pgpool: Reject client certificate CN containing embedded NUL byte.

From: Taiki Koshino <koshino(at)sraoss(dot)co(dot)jp>
To: pgpool-committers(at)lists(dot)postgresql(dot)org
Subject: pgpool: Reject client certificate CN containing embedded NUL byte.
Date: 2026-09-29 04:41:29
Message-ID: E1xBPej-00000002e7y-1UMt@gothos.postgresql.org
Views: Whole Thread | Raw Message | Download mbox | Resend email
Thread:
Lists: pgpool-committers

Reject client certificate CN containing embedded NUL byte.

X509_NAME_get_text_by_NID returns the ASN.1 byte length of the Common
Name string. pgpool stored the buffer as a C string and later compared
it to the HBA-supplied username with strcasecmp(). If the certificate
CN contains an embedded NUL byte (e.g. "target\0attacker"), the
ASN.1-length view of the name and the C-string view disagree:
strcasecmp() truncates at the embedded NUL, so a peer presenting a
maliciously crafted certificate authenticates as the prefix.

Reject the certificate when the C-string length of the extracted CN
differs from the byte length returned by X509_NAME_get_text_by_NID().

Reported-by: Emond Papegaaij <emond(dot)papegaaij(at)topicus(dot)nl>
Reported-by: Claude
Author: Bo Peng <pengbo(at)sraoss(dot)co(dot)jp>
CVE-2026-92868
Backpatch-through: v4.3

Branch
------
V4_7_STABLE

Details
-------
https://git.postgresql.org/gitweb?p=pgpool2.git;a=commitdiff;h=f135cf0fa58bd6c9d0edcbd6b36f67331cc96007

Modified Files
--------------
src/utils/pool_ssl.c | 6 ++++++
1 file changed, 6 insertions(+)

Browse pgpool-committers by date

  From Date Subject
Next Message Taiki Koshino 2026-09-29 04:43:11 pgpool: Bound wd_nodes JSON array parsing in get_pool_config_from_json.
Previous Message Tatsuo Ishii 2026-09-20 05:00:00 pgpool: Test: enhance 018.detach_primary regression test.