pgsql: Fix privilege handling in postgres_fdw statistics import.

From: Etsuro Fujita <efujita(at)postgresql(dot)org>
To: pgsql-committers(at)lists(dot)postgresql(dot)org
Subject: pgsql: Fix privilege handling in postgres_fdw statistics import.
Date: 2026-09-26 11:36:38
Message-ID: E1xAQhq-00000001LHk-3Bv7@gemulon.postgresql.org
Views: Whole Thread | Raw Message | Download mbox | Resend email
Thread:
Lists: pgsql-committers

Fix privilege handling in postgres_fdw statistics import.

When ANALYZE imports statistics from a remote server, it fetched/stored
the statistics while still running as the user executing ANALYZE, not as
the foreign table's owner. This is inconsistent with the sampling path,
and it causes a security issue: a role that owns a foreign table but has
no access to the underlying remote data (eg, no access privileges on the
remote server) could obtain that data by having a privileged user run
ANALYZE on the table; the imported statistics like most_common_vals then
expose sampled values from the remote data, as shown in the reproducer
on the discussion thread.

To fix, switch to the foreign table owner's userid in analyze_rel()
before calling the ImportForeignStatistics() routine, mirroring the
identity used by the sampling path. This not only makes the privilege
handling consistent between the sampling/import paths, but also prevents
statistics import from disclosing data the table owner couldn't
otherwise obtain.

Oversight in commit 28972b6fc.

Reported-by: Fujii Masao <masao(dot)fujii(at)gmail(dot)com>
Reported-by: Osama Abdul Qader <osamaabdulqader(dot)cs(at)gmail(dot)com>
Reported-by: Noah Misch <noah(at)leadboat(dot)com>
Author: Noah Misch <noah(at)leadboat(dot)com>
Reviewed-by: Matheus Alcantara <matheusssilv97(at)gmail(dot)com>
Reviewed-by: Etsuro Fujita <etsuro(dot)fujita(at)gmail(dot)com>
Discussion: https://postgr.es/m/CAPmGK16jVk+i2KMkkgR9ajoPdaUAinvcspkk5Bc6urbo2xYTMQ@mail.gmail.com
Backpatch-through: 19

Branch
------
master

Details
-------
https://git.postgresql.org/pg/commitdiff/7d47e41238004b6b8bce076d4bb76d858257b58d

Modified Files
--------------
contrib/postgres_fdw/postgres_fdw.c | 9 ++++-----
src/backend/commands/analyze.c | 30 ++++++++++++++++++++++++++----
2 files changed, 30 insertions(+), 9 deletions(-)

Browse pgsql-committers by date

  From Date Subject
Next Message Etsuro Fujita 2026-09-26 11:41:42 pgsql: postgres_fdw: Improve comment in fetch_remote_statistics().
Previous Message Amit Langote 2026-09-26 02:14:28 pgsql: Check EXECUTE privilege on functions invoked by the RI fast path