Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 30 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mobilitydb
Mobilitydb mobilitydb |
|
| Vendors & Products |
Mobilitydb
Mobilitydb mobilitydb |
Tue, 29 Sep 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MobilityDB version 1.3.0 and earlier contains an out-of-bounds read vulnerability in the MEOS binary and library WKB deserialization logic that allows unprivileged database users to crash the PostgreSQL backend process by supplying a crafted WKB payload with a negative length field. The negative length value wraps to a large unsigned size_t due to missing signed validation, bypasses an overflow-unsafe pointer arithmetic bounds check in wkb_parse_state_check(), and causes memcpy() in text_from_wkb_state() to operate with a corrupted unbounded length, resulting in a remote denial-of-service condition affecting all sessions on the PostgreSQL instance. | |
| Title | MobilityDB through 1.3.0 Out-of-bounds Read DoS via WKB Deserialization | |
| Weaknesses | CWE-195 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-29T17:57:36.883Z
Reserved: 2026-09-29T15:52:45.482Z
Link: CVE-2026-102639
No data.
Status : Deferred
Published: 2026-09-29T18:17:09.173
Modified: 2026-09-30T17:32:07.107
Link: CVE-2026-102639
No data.
OpenCVE Enrichment
Updated: 2026-09-30T20:39:39Z