[PostGIS] #6118: Out-of-bounds read in geometry_type_from_string() on an empty type modifier

PostGIS trac at osgeo.org
Mon Sep 7 05:23:26 PDT 2026


#6118: Out-of-bounds read in geometry_type_from_string() on an empty type modifier
-----------------------+-----------------------------
  Reporter:  eivkov    |      Owner:  pramsey
      Type:  defect    |     Status:  new
  Priority:  critical  |  Milestone:  PostGIS 3.6.5
 Component:  postgis   |    Version:  master
Resolution:            |   Keywords:  buffer overflow
-----------------------+-----------------------------
Comment (by Darafei Praliaskouski <me@…>):

 In [changeset:"95abfeebc9c30f325bb6ad8b07e13eb774696ce2/git"
 95abfeeb/git]:
 {{{#!CommitTicketReference repository="git"
 revision="95abfeebc9c30f325bb6ad8b07e13eb774696ce2"
 Preserve empty typmod outputs and add SQL regression coverage

 Keep the two original contributor commits unchanged and integrate current
 master. Initialize output fields before rejecting an empty modifier,
 assert the failure contract, and add SQL regression coverage, release
 notes and author alias normalization.

 References #6118
 }}}
-- 
Ticket URL: <https://trac.osgeo.org/postgis/ticket/6118#comment:2>
PostGIS <http://trac.osgeo.org/postgis/>
The PostGIS Trac is used for bug, enhancement & task tracking, a user and developer wiki, and a view into the subversion code repository of PostGIS project.


More information about the postgis-tickets mailing list