STIGQter STIGQter: STIG Summary: Crunchy Data Postgres 16 Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 01 Jul 2026:

Security-relevant software updates to PostgreSQL must be installed within the time period directed by an authoritative source (e.g., IAVM, CTOs, DTMs, and STIGs).

DISA Rule

SV-261936r1137667_rule

Vulnerability Number

V-261936

Group Title

SRG-APP-000456-DB-000390

Rule Version

CD16-00-009200

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Institute and adhere to policies and procedures to ensure that patches are consistently applied to PostgreSQL within the time allowed.

Check Contents

If new packages are available for PostgreSQL, they can be reviewed in the package manager appropriate for the server operating system:

To list the version of installed PostgreSQL using psql:

$ sudo su - postgres
$ psql --version

To list the current version of software for RPM:

$ rpm -qa | grep postgres

To list the current version of software for APT:

$ apt-cache policy postgres

All versions of PostgreSQL are listed here: http://www.postgresql.org/support/versioning/.

All security-relevant software updates for PostgreSQL are listed here: http://www.postgresql.org/support/security/.

If PostgreSQL is not at the latest version, this is a finding.

If PostgreSQL is not at the latest version and the evaluated version has CVEs (IAVAs), then this is a CAT I finding.

Vulnerability Number

V-261936

Documentable

False

Rule Version

CD16-00-009200

Severity Override Guidance

If new packages are available for PostgreSQL, they can be reviewed in the package manager appropriate for the server operating system:

To list the version of installed PostgreSQL using psql:

$ sudo su - postgres
$ psql --version

To list the current version of software for RPM:

$ rpm -qa | grep postgres

To list the current version of software for APT:

$ apt-cache policy postgres

All versions of PostgreSQL are listed here: http://www.postgresql.org/support/versioning/.

All security-relevant software updates for PostgreSQL are listed here: http://www.postgresql.org/support/security/.

If PostgreSQL is not at the latest version, this is a finding.

If PostgreSQL is not at the latest version and the evaluated version has CVEs (IAVAs), then this is a CAT I finding.

Check Content Reference

M

Target Key

5598