{"id":"RLSA-2026:65899","summary":"Important: postgresql16-postgis security update","details":"PostGIS adds support for geographic objects to the PostgreSQL object-relational database. In effect, PostGIS \"spatially enables\" the PostgreSQL server, allowing it to be used as a backend spatial database for geographic information systems (GIS), much like ESRI's SDE or Oracle's Spatial extension. PostGIS follows the OpenGIS \"Simple Features Specification for SQL\" and has been certified as compliant with the \"Types and Functions\" profile.\n\nSecurity Fix(es):\n\n* postgis: PostGIS: Memory Disclosure and Denial of Service via Malformed FlatGeobuf Buffer (CVE-2026-73515)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.","modified":"2026-09-10T00:30:02.750739527Z","published":"2026-09-10T00:09:11.134895Z","upstream":["CVE-2026-73515"],"database_specific":{"license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","source_advisory":"RHSA-2026:65899"},"references":[{"type":"ADVISORY","url":"https://errata.rockylinux.org/RLSA-2026:65899"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2515434"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:65899"}],"affected":[{"package":{"name":"postgresql16-postgis","ecosystem":"Rocky Linux:10","purl":"pkg:rpm/rocky-linux/postgresql16-postgis?distro=rocky-linux-10&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:3.5.3-4.el10_2.1"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2026:65899.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"}],"credits":[{"name":"Rocky Enterprise Software Foundation"},{"name":"Red Hat"}]}