Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-73515

Опубликовано: 13 авг. 2026
Источник: redhat
CVSS3: 8.1

Описание

PostGIS before 3.7.0beta2 contains an out-of-bounds read vulnerability that allows attackers to cause memory disclosure or a server crash by supplying a malformed FlatGeobuf buffer. The FlatGeobuf property metadata decoder verifies that a string length field is present but fails to verify that the subsequent string body is contained within the supplied buffer before materializing it into a SQL-visible value, enabling memory disclosure or denial of service.

A flaw was found in PostGIS. This out-of-bounds read vulnerability allows a remote attacker to cause memory disclosure or a server crash. This occurs when a malformed FlatGeobuf buffer is supplied, as the FlatGeobuf property metadata decoder fails to verify that the string body is contained within the buffer. This can lead to sensitive information disclosure or a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10postgresql16-postgisAffected
Red Hat Enterprise Linux 10postgresql18-postgisAffected
Red Hat Enterprise Linux 9postgresql:16/postgisAffected
Red Hat Enterprise Linux 9postgresql:18/postgisAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2515434postgis: PostGIS: Memory Disclosure and Denial of Service via Malformed FlatGeobuf Buffer

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
15 дней назад

PostGIS before 3.7.0beta2 contains an out-of-bounds read vulnerability that allows attackers to cause memory disclosure or a server crash by supplying a malformed FlatGeobuf buffer. The FlatGeobuf property metadata decoder verifies that a string length field is present but fails to verify that the subsequent string body is contained within the supplied buffer before materializing it into a SQL-visible value, enabling memory disclosure or denial of service.

CVSS3: 8.1
nvd
15 дней назад

PostGIS before 3.7.0beta2 contains an out-of-bounds read vulnerability that allows attackers to cause memory disclosure or a server crash by supplying a malformed FlatGeobuf buffer. The FlatGeobuf property metadata decoder verifies that a string length field is present but fails to verify that the subsequent string body is contained within the supplied buffer before materializing it into a SQL-visible value, enabling memory disclosure or denial of service.

CVSS3: 8.1
debian
15 дней назад

PostGIS before 3.7.0beta2 contains an out-of-bounds read vulnerability ...

CVSS3: 8.1
github
15 дней назад

PostGIS before 3.7.0beta2 contains an out-of-bounds read vulnerability that allows attackers to cause memory disclosure or a server crash by supplying a malformed FlatGeobuf buffer. The FlatGeobuf property metadata decoder verifies that a string length field is present but fails to verify that the subsequent string body is contained within the supplied buffer before materializing it into a SQL-visible value, enabling memory disclosure or denial of service.

8.1 High

CVSS3