PT-2026-102787 · Postgresql Global Development Group+1 · Postgresql+1
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
MobilityDB versions prior to 1.3.1
Description
An out-of-bounds read exists in the MEOS binary and library WKB deserialization logic. Unprivileged database users can cause a remote denial-of-service condition, crashing the PostgreSQL backend process and affecting all sessions on the instance. This occurs when a crafted WKB payload is supplied with a negative length field. Due to missing signed validation, the negative length wraps to a large unsigned
size t, bypassing an overflow-unsafe pointer arithmetic bounds check in the wkb parse state check() function. Consequently, the memcpy() function in text from wkb state() operates with a corrupted unbounded length.Recommendations
Update MobilityDB to version 1.3.1 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mobilitydb
Postgresql