PT-2026-102787 · Postgresql Global Development Group+1 · Postgresql+1

·

CVE-2026-102639

·

Published

2026-09-29

·

Updated

2026-09-29

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions MobilityDB versions prior to 1.3.1
Description An out-of-bounds read exists in the MEOS binary and library WKB deserialization logic. Unprivileged database users can cause a remote denial-of-service condition, crashing the PostgreSQL backend process and affecting all sessions on the instance. This occurs when a crafted WKB payload is supplied with a negative length field. Due to missing signed validation, the negative length wraps to a large unsigned size t, bypassing an overflow-unsafe pointer arithmetic bounds check in the wkb parse state check() function. Consequently, the memcpy() function in text from wkb state() operates with a corrupted unbounded length.
Recommendations Update MobilityDB to version 1.3.1 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-102639
GHSA-2C92-2W7C-PM3G

Affected Products

Mobilitydb
Postgresql