RLSA-2026:65899

Source
https://errata.rockylinux.org/RLSA-2026:65899
Import Source
https://storage.googleapis.com/resf-osv-data/RLSA-2026:65899.json
JSON Data
https://api.osv.dev/v1/vulns/RLSA-2026:65899
Upstream
Published
2026-09-10T00:09:11Z
Modified
2026-09-10T00:30:02Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H CVSS Calculator
Summary
Important: postgresql16-postgis security update
Details

PostGIS adds support for geographic objects to the PostgreSQL object-relational database. In effect, PostGIS "spatially enables" the PostgreSQL server, allowing it to be used as a backend spatial database for geographic information systems (GIS), much like ESRI's SDE or Oracle's Spatial extension. PostGIS follows the OpenGIS "Simple Features Specification for SQL" and has been certified as compliant with the "Types and Functions" profile.

Security Fix(es):

  • postgis: PostGIS: Memory Disclosure and Denial of Service via Malformed FlatGeobuf Buffer (CVE-2026-73515)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Database specific
{
    "license": "CC-BY-4.0",
    "license_url": "https://creativecommons.org/licenses/by/4.0/",
    "source_advisory": "RHSA-2026:65899"
}
References
Credits
    • Rocky Enterprise Software Foundation
    • Red Hat

Affected packages

Rocky Linux:10 / postgresql16-postgis

Package

Name
postgresql16-postgis
Purl
pkg:rpm/rocky-linux/postgresql16-postgis?distro=rocky-linux-10&epoch=0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0:3.5.3-4.el10_2.1
Database specific
Show details
{
    "yum_repository": "AppStream"
}

Database specific

source
"https://storage.googleapis.com/resf-osv-data/RLSA-2026:65899.json"