CVE-2026-90775

NameCVE-2026-90775
DescriptionPostGIS address_standardizer through 3.7.0 fails to validate the Weight parameter from caller-supplied rules tables before using it as an array index. Attackers can craft malicious rule rows with out-of-range Weight values to trigger out-of-bounds reads in the load_value array, causing the PostgreSQL backend process to crash and terminate all cluster sessions.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1147616

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
address-standardizer (PTS)forky, sid3.7.0-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
address-standardizersource(unstable)(unfixed)1147616

Notes

https://github.com/postgis/address_standardizer/pull/6
Fixed by: https://github.com/postgis/address_standardizer/commit/a5cb4b1360a040973092f13b1af97a718e7e104a

Search for package or bug name: Reporting problems