821Z", "rpms": {"Rocky Linux 9": {"nvras": ["libpq-0:13.23-1.el9_7.aarch64.rpm", "libpq-0:13.23-1.el9_7.i686.rpm", "libpq-0:13.23-1.el9_7.ppc64le.rpm", "libpq-0:13.23-1.el9_7.s390x.rpm", "libpq-0:13.23-1.el9_7.src.rpm", "libpq-0:13.23-1.el9_7.x86_64.rpm", "libpq-debuginfo-0:13.23-1.el9_7.aarch64.rpm", "libpq-debuginfo-0:13.23-1.el9_7.i686.rpm", "libpq-debuginfo-0:13.23-1.el9_7.ppc64le.rpm", "libpq-debuginfo-0:13.23-1.el9_7.s390x.rpm", "libpq-debuginfo-0:13.23-1.el9_7.x86_64.rpm", "libpq-debugsource-0:13.23-1.el9_7.aarch64.rpm", "libpq-debugsource-0:13.23-1.el9_7.i686.rpm", "libpq-debugsource-0:13.23-1.el9_7.ppc64le.rpm", "libpq-debugsource-0:13.23-1.el9_7.s390x.rpm","libpq-debugsource-0:13.23-1.el9_7.x86_64.rpm", "libpq-devel-0:13.23-1.el9_7.aarch64.rpm", "libpq-devel-0:13.23-1.el9_7.i686.rpm", "libpq-devel-0:13.23-1.el9_7.ppc64le.rpm", "libpq-devel-0:13.23-1.el9_7.s390x.rpm", "libpq-devel-0:13.23-1.el9_7.x86_64.rpm", "libpq-devel-debuginfo-0:13.23-1.el9_7.aarch64.rpm", "libpq-devel-debuginfo-0:13.23-1.el9_7.i686.rpm", "libpq-devel-debuginfo-0:13.23-1.el9_7.ppc64le.rpm", "libpq-devel-debuginfo-0:13.23-1.el9_7.s390x.rpm", "libpq-devel-debuginfo-0:13.23-1.el9_7.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. A moderate libpq security update available for Rocky Linux 9 addresses a critical issue affecting PostgreSQL connections.. libpq security update, Rocky Linux, PostgreSQL client, security advisory. . Severity: moderate. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-0458 http://linux.oracle.com/errata/ELSA-2026-0458.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: libpq-13.23-1.el9_7.i686.rpm libpq-13.23-1.el9_7.x86_64.rpm libpq-devel-13.23-1.el9_7.i686.rpm libpq-devel-13.23-1.el9_7.x86_64.rpm aarch64: libpq-13.23-1.el9_7.aarch64.rpm libpq-devel-13.23-1.el9_7.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates/libpq-13.23-1.el9_7.src.rpm Related CVEs: CVE-2025-12818 Description of changes: [13.23-1] - Rebase to upstream release 13.23 - Resolves: RHEL-131279 (CVE-2025-12818) _______________________________________________ El-errata mailing list
Get the latest Linux and open source security news straight to your inbox.