CVE-2025-61021
Red Hat Enterprise Linux (postgis, virtuoso-opensource): Mehrere Schwachstellen
highEPSS 0.5%
Description
Metrics
Severity
high
95.15
no public PoC known
7.5
Published
2026-09-10 12:47 UTC
—
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- New CVE Received2026-06-23 17:16 UTC· cve@mitre.org
- Affected: n/a
- Description: An issue in the sqlo_natural_join_cond component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
- Reference: https://github.com/openlink/virtuoso-opensource/issues/1223
Affected products
Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.
Red Hat
Enterprise Linux10
Red Hat
Enterprise Linux7 Extended Lifecycle Support
References & sources
- https://mehmetince.net/part-1-6-systemic-risks-in-the-managed-postgresql-industry-extension-risks-are-real-exploiting-postgis-memory-corruption-bug-at-neondb-supabase-and-many-more/technical-descriptionexploit
- https://gitea.osgeo.org/postgis/postgis/raw/tag/3.7.0beta2/NEWSrelease-notes
- https://www.vulncheck.com/advisories/postgis-0beta2-out-of-bounds-read-via-flatgeobuf-bufferthird-party-advisory
- https://github.com/openlink/virtuoso-opensource/issues/1223
Linked CVEs
- CVE-2026-73515
PostGIS before 3.7.0beta2 contains an out-of-bounds read vulnerability that allows attackers to cause memory disclosure or a server crash…
highCVSSv3 8.1 - CVE-2025-61021
An issue in the sqlo_natural_join_cond component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (D…
highCVSSv3 7.5
IDCVE-2025-61021