<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T20:37:55.582643+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:65899</id>
    <title>ALSA-2026:65899 — Important: postgresql16-postgis security update</title>
    <updated>2026-10-03T20:37:55.855081+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: postgis, AlmaLinux:10: postgis-client, AlmaLinux:10: postgis-docs, AlmaLinux:10: postgis-upgrade, AlmaLinux:10: postgis-utils</p>
<p>PostGIS adds support for geographic objects to the PostgreSQL object-relational database. In effect, PostGIS "spatially enables" the PostgreSQL server, allowing it to be used as a backend spatial database for geographic information systems (GIS), much like ESRI's SDE or Oracle's Spatial extension. PostGIS follows the OpenGIS "Simple Features Specification for SQL" and has been certified as compliant with the "Types and Functions" profile.</p>
<p>Security Fix(es):</p>
<p>* postgis: PostGIS: Memory Disclosure and Denial of Service via Malformed FlatGeobuf Buffer (CVE-2026-73515)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:65899"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-postgis-2026-73515</id>
    <title>BIT-postgis-2026-73515 — PostGIS &lt; 3.7.0 Out-of-Bounds Read via FlatGeobuf Buffer</title>
    <updated>2026-10-03T20:37:55.855162+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: postgis</p>
<p>PostGIS before 3.7.0 contains an out-of-bounds read vulnerability that allows attackers to cause memory disclosure or a server crash by supplying a malformed FlatGeobuf buffer. The FlatGeobuf property metadata decoder verifies that a string length field is present but fails to verify that the subsequent string body is contained within the supplied buffer before materializing it into a SQL-visible value, enabling memory disclosure or denial of service.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-postgis-2026-73515"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-352773</id>
    <title>EUVD-2026-352773</title>
    <updated>2026-10-03T20:37:55.855187+00:00</updated>
    <content>EUVD-2026-352773</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-352773"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-73515</id>
    <title>fkie_cve-2026-73515</title>
    <updated>2026-10-03T20:37:55.855230+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>PostGIS before 3.7.0beta2 contains an out-of-bounds read vulnerability that allows attackers to cause memory disclosure or a server crash by supplying a malformed FlatGeobuf buffer. The FlatGeobuf property metadata decoder verifies that a string length field is present but fails to verify that the subsequent string body is contained within the supplied buffer before materializing it into a SQL-visible value, enabling memory disclosure or denial of service.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-73515"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-qv7r-wgc7-6mc6</id>
    <title>GHSA-qv7r-wgc7-6mc6</title>
    <updated>2026-10-03T20:37:55.855263+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>PostGIS before 3.7.0beta2 contains an out-of-bounds read vulnerability that allows attackers to cause memory disclosure or a server crash by supplying a malformed FlatGeobuf buffer. The FlatGeobuf property metadata decoder verifies that a string length field is present but fails to verify that the subsequent string body is contained within the supplied buffer before materializing it into a SQL-visible value, enabling memory disclosure or denial of service.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-qv7r-wgc7-6mc6"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:65899</id>
    <title>RHSA-2026:65899 — Red Hat Security Advisory: postgresql16-postgis security update</title>
    <updated>2026-10-03T20:37:55.855280+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>postgis: PostGIS: Memory Disclosure and Denial of Service via Malformed FlatGeobuf Buffer</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:65899"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:65899</id>
    <title>RLSA-2026:65899 — Important: postgresql16-postgis security update</title>
    <updated>2026-10-03T20:37:55.855298+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: postgresql16-postgis</p>
<p>PostGIS adds support for geographic objects to the PostgreSQL object-relational database. In effect, PostGIS "spatially enables" the PostgreSQL server, allowing it to be used as a backend spatial database for geographic information systems (GIS), much like ESRI's SDE or Oracle's Spatial extension. PostGIS follows the OpenGIS "Simple Features Specification for SQL" and has been certified as compliant with the "Types and Functions" profile.</p>
<p>Security Fix(es):</p>
<p>* postgis: PostGIS: Memory Disclosure and Denial of Service via Malformed FlatGeobuf Buffer (CVE-2026-73515)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:65899"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-73515</id>
    <title>UBUNTU-CVE-2026-73515</title>
    <updated>2026-10-03T20:37:55.855323+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: postgis, Ubuntu:18.04:LTS: postgis, Ubuntu:20.04:LTS: postgis, Ubuntu:22.04:LTS: postgis, Ubuntu:24.04:LTS: postgis, Ubuntu:26.04:LTS: postgis</p>
<p>PostGIS before 3.7.0beta2 contains an out-of-bounds read vulnerability that allows attackers to cause memory disclosure or a server crash by supplying a malformed FlatGeobuf buffer. The FlatGeobuf property metadata decoder verifies that a string length field is present but fails to verify that the subsequent string body is contained within the supplied buffer before materializing it into a SQL-visible value, enabling memory disclosure or denial of service.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-73515"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3306</id>
    <title>WID-SEC-W-2026-3306 — Red Hat Enterprise Linux (postgis, virtuoso-opensource): Mehrere Schwachstellen</title>
    <updated>2026-10-03T20:37:55.855349+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um einen Denial of Service Angriff durchzuführen oder vertrauliche Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3306"/>
  </entry>
</feed>
