This is a security and bugfix release for 1.3. All users of 1.3.0 should upgrade.
Security
MobilityDB 1.3.1 fixes CVE-2026-102639 (GHSA-2c92-2w7c-pm3g), an out-of-bounds read in the Well-Known Binary (WKB) input of temporal, set and span values. A crafted binary value, for example a ttext whose text length is negative, passed the bounds check of the WKB reader, so any database user able to call a binary input function (ttextFromBinary, ttextFromHexWKB, the binary receive functions used by COPY ... BINARY and binary protocol parameters) could crash the PostgreSQL backend. In this release every read is compared with the bytes left in the buffer, lengths and counts are checked before they are used, the type code of the header is validated, and parsing stops at the first failed check.
Credit: Harsh Raj Singhania, who reported the issue through VulnCheck.
Other changes
- The distance operators
<->between two values of the same base type (integer,bigint,float,date,timestamptz) are removed, since thebtree_gistextension defines them and loading both extensions failed withoperator <-> already exists(#1520). Thebtree_gistextension provides these operators. - MobilityDB builds against PostgreSQL 19 (#1499).
Upgrading
Compile and install MobilityDB 1.3.1, then run in each database:
ALTER EXTENSION mobilitydb UPDATE TO '1.3.1';The upgrade drops the five base-type <-> operators and their set_distance functions; nothing else in the catalog changes.
What's Changed
- Fix for pg19 compile by @robe2 in #1521
- Remove the base-type distance operators that clash with btree_gist by @estebanzimanyi in #1539
- Bound every WKB read by the bytes left in the buffer by @estebanzimanyi in #2865
- Bump stable-1.3 to 1.3.1 with its upgrade file from 1.3.0 by @estebanzimanyi in #2869
Full Changelog: v1.3.0...v1.3.1