pgsql: Return nulls honestly in aggregate "combine" functions.

From: Noah Misch <noah(at)leadboat(dot)com>
To: pgsql-committers(at)lists(dot)postgresql(dot)org
Subject: pgsql: Return nulls honestly in aggregate "combine" functions.
Date: 2026-08-10 13:41:22
Message-ID: E1wtQFm-00000000y4N-12EU@gemulon.postgresql.org
Views: Whole Thread | Raw Message | Download mbox | Resend email
Thread:
Lists: pgsql-committers

Return nulls honestly in aggregate "combine" functions.

numeric_combine() and several other state-combining functions for
aggregates cheated for the case of both inputs being NULL: they
returned a null pointer without bothering to mark it as a SQL NULL.
This was harmless in the expected usage where the result would be
passed to the same combine function or a related aggregate final
function. But it's bad news from a security standpoint, because
now that value can be passed to an internal-accepting function
even if said function is strict. While a previous patch prevented
such queries from being issued, it seems like good defense-in-depth
to expend the few additional lines of code needed to do this properly.
Comparable functions such as array_agg_combine() already do so.

Reported-by: Amy Burnett (OpenAI Codex Security)
Author: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
Backpatch-through: 14
Security: CVE-2026-14680

Branch
------
REL_19_STABLE

Details
-------
https://git.postgresql.org/pg/commitdiff/21d8cfb18f465be344dd83852792b88818c33634
Author: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>

Modified Files
--------------
src/backend/utils/adt/numeric.c | 32 ++++++++++++++++++++++++++++++++
src/backend/utils/adt/timestamp.c | 8 ++++++++
2 files changed, 40 insertions(+)

Browse pgsql-committers by date

  From Date Subject
Next Message Noah Misch 2026-08-10 13:41:23 pgsql: Check for USAGE privilege on the subtype in CREATE TYPE AS RANGE
Previous Message Noah Misch 2026-08-10 13:41:21 pgsql: Guard against overlength time zone abbreviations in to_char().