ALSA-2026:65899
Dashboard / Vulnerabilities / ALSA-2026:65899
Summary: Important: postgresql16-postgis security update
Details: PostGIS adds support for geographic objects to the PostgreSQL object-relational database. In effect, PostGIS "spatially enables" the PostgreSQL server, allowing it to be used as a backend spatial database for geographic information systems (GIS), much like ESRI's SDE or Oracle's Spatial extension. PostGIS follows the OpenGIS "Simple Features Specification for SQL" and has been certified as compliant with the "Types and Functions" profile. Security Fix(es): * postgis: PostGIS: Memory Disclosure and Denial of Service via Malformed FlatGeobuf Buffer (CVE-2026-73515) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
References: https://access.redhat.com/errata/RHSA-2026:65899, https://access.redhat.com/security/cve/CVE-2026-73515, https://bugzilla.redhat.com/2515434, https://errata.almalinux.org/10/ALSA-2026-65899.html
Affected packages
Package
Name: postgis
Purl: pkg:rpm/almalinux/postgis
Affected ranges
Type: ECOSYSTEM
Events:
