Skip to content

MobilityDB v1.3.1

Latest

Choose a tag to compare

@estebanzimanyi estebanzimanyi released this 29 Sep 16:31

This is a security and bugfix release for 1.3. All users of 1.3.0 should upgrade.

Security

MobilityDB 1.3.1 fixes CVE-2026-102639 (GHSA-2c92-2w7c-pm3g), an out-of-bounds read in the Well-Known Binary (WKB) input of temporal, set and span values. A crafted binary value, for example a ttext whose text length is negative, passed the bounds check of the WKB reader, so any database user able to call a binary input function (ttextFromBinary, ttextFromHexWKB, the binary receive functions used by COPY ... BINARY and binary protocol parameters) could crash the PostgreSQL backend. In this release every read is compared with the bytes left in the buffer, lengths and counts are checked before they are used, the type code of the header is validated, and parsing stops at the first failed check.

Credit: Harsh Raj Singhania, who reported the issue through VulnCheck.

Other changes

  • The distance operators <-> between two values of the same base type (integer, bigint, float, date, timestamptz) are removed, since the btree_gist extension defines them and loading both extensions failed with operator <-> already exists (#1520). The btree_gist extension provides these operators.
  • MobilityDB builds against PostgreSQL 19 (#1499).

Upgrading

Compile and install MobilityDB 1.3.1, then run in each database:

ALTER EXTENSION mobilitydb UPDATE TO '1.3.1';

The upgrade drops the five base-type <-> operators and their set_distance functions; nothing else in the catalog changes.

What's Changed

Full Changelog: v1.3.0...v1.3.1