pgpool: Bound wd_nodes JSON array parsing in get_pool_config_from_json.

From: Taiki Koshino <koshino(at)sraoss(dot)co(dot)jp>
To: pgpool-committers(at)lists(dot)postgresql(dot)org
Subject: pgpool: Bound wd_nodes JSON array parsing in get_pool_config_from_json.
Date: 2026-09-29 04:43:11
Message-ID: E1xBPgN-00000002gHE-2kz7@gothos.postgresql.org
Views: Whole Thread | Raw Message | Download mbox | Resend email
Thread:
Lists: pgpool-committers

Bound wd_nodes JSON array parsing in get_pool_config_from_json.

In src/watchdog/wd_json_data.c get_pool_config_from_json(), the loop
over the peer-supplied "wd_nodes" JSON array writes into
config->wd_nodes.wd_node_info[i] using the array length declared by
the peer. The destination is a fixed-size array of MAX_WATCHDOG_NUM
(128) WdNodeInfo entries (see WdNodesConfig in src/include/pool_config.h),
but no upper bound is enforced before the loop, so a peer that ships
a wd_nodes array of length > 128 walks the loop index past the end
of the array and writes peer-controlled host/port data into adjacent
heap memory.

This is the wd_nodes half of PGP-0001 (the backend_desc half is
addressed in a sibling patch). Reject any wd_nodes array whose
declared length exceeds MAX_WATCHDOG_NUM via ereport(ERROR, ...) so
the JSON is dropped before any out-of-bounds write occurs.

Inline bound check (rather than a shared parse_peer_count helper) so
this patch is self-contained and back-portable independently of any
helper migration.

Reported-by: Emond Papegaaij <emond(dot)papegaaij(at)topicus(dot)nl>
Reported-by: Claude
Author: Bo Peng <pengbo(at)sraoss(dot)co(dot)jp>
CVE-2026-92869
Backpatch-through: v4.3

Branch
------
V4_6_STABLE

Details
-------
https://git.postgresql.org/gitweb?p=pgpool2.git;a=commitdiff;h=5e6774fda6182d806b4539f92bd60d7f938a47d3

Modified Files
--------------
src/watchdog/wd_json_data.c | 6 ++++++
1 file changed, 6 insertions(+)

Browse pgpool-committers by date

  From Date Subject
Next Message Taiki Koshino 2026-09-29 04:43:39 pgpool: Add parse_peer_count helper and bound backend_desc array parsin
Previous Message Taiki Koshino 2026-09-29 04:41:29 pgpool: Reject client certificate CN containing embedded NUL byte.