| From: | Etsuro Fujita <efujita(at)postgresql(dot)org> |
|---|---|
| To: | pgsql-committers(at)lists(dot)postgresql(dot)org |
| Subject: | pgsql: Fix privilege handling in postgres_fdw statistics import. |
| Date: | 2026-09-26 11:36:38 |
| Message-ID: | E1xAQhq-00000001LHm-3Fsu@gemulon.postgresql.org |
| Views: | Whole Thread | Raw Message | Download mbox | Resend email |
| Thread: | |
| Lists: | pgsql-committers |
Fix privilege handling in postgres_fdw statistics import.
When ANALYZE imports statistics from a remote server, it fetched/stored
the statistics while still running as the user executing ANALYZE, not as
the foreign table's owner. This is inconsistent with the sampling path,
and it causes a security issue: a role that owns a foreign table but has
no access to the underlying remote data (eg, no access privileges on the
remote server) could obtain that data by having a privileged user run
ANALYZE on the table; the imported statistics like most_common_vals then
expose sampled values from the remote data, as shown in the reproducer
on the discussion thread.
To fix, switch to the foreign table owner's userid in analyze_rel()
before calling the ImportForeignStatistics() routine, mirroring the
identity used by the sampling path. This not only makes the privilege
handling consistent between the sampling/import paths, but also prevents
statistics import from disclosing data the table owner couldn't
otherwise obtain.
Oversight in commit 28972b6fc.
Reported-by: Fujii Masao <masao(dot)fujii(at)gmail(dot)com>
Reported-by: Osama Abdul Qader <osamaabdulqader(dot)cs(at)gmail(dot)com>
Reported-by: Noah Misch <noah(at)leadboat(dot)com>
Author: Noah Misch <noah(at)leadboat(dot)com>
Reviewed-by: Matheus Alcantara <matheusssilv97(at)gmail(dot)com>
Reviewed-by: Etsuro Fujita <etsuro(dot)fujita(at)gmail(dot)com>
Discussion: https://postgr.es/m/CAPmGK16jVk+i2KMkkgR9ajoPdaUAinvcspkk5Bc6urbo2xYTMQ@mail.gmail.com
Backpatch-through: 19
Branch
------
REL_19_STABLE
Details
-------
https://git.postgresql.org/pg/commitdiff/18c04668f781715614527aa85210026df2e49ed5
Modified Files
--------------
contrib/postgres_fdw/postgres_fdw.c | 9 ++++-----
src/backend/commands/analyze.c | 30 ++++++++++++++++++++++++++----
2 files changed, 30 insertions(+), 9 deletions(-)
| From | Date | Subject | |
|---|---|---|---|
| Next Message | Etsuro Fujita | 2026-09-26 11:41:42 | pgsql: postgres_fdw: Improve comment in fetch_remote_statistics(). |
| Previous Message | Amit Langote | 2026-09-26 02:14:28 | pgsql: Check EXECUTE privilege on functions invoked by the RI fast path |