pgsql: pg_createsubscriber: Obstruct SQL injection via subscription nam

From: Noah Misch <noah(at)leadboat(dot)com>
To: pgsql-committers(at)lists(dot)postgresql(dot)org
Subject: pgsql: pg_createsubscriber: Obstruct SQL injection via subscription nam
Date: 2026-05-11 12:19:37
Message-ID: E1wMPbl-0002Ub-1k@gemulon.postgresql.org
Views: Whole Thread | Raw Message | Download mbox | Resend email
Thread:
Lists: pgsql-committers

pg_createsubscriber: Obstruct SQL injection via subscription names.

drop_existing_subscription() neglected to escape the subscription
name when generating its query string. To fix, use
PQescapeIdentifier() to construct a properly escaped name, and use
it in the ALTER SUBSCRIPTION and DROP SUBSCRIPTION commands.

Reported-by: Yu Kunpeng <yu443940816(at)live(dot)com>
Author: Nathan Bossart <nathandbossart(at)gmail(dot)com>
Reviewed-by: Amit Kapila <amit(dot)kapila16(at)gmail(dot)com>
Security: CVE-2026-6476
Backpatch-through: 17

Branch
------
REL_18_STABLE

Details
-------
https://git.postgresql.org/pg/commitdiff/c2e44c370edc003367e94bde137c6d9cfab5919c
Author: Nathan Bossart <nathan(at)postgresql(dot)org>

Modified Files
--------------
src/bin/pg_basebackup/pg_createsubscriber.c | 11 ++++++++---
1 file changed, 8 insertions(+), 3 deletions(-)

Browse pgsql-committers by date

  From Date Subject
Next Message Noah Misch 2026-05-11 12:19:38 pgsql: Harden our regex engine against integer overflow in size calcula
Previous Message Noah Misch 2026-05-11 12:19:36 pgsql: Apply timingsafe_bcmp() in authentication paths