CVE-2026-102639: MobilityDB through 1.3.0 Out-of-bounds Read DoS via WKB Deserialization
MobilityDB version 1.3.0 and earlier contains an out-of-bounds read vulnerability in the MEOS binary and library WKB deserialization logic that allows unprivileged database users to crash the PostgreSQL backend process by supplying a crafted WKB payload with a negative length field. The negative length value wraps to a large unsigned sizet due to missing signed validation, bypasses an overflow-unsafe pointer arithmetic bounds check in wkbparsestatecheck(), and causes memcpy() in textfromwkbstate() to operate with a corrupted unbounded length, resulting in a remote denial-of-service condition affecting all sessions on the PostgreSQL instance.
Affected Software
Event History
Frequently Asked Questions
Who can trigger the denial of service?
An unprivileged database user can trigger it by supplying a crafted WKB payload. Exploitation does not require user interaction.
What systems are affected?
MobilityDB versions 1.3.0 and earlier are affected. A successful exploit can crash the PostgreSQL backend process and disrupt all sessions on that PostgreSQL instance.
What should be prioritized for remediation?
Upgrade to a release newer than 1.3.0. The available references include MobilityDB releases 1.3.1 and 1.2.2.