سایبرنامه
medium

CVE-2026-90775

PostGIS address_standardizer through 3.7.0 fails to validate the Weight parameter from caller-supplied rules tables before using it as an array index. Attackers can craft malicious rule rows with out-of-range Weight values to trigger out-of-bounds reads in the load_value array, causing the PostgreSQL backend process to crash and terminate all cluster sessions.

امتیاز CVSS

6.5

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

تحلیلِ بردارِ CVSS

CWE
CWE-125
تاریخ انتشار
۲۲ شهریور ۱۴۰۵

منابع