| From: | Taiki Koshino <koshino(at)sraoss(dot)co(dot)jp> |
|---|---|
| To: | pgpool-committers(at)lists(dot)postgresql(dot)org |
| Subject: | pgpool: Reject client certificate CN containing embedded NUL byte. |
| Date: | 2026-09-29 04:41:29 |
| Message-ID: | E1xBPej-00000002e7y-1UMt@gothos.postgresql.org |
| Views: | Whole Thread | Raw Message | Download mbox | Resend email |
| Thread: | |
| Lists: | pgpool-committers |
Reject client certificate CN containing embedded NUL byte.
X509_NAME_get_text_by_NID returns the ASN.1 byte length of the Common
Name string. pgpool stored the buffer as a C string and later compared
it to the HBA-supplied username with strcasecmp(). If the certificate
CN contains an embedded NUL byte (e.g. "target\0attacker"), the
ASN.1-length view of the name and the C-string view disagree:
strcasecmp() truncates at the embedded NUL, so a peer presenting a
maliciously crafted certificate authenticates as the prefix.
Reject the certificate when the C-string length of the extracted CN
differs from the byte length returned by X509_NAME_get_text_by_NID().
Reported-by: Emond Papegaaij <emond(dot)papegaaij(at)topicus(dot)nl>
Reported-by: Claude
Author: Bo Peng <pengbo(at)sraoss(dot)co(dot)jp>
CVE-2026-92868
Backpatch-through: v4.3
Branch
------
V4_7_STABLE
Details
-------
https://git.postgresql.org/gitweb?p=pgpool2.git;a=commitdiff;h=f135cf0fa58bd6c9d0edcbd6b36f67331cc96007
Modified Files
--------------
src/utils/pool_ssl.c | 6 ++++++
1 file changed, 6 insertions(+)
| From | Date | Subject | |
|---|---|---|---|
| Next Message | Taiki Koshino | 2026-09-29 04:43:11 | pgpool: Bound wd_nodes JSON array parsing in get_pool_config_from_json. |
| Previous Message | Tatsuo Ishii | 2026-09-20 05:00:00 | pgpool: Test: enhance 018.detach_primary regression test. |