postgres.git / summary / log / commit / refs

commit    1c732c8518d88c2663f96236bf8bb104f3d0a5d4
Author:   Tom Lane <tgl@sss.pgh.pa.us>
Date:     Mon Aug 17 22:09:07 2026 +0000

    Tighten up tsqueryrecv().
    
    tsqueryrecv() accepted zero-length lexemes, which tsqueryin() doesn't.
    It also accepted phrase distance values larger than MAXENTRYPOS,
    which tsqueryin() doesn't.  While neither of these omissions are
    very harmful in themselves, they do allow accepting tsquery values
    that will fail in a subsequent textual dump/reload.
    
    Commit 23d9ad771 performed similar tightening of tsvectorrecv(),
    but I left off these changes at the time because they didn't seem
    to have security implications.
    
    Reported-by: Claude Code (via Noah Misch)
    Author: Tom Lane <tgl@sss.pgh.pa.us>
    Reviewed-by: Chao Li <li.evan.chao@gmail.com>
    Discussion: https://postgr.es/m/455079.1786897319@sss.pgh.pa.us
    Backpatch-through: 14


src/backend/utils/adt/tsquery.c | 12 +++++++++++- 1 file changed, 11 insertions(+), 1 deletion(-) diff --git a/src/backend/utils/adt/tsquery.c b/src/backend/utils/adt/tsquery.c index c49b06f72bb..a63b8f75eb8 100644 --- a/src/backend/utils/adt/tsquery.c +++ b/src/backend/utils/adt/tsquery.c @@ -1273,6 +1273,9 @@ tsqueryrecv(PG_FUNCTION_ARGS) if (weight > 0xF) elog(ERROR, "invalid tsquery: invalid weight bitmap"); + if (val_len == 0) + elog(ERROR, "invalid tsquery: empty operand"); + if (val_len > MAXSTRLEN) elog(ERROR, "invalid tsquery: operand too long"); @@ -1312,7 +1315,14 @@ tsqueryrecv(PG_FUNCTION_ARGS) item->qoperator.oper = oper; if (oper == OP_PHRASE) - item->qoperator.distance = (int16) pq_getmsgint(buf, sizeof(int16)); + { + unsigned int dist = pq_getmsgint(buf, sizeof(int16)); + + if (dist > MAXENTRYPOS) + elog(ERROR, "invalid tsquery: invalid phrase distance %u", + dist); + item->qoperator.distance = (int16) dist; + } } else elog(ERROR, "unrecognized tsquery node type: %d", item->type); [parent: 9c1e3b58bf54]