| From: | Noah Misch <noah(at)leadboat(dot)com> |
|---|---|
| To: | pgsql-committers(at)lists(dot)postgresql(dot)org |
| Subject: | pgsql: Use palloc_array() in pltcl and plperl to avoid overflow |
| Date: | 2026-08-10 13:41:22 |
| Message-ID: | E1wtQFm-00000000y4k-24E2@gemulon.postgresql.org |
| Views: | Whole Thread | Raw Message | Download mbox | Resend email |
| Thread: | |
| Lists: | pgsql-committers |
Use palloc_array() in pltcl and plperl to avoid overflow
Some of these could overflow on 32-bit systems with the right input.
Convert all cases where we called palloc() with multiplication to fix
them. Not all of them were bugs, but it's better to be safe than
sorry.
Reported-by: Tulya Project, Team Dhiutsa, Bitecope Technologies Private Ltd
Backpatch-through: 14
Security: CVE-2026-14677
Branch
------
REL_19_STABLE
Details
-------
https://git.postgresql.org/pg/commitdiff/a1c1727cb400b8ae61a13844d7e22ef38e7da79b
Author: Heikki Linnakangas <heikki(dot)linnakangas(at)iki(dot)fi>
Modified Files
--------------
src/pl/plperl/SPI.xs | 6 +++---
src/pl/plperl/plperl.c | 26 +++++++++++++-------------
src/pl/tcl/pltcl.c | 16 ++++++++--------
3 files changed, 24 insertions(+), 24 deletions(-)
| From | Date | Subject | |
|---|---|---|---|
| Next Message | Noah Misch | 2026-08-10 13:41:23 | pgsql: Check for USAGE privilege on the subtype in CREATE TYPE AS RANGE |
| Previous Message | Noah Misch | 2026-08-10 13:41:21 | pgsql: Guard against overlength time zone abbreviations in to_char(). |