pgsql: Use palloc_array() in pltcl and plperl to avoid overflow

From: Noah Misch <noah(at)leadboat(dot)com>
To: pgsql-committers(at)lists(dot)postgresql(dot)org
Subject: pgsql: Use palloc_array() in pltcl and plperl to avoid overflow
Date: 2026-08-10 13:41:24
Message-ID: E1wtQFo-00000000y8m-2bkl@gemulon.postgresql.org
Views: Whole Thread | Raw Message | Download mbox | Resend email
Thread:
Lists: pgsql-committers

Use palloc_array() in pltcl and plperl to avoid overflow

Some of these could overflow on 32-bit systems with the right input.
Convert all cases where we called palloc() with multiplication to fix
them. Not all of them were bugs, but it's better to be safe than
sorry.

Reported-by: Tulya Project, Team Dhiutsa, Bitecope Technologies Private Ltd
Backpatch-through: 14
Security: CVE-2026-14677

Branch
------
REL_18_STABLE

Details
-------
https://git.postgresql.org/pg/commitdiff/028ee716a7902bd2a68843a5d317a6821a0500e2
Author: Heikki Linnakangas <heikki(dot)linnakangas(at)iki(dot)fi>

Modified Files
--------------
src/pl/plperl/SPI.xs | 6 +++---
src/pl/plperl/plperl.c | 38 +++++++++++++++++++-------------------
src/pl/tcl/pltcl.c | 20 ++++++++++----------
3 files changed, 32 insertions(+), 32 deletions(-)

Browse pgsql-committers by date

  From Date Subject
Next Message Noah Misch 2026-08-10 13:41:25 pgsql: Check for USAGE privilege on the composite type in ALTER TABLE O
Previous Message Noah Misch 2026-08-10 13:41:23 pgsql: Save/restore more lexer state when skipping text due to \if.