Oracle Linux 8:postgresql:15 (ELSA-2026-69923)

high Nessus Plugin ID 349763

概要

遠端 Oracle Linux 主機缺少一個或多個安全性更新。

說明

遠端 Oracle Linux 8 主機中安裝的套件受到 ELSA-2026-69923 公告中提及的多個弱點影響。

pgaudit [1.7.0-1]
- 更新至 1.7.0
- 支援 postgresql 15
- 相關項目:#2128241

[1.5.0-1]
- 更新至版本 1.5.0 相關:#1855776

[1.4.0-4]
- 針對 libpq-12.1-3 進行重建的 Bump 版本

[1.4.0-3]
- BuildRequires libpq-devel

[1.4.0-2]
- BuildRequires postgresql-server-devel

[1.4.0-1]
- 更新至 1.4.0

[1.3.1-1]
- 1.3.1 的更新並套用 pgsql v12 相容性的修補程式

[1.2.0-4]
- SCLize SPEC

[1.2.0-3]
- 已針對 https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild 重新建構

[1.2.0-2]
- 已針對 https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild 重新建構

pg_repack [1.4.8-1]
- 更新至 1.4.8 版
- 支援 postgresql 15
- 相關項目:#2128241

[1.4.6-4]
- 針對 IMA sigs、glibc 2.34、aarch64 旗標重新建構 相關:rhbz#1991688

[1.4.6-3]
- 針對 openssl 3.0 的 RHEL 9 BETA 重新建構,相關:rhbz#1971065

[1.4.6-2]
- 根據 postgresql 伺服器執行的動作構建 jit 相關:#1933048

[1.4.6-1]
- 重定基底至上游版本 1.4.6

[1.4.5-3]
- 已針對 https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild 重新建構

[1.4.5-2]
- 已針對 https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild 重新建構

[1.4.5-1]
- 初始封裝

postgres-decoderbufs [1.9.7-1.Final]
- postgresql 15 資料流的初始匯入
- 相關項目:#2128241

[1.4.0-4.Final]
- 針對 IMA sigs、glibc 2.34、aarch64 旗標重新建構 相關:rhbz#1991688

[1.4.0-3.Final]
- 根據 postgresql 伺服器執行的動作構建 jit 相關:#1933048

[1.4.0-2.Final]
- 已於 2021 年 4 月 15 日針對 RHEL 9 BETA 重新建構。相關:rhbz#1947937

[1.4.0-1.Final]
- 更新至新版本 1.4.0

[1.1.0-0.6.Final]
- 已針對 https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild 重新建構

[1.1.0-0.5.Final]
- 針對 protobuf 重新建構 3.14

[1.1.0-0.4.Final]
- 針對 protobuf 重新建構 3.13

[1.1.0-0.3.Final]
- 已針對 https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild 重新建構

[1.1.0-0.2.Final]
- 針對 protobuf 重新建構 3.12

postgresql [15.19-1]
- 更新至 15.19
- 解決: RHEL-250764

Tenable 已直接從 Oracle Linux 安全公告擷取前置描述區塊。

請注意,Nessus 並未測試這些問題,而是僅依據應用程式自我報告的版本號碼作出判斷。

解決方案

更新受影響的套件。

另請參閱

https://linux.oracle.com/errata/ELSA-2026-69923.html

Plugin 詳細資訊

嚴重性: High

ID: 349763

檔案名稱: oraclelinux_ELSA-2026-69923.nasl

版本: 1.1

類型: Local

代理程式: unix

已發布: 2026/9/24

已更新: 2026/9/24

支援的感應器: Continuous Assessment, Frictionless Assessment Agent, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

風險資訊

VPR

風險因素: High

分數: 7.9

百分位數: 99.35

CVSS v2

風險因素: Critical

基本分數: 10

時間性分數: 7.8

媒介: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS 評分資料來源: CVE-2026-18408

CVSS v3

風險因素: High

基本分數: 8.8

時間性分數: 7.9

媒介: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

時間媒介: CVSS:3.0/E:P/RL:O/RC:C

CVSS 評分資料來源: CVE-2026-19385

弱點資訊

CPE: cpe:/o:oracle:linux:8, p-cpe:/a:oracle:linux:pg_repack, p-cpe:/a:oracle:linux:pgaudit, p-cpe:/a:oracle:linux:postgres-decoderbufs, p-cpe:/a:oracle:linux:postgresql-contrib, p-cpe:/a:oracle:linux:postgresql-docs, p-cpe:/a:oracle:linux:postgresql-plperl, p-cpe:/a:oracle:linux:postgresql-plpython3, p-cpe:/a:oracle:linux:postgresql-pltcl, p-cpe:/a:oracle:linux:postgresql-private-devel, p-cpe:/a:oracle:linux:postgresql-private-libs, p-cpe:/a:oracle:linux:postgresql-server-devel, p-cpe:/a:oracle:linux:postgresql-server, p-cpe:/a:oracle:linux:postgresql-static, p-cpe:/a:oracle:linux:postgresql-test-rpm-macros, p-cpe:/a:oracle:linux:postgresql-test, p-cpe:/a:oracle:linux:postgresql-upgrade-devel, p-cpe:/a:oracle:linux:postgresql-upgrade, p-cpe:/a:oracle:linux:postgresql

必要的 KB 項目: Host/OracleLinux, Host/RedHat/release, Host/RedHat/rpm-list, Host/local_checks_enabled

可被惡意程式利用: true

可輕鬆利用: Exploits are available

修補程式發佈日期: 2026/9/23

弱點發布日期: 2026/8/13

參考資訊

CVE: CVE-2026-14662, CVE-2026-14664, CVE-2026-14668, CVE-2026-14669, CVE-2026-14670, CVE-2026-14671, CVE-2026-14677, CVE-2026-14679, CVE-2026-14680, CVE-2026-15741, CVE-2026-15742, CVE-2026-16239, CVE-2026-18408, CVE-2026-19385, CVE-2026-6464, CVE-2026-6471

IAVB: 2026-B-0238