| From: | Taiki Koshino <koshino(at)sraoss(dot)co(dot)jp> |
|---|---|
| To: | pgpool-committers(at)lists(dot)postgresql(dot)org |
| Subject: | pgpool: Add parse_peer_count helper and bound backend_desc array parsin |
| Date: | 2026-09-29 04:43:39 |
| Message-ID: | E1xBPgp-00000002gdq-2ZH3@gothos.postgresql.org |
| Views: | Whole Thread | Raw Message | Download mbox | Resend email |
| Thread: | |
| Lists: | pgpool-committers |
Add parse_peer_count helper and bound backend_desc array parsing.
The wd_json_data.c parsers consume JSON payloads supplied by watchdog
peers (any TCP host that can reach wd_port; auth defeated by the
default-empty wd_authkey) and write the parsed contents into
fixed-size arrays inside palloc'd POOL_CONFIG / BackendDesc /
WdNodeInfo storage. get_pool_config_from_json() in particular copied
value->u.array.length verbatim into config->backend_desc->num_backends
without any upper bound, so a peer-supplied "backend_desc" array of
more than MAX_NUM_BACKENDS (128) entries drove the loop past the
embedded BackendInfo backend_info[MAX_NUM_BACKENDS] array, writing
attacker-controlled port and hostname bytes into adjacent heap. The
sibling parser get_pg_backend_node_status_from_json() already clamps
the same way, so this is a per-handler omission, not a structural
limit; sibling wd_nodes parsing in the same function has the same
bug and will be migrated in a follow-up patch.
Introduce a static helper
static int
parse_peer_count(const json_value *jv, const char *field,
int max_count);
that validates the value is a JSON array, reads its length, and
rejects with ereport(ERROR, ...) when the count is negative or
exceeds the caller-supplied bound. The longjmp out of the parser
matches the existing exit channel for json_get_*_value_for_key on
malformed input, so callers do not need new error-path handling.
Migrate the backend_desc loop in get_pool_config_from_json() to use
the helper, capped at MAX_NUM_BACKENDS. Replace the per-element
strncpy(... sizeof(field) - 1) with strlcpy(... sizeof(field)) so
the destination is guaranteed NUL-terminated when the peer-supplied
hostname is exactly MAX_DB_HOST_NAMELEN (254) bytes.
Reported-by: Emond Papegaaij <emond(dot)papegaaij(at)topicus(dot)nl>
Reported-by: Claude
Author: Bo Peng <pengbo(at)sraoss(dot)co(dot)jp>
CVE-2026-92869
Backpatch-through: v4.3
Branch
------
V4_5_STABLE
Details
-------
https://git.postgresql.org/gitweb?p=pgpool2.git;a=commitdiff;h=0fa72fa3e7e62731f02994d4e0fc157b764ef22c
Modified Files
--------------
src/watchdog/wd_json_data.c | 36 +++++++++++++++++++++++++++++++-----
1 file changed, 31 insertions(+), 5 deletions(-)
| From | Date | Subject | |
|---|---|---|---|
| Next Message | Taiki Koshino | 2026-09-29 04:43:57 | pgpool: Fix operator precedence in parse_wd_node_function_json NodeIdLi |
| Previous Message | Taiki Koshino | 2026-09-29 04:43:11 | pgpool: Bound wd_nodes JSON array parsing in get_pool_config_from_json. |