Source: address-standardizer Version: 3.7.0-1 Severity: important Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerability was published for address-standardizer. CVE-2026-90775[0]: | PostGIS address_standardizer through 3.7.0 fails to validate the | Weight parameter from caller-supplied rules tables before using it | as an array index. Attackers can craft malicious rule rows with out- | of-range Weight values to trigger out-of-bounds reads in the | load_value array, causing the PostgreSQL backend process to crash | and terminate all cluster sessions. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-90775 https://www.cve.org/CVERecord?id=CVE-2026-90775 [1] https://github.com/postgis/address_standardizer/pull/6 [2] https://github.com/postgis/address_standardizer/commit/a5cb4b1360a040973092f13b1af97a718e7e104a Regards, Salvatore

