pgsql: Use value of scram_iterations in mock_scram_secret().

From: Noah Misch <noah(at)leadboat(dot)com>
To: pgsql-committers(at)lists(dot)postgresql(dot)org
Subject: pgsql: Use value of scram_iterations in mock_scram_secret().
Date: 2026-08-10 13:41:29
Message-ID: E1wtQFt-00000000yGq-2WgQ@gemulon.postgresql.org
Views: Whole Thread | Raw Message | Download mbox | Resend email
Thread:
Lists: pgsql-committers

Use value of scram_iterations in mock_scram_secret().

Presently, mock_scram_secret() always uses
SCRAM_SHA_256_DEFAULT_ITERATIONS, which poses an observable
response discrepancy hazard when scram_iterations is set to
something else. To fix, use the value of the configuration
parameter instead, and document that unauthenticated users can
discover the existence of roles with passwords created with
different iteration counts.

Reported-by: Radim Marek <radim(at)boringsql(dot)com>
Author: Nathan Bossart <nathandbossart(at)gmail(dot)com>
Reviewed-by: Michael Paquier <michael(at)paquier(dot)xyz>
Reviewed-by: Heikki Linnakangas <hlinnaka(at)iki(dot)fi>
Reviewed-by: Jacob Champion <champion(dot)p(at)gmail(dot)com>
Security: CVE-2026-14672
Backpatch-through: 16

Branch
------
REL_16_STABLE

Details
-------
https://git.postgresql.org/pg/commitdiff/fadbe882d16112fd8c5ccf2b73eb9621dbfe130a
Author: Nathan Bossart <nathan(at)postgresql(dot)org>

Modified Files
--------------
doc/src/sgml/config.sgml | 13 +++++++++++++
src/backend/libpq/auth-scram.c | 2 +-
2 files changed, 14 insertions(+), 1 deletion(-)

Browse pgsql-committers by date

  From Date Subject
Next Message Noah Misch 2026-08-10 13:41:30 pgsql: Reject calls from SQL to functions that take or return type inte
Previous Message Noah Misch 2026-08-10 13:41:28 pgsql: Harden tsquery code against overflows.