| From: | Noah Misch <noah(at)leadboat(dot)com> |
|---|---|
| To: | pgsql-committers(at)lists(dot)postgresql(dot)org |
| Subject: | pgsql: Return nulls honestly in aggregate "combine" functions. |
| Date: | 2026-08-10 13:41:22 |
| Message-ID: | E1wtQFm-00000000y4N-12EU@gemulon.postgresql.org |
| Views: | Whole Thread | Raw Message | Download mbox | Resend email |
| Thread: | |
| Lists: | pgsql-committers |
Return nulls honestly in aggregate "combine" functions.
numeric_combine() and several other state-combining functions for
aggregates cheated for the case of both inputs being NULL: they
returned a null pointer without bothering to mark it as a SQL NULL.
This was harmless in the expected usage where the result would be
passed to the same combine function or a related aggregate final
function. But it's bad news from a security standpoint, because
now that value can be passed to an internal-accepting function
even if said function is strict. While a previous patch prevented
such queries from being issued, it seems like good defense-in-depth
to expend the few additional lines of code needed to do this properly.
Comparable functions such as array_agg_combine() already do so.
Reported-by: Amy Burnett (OpenAI Codex Security)
Author: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
Backpatch-through: 14
Security: CVE-2026-14680
Branch
------
REL_19_STABLE
Details
-------
https://git.postgresql.org/pg/commitdiff/21d8cfb18f465be344dd83852792b88818c33634
Author: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
Modified Files
--------------
src/backend/utils/adt/numeric.c | 32 ++++++++++++++++++++++++++++++++
src/backend/utils/adt/timestamp.c | 8 ++++++++
2 files changed, 40 insertions(+)
| From | Date | Subject | |
|---|---|---|---|
| Next Message | Noah Misch | 2026-08-10 13:41:23 | pgsql: Check for USAGE privilege on the subtype in CREATE TYPE AS RANGE |
| Previous Message | Noah Misch | 2026-08-10 13:41:21 | pgsql: Guard against overlength time zone abbreviations in to_char(). |