PostgreSQL pg_basebackup and pg_rewind can overwrite unrelated files of origin superuser choice
Published May 14, 2026
8.8
HIGHCVSS 3.1
EPSS 0.32%
Description
Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Affected products
- Vendor n/a Product PostgreSQL Defaultunaffected
- Version 0StatusaffectedConstraints<14.23
- Version 15StatusaffectedConstraints<15.18
- Version 16StatusaffectedConstraints<16.14
- Version 17StatusaffectedConstraints<17.10
- Version 18StatusaffectedConstraints<18.4
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| n/a | PostgreSQL | unaffected |
|
- < 14.23
- ≥ 15.0 · < 15.18
- ≥ 16.0 · < 16.14
- ≥ 17.0 · < 17.10
- ≥ 18.0 · < 18.4
No data.
Red Hat Enterprise Linux 10
postgresql16-0:16.14-1.el10_2
Fixed · RHSA-2026:27743
Red Hat Enterprise Linux 10
postgresql18-0:18.4-1.el10_2
Fixed · RHSA-2026:27742
Red Hat Enterprise Linux 10.0 Extended Update Support
postgresql16-0:16.14-1.el10_0
Fixed · RHSA-2026:27718
Red Hat Enterprise Linux 8
libpq-0:13.23-2.el8_10
Fixed · RHSA-2026:27738
Red Hat Enterprise Linux 8
postgresql:12-8100020260605152253.489197e6
Fixed · RHSA-2026:28999
Red Hat Enterprise Linux 8
postgresql:13-8100020260605152256.489197e6
Fixed · RHSA-2026:28208
Red Hat Enterprise Linux 8
postgresql:15-8100020260605152259.489197e6
Fixed · RHSA-2026:26181
Red Hat Enterprise Linux 8
postgresql:16-8100020260530205218.489197e6
Fixed · RHSA-2026:28143
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
libpq-0:13.23-1.el8_4.1
Fixed · RHSA-2026:44420
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
postgresql:12-8040020260624104459.522a0ee4
Fixed · RHSA-2026:34362
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
postgresql:13-8040020260630100922.522a0ee4
Fixed · RHSA-2026:34363
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
libpq-0:13.23-1.el8_4.1
Fixed · RHSA-2026:44420
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
postgresql:12-8040020260624104459.522a0ee4
Fixed · RHSA-2026:34362
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
postgresql:13-8040020260630100922.522a0ee4
Fixed · RHSA-2026:34363
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
postgresql:12-8060020260623094704.ad008a3a
Fixed · RHSA-2026:29815
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
postgresql:13-8060020260625065744.ad008a3a
Fixed · RHSA-2026:32994
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On
postgresql:12-8060020260623094704.ad008a3a
Fixed · RHSA-2026:29815
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On
postgresql:13-8060020260625065744.ad008a3a
Fixed · RHSA-2026:32994
Red Hat Enterprise Linux 8.8 Telecommunications Update Service
libpq-0:13.23-1.el8_8.1
Fixed · RHSA-2026:35880
Red Hat Enterprise Linux 8.8 Telecommunications Update Service
postgresql:12-8080020260626093604.63b34585
Fixed · RHSA-2026:34043
Red Hat Enterprise Linux 8.8 Telecommunications Update Service
postgresql:13-8080020260709122729.63b34585
Fixed · RHSA-2026:42555
Red Hat Enterprise Linux 8.8 Telecommunications Update Service
postgresql:15-8080020260615085052.63b34585
Fixed · RHSA-2026:26561
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
libpq-0:13.23-1.el8_8.1
Fixed · RHSA-2026:35880
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
postgresql:12-8080020260626093604.63b34585
Fixed · RHSA-2026:34043
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
postgresql:13-8080020260709122729.63b34585
Fixed · RHSA-2026:42555
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
postgresql:15-8080020260615085052.63b34585
Fixed · RHSA-2026:26561
Red Hat Enterprise Linux 9
postgresql-0:13.23-3.el9_8
Fixed · RHSA-2026:27741
Red Hat Enterprise Linux 9
postgresql:15-9080020260605124405.rhel9
Fixed · RHSA-2026:28037
Red Hat Enterprise Linux 9
postgresql:16-9080020260605131007.rhel9
Fixed · RHSA-2026:26203
Red Hat Enterprise Linux 9
postgresql:18-9080020260605125734.rhel9
Fixed · RHSA-2026:26204
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
postgresql-0:13.23-1.el9_2.2
Fixed · RHSA-2026:29953
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
postgresql:15-9020020260625101129.rhel9
Fixed · RHSA-2026:33497
Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions
postgresql-0:13.23-1.el9_4.2
Fixed · RHSA-2026:29904
Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions
postgresql:15-9040020260616071806.rhel9
Fixed · RHSA-2026:33441
Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions
postgresql:16-9040020260612132455.rhel9
Fixed · RHSA-2026:26524
Red Hat Enterprise Linux 9.6 Extended Update Support
postgresql-0:13.23-1.el9_6.2
Fixed · RHSA-2026:29212
Red Hat Enterprise Linux 9.6 Extended Update Support
postgresql:15-9060020260622062902.rhel9
Fixed · RHSA-2026:32983
Red Hat Enterprise Linux 9.6 Extended Update Support
postgresql:16-9060020260612084605.rhel9
Fixed · RHSA-2026:26525
Red Hat Hardened Images
postgresql17-main-17.10-0.1.hum1
Fixed · RHSA-2026:21182
Red Hat Hardened Images
postgresql18-main-18.4-0.1.hum1
Fixed · RHSA-2026:22878
Red Hat Update Infrastructure 5
rhui5/rhua-rhel9:1784795076
Fixed · RHSA-2026:44481
Red Hat Update Infrastructure 5
rhui5/rhua-tp-rhel9:1787241260
Fixed · RHSA-2026:58981
Red Hat Enterprise Linux 6
postgresql
Out of support scope
Red Hat Enterprise Linux 7
postgresql
Not affected
Red Hat Enterprise Linux 8
postgresql
Not affected
Red Hat Enterprise Linux 8
postgresql-jdbc
Not affected
Self-service automation portal 2
ansible-automation-platform/bootc-automation-portal-rhel9
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | postgresql16-0:16.14-1.el10_2 | Fixed | RHSA-2026:27743 |
| Red Hat Enterprise Linux 10 | postgresql18-0:18.4-1.el10_2 | Fixed | RHSA-2026:27742 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | postgresql16-0:16.14-1.el10_0 | Fixed | RHSA-2026:27718 |
| Red Hat Enterprise Linux 8 | libpq-0:13.23-2.el8_10 | Fixed | RHSA-2026:27738 |
| Red Hat Enterprise Linux 8 | postgresql:12-8100020260605152253.489197e6 | Fixed | RHSA-2026:28999 |
| Red Hat Enterprise Linux 8 | postgresql:13-8100020260605152256.489197e6 | Fixed | RHSA-2026:28208 |
| Red Hat Enterprise Linux 8 | postgresql:15-8100020260605152259.489197e6 | Fixed | RHSA-2026:26181 |
| Red Hat Enterprise Linux 8 | postgresql:16-8100020260530205218.489197e6 | Fixed | RHSA-2026:28143 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | libpq-0:13.23-1.el8_4.1 | Fixed | RHSA-2026:44420 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | postgresql:12-8040020260624104459.522a0ee4 | Fixed | RHSA-2026:34362 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | postgresql:13-8040020260630100922.522a0ee4 | Fixed | RHSA-2026:34363 |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | libpq-0:13.23-1.el8_4.1 | Fixed | RHSA-2026:44420 |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | postgresql:12-8040020260624104459.522a0ee4 | Fixed | RHSA-2026:34362 |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | postgresql:13-8040020260630100922.522a0ee4 | Fixed | RHSA-2026:34363 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | postgresql:12-8060020260623094704.ad008a3a | Fixed | RHSA-2026:29815 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | postgresql:13-8060020260625065744.ad008a3a | Fixed | RHSA-2026:32994 |
| Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On | postgresql:12-8060020260623094704.ad008a3a | Fixed | RHSA-2026:29815 |
| Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On | postgresql:13-8060020260625065744.ad008a3a | Fixed | RHSA-2026:32994 |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | libpq-0:13.23-1.el8_8.1 | Fixed | RHSA-2026:35880 |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | postgresql:12-8080020260626093604.63b34585 | Fixed | RHSA-2026:34043 |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | postgresql:13-8080020260709122729.63b34585 | Fixed | RHSA-2026:42555 |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | postgresql:15-8080020260615085052.63b34585 | Fixed | RHSA-2026:26561 |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | libpq-0:13.23-1.el8_8.1 | Fixed | RHSA-2026:35880 |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | postgresql:12-8080020260626093604.63b34585 | Fixed | RHSA-2026:34043 |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | postgresql:13-8080020260709122729.63b34585 | Fixed | RHSA-2026:42555 |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | postgresql:15-8080020260615085052.63b34585 | Fixed | RHSA-2026:26561 |
| Red Hat Enterprise Linux 9 | postgresql-0:13.23-3.el9_8 | Fixed | RHSA-2026:27741 |
| Red Hat Enterprise Linux 9 | postgresql:15-9080020260605124405.rhel9 | Fixed | RHSA-2026:28037 |
| Red Hat Enterprise Linux 9 | postgresql:16-9080020260605131007.rhel9 | Fixed | RHSA-2026:26203 |
| Red Hat Enterprise Linux 9 | postgresql:18-9080020260605125734.rhel9 | Fixed | RHSA-2026:26204 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | postgresql-0:13.23-1.el9_2.2 | Fixed | RHSA-2026:29953 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | postgresql:15-9020020260625101129.rhel9 | Fixed | RHSA-2026:33497 |
| Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | postgresql-0:13.23-1.el9_4.2 | Fixed | RHSA-2026:29904 |
| Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | postgresql:15-9040020260616071806.rhel9 | Fixed | RHSA-2026:33441 |
| Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | postgresql:16-9040020260612132455.rhel9 | Fixed | RHSA-2026:26524 |
| Red Hat Enterprise Linux 9.6 Extended Update Support | postgresql-0:13.23-1.el9_6.2 | Fixed | RHSA-2026:29212 |
| Red Hat Enterprise Linux 9.6 Extended Update Support | postgresql:15-9060020260622062902.rhel9 | Fixed | RHSA-2026:32983 |
| Red Hat Enterprise Linux 9.6 Extended Update Support | postgresql:16-9060020260612084605.rhel9 | Fixed | RHSA-2026:26525 |
| Red Hat Hardened Images | postgresql17-main-17.10-0.1.hum1 | Fixed | RHSA-2026:21182 |
| Red Hat Hardened Images | postgresql18-main-18.4-0.1.hum1 | Fixed | RHSA-2026:22878 |
| Red Hat Update Infrastructure 5 | rhui5/rhua-rhel9:1784795076 | Fixed | RHSA-2026:44481 |
| Red Hat Update Infrastructure 5 | rhui5/rhua-tp-rhel9:1787241260 | Fixed | RHSA-2026:58981 |
| Red Hat Enterprise Linux 6 | postgresql | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | postgresql | Not affected | n/a |
| Red Hat Enterprise Linux 8 | postgresql | Not affected | n/a |
| Red Hat Enterprise Linux 8 | postgresql-jdbc | Not affected | n/a |
| Self-service automation portal 2 | ansible-automation-platform/bootc-automation-portal-rhel9 | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This MODERATE symlink following vulnerability in PostgreSQL's pg_basebackup and pg_rewind allows an origin superuser to overwrite local files. Exploitation requires local access, high privileges (superuser), and specific intermediate actions before server restart. Impact is high to confidentiality, integrity, and availability if exploited. Affects versions before 18.4, 17.10, 16.14, 15.18, and 14.23.
References (6)
- https://access.redhat.com/security/cve/CVE-2026-6475 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2477439 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-30286 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-6475
- https://www.cve.org/CVERecord?id=CVE-2026-6475
- https://www.postgresql.org/support/security/CVE-2026-6475/ PatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-6475 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2477439 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-30286 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-6475 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-6475 | ||
| https://www.postgresql.org/support/security/CVE-2026-6475/ | PatchVendor Advisory |
Change history (0)
No recorded changes yet.