pgpool: Add parse_peer_count helper and bound backend_desc array parsin

From: Taiki Koshino <koshino(at)sraoss(dot)co(dot)jp>
To: pgpool-committers(at)lists(dot)postgresql(dot)org
Subject: pgpool: Add parse_peer_count helper and bound backend_desc array parsin
Date: 2026-09-29 04:43:39
Message-ID: E1xBPgp-00000002gdq-2ZH3@gothos.postgresql.org
Views: Whole Thread | Raw Message | Download mbox | Resend email
Thread:
Lists: pgpool-committers

Add parse_peer_count helper and bound backend_desc array parsing.

The wd_json_data.c parsers consume JSON payloads supplied by watchdog
peers (any TCP host that can reach wd_port; auth defeated by the
default-empty wd_authkey) and write the parsed contents into
fixed-size arrays inside palloc'd POOL_CONFIG / BackendDesc /
WdNodeInfo storage. get_pool_config_from_json() in particular copied
value->u.array.length verbatim into config->backend_desc->num_backends
without any upper bound, so a peer-supplied "backend_desc" array of
more than MAX_NUM_BACKENDS (128) entries drove the loop past the
embedded BackendInfo backend_info[MAX_NUM_BACKENDS] array, writing
attacker-controlled port and hostname bytes into adjacent heap. The
sibling parser get_pg_backend_node_status_from_json() already clamps
the same way, so this is a per-handler omission, not a structural
limit; sibling wd_nodes parsing in the same function has the same
bug and will be migrated in a follow-up patch.

Introduce a static helper

static int
parse_peer_count(const json_value *jv, const char *field,
int max_count);

that validates the value is a JSON array, reads its length, and
rejects with ereport(ERROR, ...) when the count is negative or
exceeds the caller-supplied bound. The longjmp out of the parser
matches the existing exit channel for json_get_*_value_for_key on
malformed input, so callers do not need new error-path handling.

Migrate the backend_desc loop in get_pool_config_from_json() to use
the helper, capped at MAX_NUM_BACKENDS. Replace the per-element
strncpy(... sizeof(field) - 1) with strlcpy(... sizeof(field)) so
the destination is guaranteed NUL-terminated when the peer-supplied
hostname is exactly MAX_DB_HOST_NAMELEN (254) bytes.

Reported-by: Emond Papegaaij <emond(dot)papegaaij(at)topicus(dot)nl>
Reported-by: Claude
Author: Bo Peng <pengbo(at)sraoss(dot)co(dot)jp>
CVE-2026-92869
Backpatch-through: v4.3

Branch
------
V4_5_STABLE

Details
-------
https://git.postgresql.org/gitweb?p=pgpool2.git;a=commitdiff;h=0fa72fa3e7e62731f02994d4e0fc157b764ef22c

Modified Files
--------------
src/watchdog/wd_json_data.c | 36 +++++++++++++++++++++++++++++++-----
1 file changed, 31 insertions(+), 5 deletions(-)

Browse pgpool-committers by date

  From Date Subject
Next Message Taiki Koshino 2026-09-29 04:43:57 pgpool: Fix operator precedence in parse_wd_node_function_json NodeIdLi
Previous Message Taiki Koshino 2026-09-29 04:43:11 pgpool: Bound wd_nodes JSON array parsing in get_pool_config_from_json.