Linuxsecurity Critical Memory Disclosure Vulnerabilities in PostgreSQL PostGIS
Article Content
- •CVE-2026-73515 affects PostgreSQL PostGIS versions 16, 17, and 18.
- •CISA confirms active exploitation of these vulnerabilities in the wild.
- •Immediate patching is recommended for affected systems to prevent memory disclosure and denial of service.
Multiple memory disclosure vulnerabilities have been identified in PostgreSQL PostGIS versions 16, 17, and 18, affecting Fedora 43 and 44. These vulnerabilities, tracked as CVE-2026-73515, allow for potential denial of service and memory disclosure via malformed FlatGeobuf buffers. CISA has confirmed active exploitation of these vulnerabilities in the wild, prompting urgent advisories for system administrators to apply patches. The vulnerabilities affect systems using PostgreSQL with PostGIS extensions, which are widely used in geographic information systems. The issues were first published on August 13, 2026, and have been backported in recent updates. Administrators are advised to upgrade their systems immediately to mitigate the risks associated with these vulnerabilities.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (6)
Following this threat?
Track Fedora and CVE-2026-73515 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Vulnerabilities in Oracle Linux 10 Affecting Admin Control Oracle has issued advisories for two critical vulnerabilities in Linux 10 affecting PostgreSQL and perl-DBI. CVE-2026-73515 allows attackers to gain admin control through chained flaws in PostGIS, while CVE-2026-19546 addresses an incomplete fix for CVE-2026-14380 in DBI::Profile. Both vulnerabilities were published…
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…