| From: | Noah Misch <noah(at)leadboat(dot)com> |
|---|---|
| To: | pgsql-committers(at)lists(dot)postgresql(dot)org |
| Subject: | pgsql: pg_createsubscriber: Obstruct SQL injection via subscription nam |
| Date: | 2026-05-11 12:19:37 |
| Message-ID: | E1wMPbl-0002Ub-1k@gemulon.postgresql.org |
| Views: | Whole Thread | Raw Message | Download mbox | Resend email |
| Thread: | |
| Lists: | pgsql-committers |
pg_createsubscriber: Obstruct SQL injection via subscription names.
drop_existing_subscription() neglected to escape the subscription
name when generating its query string. To fix, use
PQescapeIdentifier() to construct a properly escaped name, and use
it in the ALTER SUBSCRIPTION and DROP SUBSCRIPTION commands.
Reported-by: Yu Kunpeng <yu443940816(at)live(dot)com>
Author: Nathan Bossart <nathandbossart(at)gmail(dot)com>
Reviewed-by: Amit Kapila <amit(dot)kapila16(at)gmail(dot)com>
Security: CVE-2026-6476
Backpatch-through: 17
Branch
------
REL_18_STABLE
Details
-------
https://git.postgresql.org/pg/commitdiff/c2e44c370edc003367e94bde137c6d9cfab5919c
Author: Nathan Bossart <nathan(at)postgresql(dot)org>
Modified Files
--------------
src/bin/pg_basebackup/pg_createsubscriber.c | 11 ++++++++---
1 file changed, 8 insertions(+), 3 deletions(-)
| From | Date | Subject | |
|---|---|---|---|
| Next Message | Noah Misch | 2026-05-11 12:19:38 | pgsql: Harden our regex engine against integer overflow in size calcula |
| Previous Message | Noah Misch | 2026-05-11 12:19:36 | pgsql: Apply timingsafe_bcmp() in authentication paths |