CVE-2026-6478

Red Hat Security Advisory: Red Hat Update Infrastructure 5.3 Technology Preview security update

Beschreibung

Ein verdeckter Zeitkanal bei der Vergleichung von MD5-gespeicherten Passwörtern in der PostgreSQL-Authentifizierung ermöglicht es einem Angreifer, Benutzeranmeldeinformationen zu erlangen, die zur Authentifizierung ausreichend sind. Dies betrifft scram-sha-256-Passwörter nicht, da diese das Standardformat in allen unterstützten Versionen sind. Aktuelle Datenbanken können jedoch MD5-gespeicherte Passwörter enthalten, die aus Upgrades von PostgreSQL 13 oder früher stammen. Betroffen sind Versionen vor PostgreSQL 18.4, 17.10, 16.14, 15.18 und 14.23.

Metriken

Severity
medium
kein öffentlicher PoC bekannt
6.5
Quelle: nvd-v3
44.7 %
Hoch — CVE rangiert über dem Median aller heute bewerteten CVEs (Rang ≥ 36 %).
0.6 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-08-24 11:15 UTC
CWE-385

Weakness-Klassen (CWE)

  • CWE-385Base

    Covert Timing Channel

    Covert timing channels convey information by modulating some aspect of system behavior over time, so that the program receiving the information can observe system behavior and infer protected information.

    cwe.mitre.org →

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. CVE Modified2026-08-25 13:19 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Reference: https://access.redhat.com/errata/RHSA-2026:58981
    • Affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support (+43)Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support (+44)
  2. CVE Modified2026-08-03 13:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Reference: https://access.redhat.com/errata/RHSA-2026:49521
    • Affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support (+43)Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support (+43)
  3. CVE Modified2026-07-24 13:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Reference: https://access.redhat.com/errata/RHSA-2026:44420
    • Reference: https://access.redhat.com/errata/RHSA-2026:44481
    • Affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support (+40)Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support (+43)
  4. CVE Modified2026-07-21 12:19 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Reference: https://access.redhat.com/errata/RHSA-2026:42555
    • Affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support (+38)Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support (+40)
  5. CVE Modified2026-07-06 13:17 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Reference: https://access.redhat.com/errata/RHSA-2026:35880

Betroffene Betriebssysteme

  • linux

    ubuntu / coreutilsjammy

  • linux

    ubuntu / coreutilsnoble

  • linux

    ubuntu / coreutilsresolute

  • linux

    debian / debian_linux11.0

  • linux

    redhat / enterprise_linux10.0

  • linux

    redhat / enterprise_linux10.2

  • linux

    redhat / enterprise_linux6.0

  • linux

    redhat / enterprise_linux7.0

  • linux

    redhat / enterprise_linux8.0

  • linux

    redhat / enterprise_linux9.0

  • linux

    redhat / enterprise_linux9.8

  • linux

    redhat / enterprise_linux_for_els10.2

  • linux

    redhat / enterprise_linux_for_els8.10

  • linux

    redhat / enterprise_linux_for_els9.8

  • linux

    redhat / enterprise_linux_for_eus10.2

  • linux

    redhat / enterprise_linux_for_eus9.8

  • linux

    redhat / enterprise_linux_for_ibm_z_systems10.2

  • linux

    redhat / enterprise_linux_for_ibm_z_systems8.0_s390x

  • linux

    redhat / enterprise_linux_for_ibm_z_systems9.0_s390x

  • linux

    redhat / enterprise_linux_for_ibm_z_systems_els10.2

  • linux

    redhat / enterprise_linux_for_ibm_z_systems_els8.10

  • linux

    redhat / enterprise_linux_for_ibm_z_systems_els9.8

  • linux

    redhat / enterprise_linux_for_ibm_z_systems_eus10.2

  • linux

    redhat / enterprise_linux_for_ibm_z_systems_eus9.8

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • Apple

    iOS18.7.10

  • Apple

    iOS26.6.1

  • Apple

    iPadOS18.7.10

  • Apple

    iPadOS26.6.1

  • Apple

    macOSTahoe 26.6.2

  • bitnami

    jre1.9.0

  • bitnami

    nginx-gateway0.1.17

  • bitnami

    nginx-gateway-fabric1.3.0

  • bitnami

    postgresql15.0.0

  • bitnami

    postgresql16.0.0

  • bitnami

    postgresql17.0.0

  • bitnami

    postgresql18.0.0

  • bitnami

    python-min3.10.0

  • bitnami

    python-min3.11.0

  • bitnami

    python-min3.12.0

  • bitnami

    python-min3.13.0

  • bitnami

    python-min3.14.0

  • f5

    dos4.3.0 – 4.7.0

  • f5

    dos

  • f5

    nginx_gateway_fabric1.3.0 – 1.6.2

  • f5

    nginx_gateway_fabric2.0.0 – 2.5.1

  • f5

    nginx_ingress_controller3.5.0 – 3.7.2

  • f5

    nginx_ingress_controller4.0.0 – 4.0.1

  • f5

    nginx_ingress_controller5.0.0 – 5.4.1

Quellen & Referenzen

Verknüpfte CVEs

93 weitere CVEs anzeigen
IDCVE-2026-6478