pgsql: Be more wary about constant's datatype in scalarineqsel().

From: Noah Misch <noah(at)leadboat(dot)com>
To: pgsql-committers(at)lists(dot)postgresql(dot)org
Subject: pgsql: Be more wary about constant's datatype in scalarineqsel().
Date: 2026-08-10 13:41:27
Message-ID: E1wtQFr-00000000yC6-0I8L@gemulon.postgresql.org
Views: Whole Thread | Raw Message | Download mbox | Resend email
Thread:
Lists: pgsql-committers

Be more wary about constant's datatype in scalarineqsel().

The special case here for estimating conditions involving a ctid
column failed to check that the RHS constant is of type tid.
While that'd always be true for the built-in operators that
reference this selectivity estimator, a maliciously constructed
operator could provide a user-controlled Datum value that would
get interpreted as an ItemPointer pointer. That at least risks
SIGSEGV, and perhaps with a bit of sweat it could be used for
server memory disclosure.

Reported-by: Hcamael <baiyjrh(at)gmail(dot)com>
Author: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
Reviewed-by: Noah Misch <noah(at)leadboat(dot)com>
Backpatch-through: 14
Security: CVE-2026-14668

Branch
------
REL_17_STABLE

Details
-------
https://git.postgresql.org/pg/commitdiff/0ebf896f44d2a930c7e3722621e319a3d923c830
Author: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>

Modified Files
--------------
src/backend/utils/adt/selfuncs.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)

Browse pgsql-committers by date

  From Date Subject
Next Message Noah Misch 2026-08-10 13:41:28 pgsql: Harden tsquery code against overflows.
Previous Message Noah Misch 2026-08-10 13:41:26 pgsql: Fix potential buffer overrun in regexp match/split functions.