postgres.git / summary / log / commit / refs
commit 510a05f07cb5ff86fbbedac848ee5c80b8bbfd83
Author: Noah Misch <noah@leadboat.com>
Date: Sun May 17 01:01:35 2026 +0000
Use ereport(ERROR), not Assert(), for publisher tuples missing columns.
Three locations use Assert() to guard against a mismatch between the
number of columns advertised in the RELATION message and the number
actually received in the subsequent INSERT/UPDATE tuple message. Since
these values originate from the publisher, the check must survive into
production builds.
A malicious or buggy publisher can send a RELATION claiming N columns
and an INSERT claiming M < N columns. The subscriber's apply worker
indexes into colvalues[]/colstatus[] using column indices from the
RELATION message's attribute map, causing a heap out-of-bounds read when
the tuple's column array is smaller than expected. We've looked, without
success, for a scenario in which the publisher holds sufficient control
over these out-of-bounds bytes to exploit this or even to reach a
SIGSEGV. Despite not finding one, the code has been fragile. Back-patch
to v14 (all supported versions).
Reported-by: Varik Matevosyan <varikmatevosyan@gmail.com>
Author: Varik Matevosyan <varikmatevosyan@gmail.com>
Discussion: https://postgr.es/m/CA+bBoog3cCogktzfLb9bppUByu-10B3CFp8u=iKXG_OvtAguCw@mail.gmail.com
Backpatch-through: 14
src/backend/replication/logical/worker.c | 23 +++++++++++++++++++----
1 file changed, 19 insertions(+), 4 deletions(-)
diff --git a/src/backend/replication/logical/worker.c b/src/backend/replication/logical/worker.c
index 93a7714922e..5bcefd4523a 100644
--- a/src/backend/replication/logical/worker.c
+++ b/src/backend/replication/logical/worker.c
@@ -553,9 +553,15 @@ slot_store_data(TupleTableSlot *slot, LogicalRepRelMapEntry *rel,
if (!att->attisdropped && remoteattnum >= 0)
{
- StringInfo colvalue = &tupleData->colvalues[remoteattnum];
+ StringInfo colvalue;
+
+ if (remoteattnum >= tupleData->ncols)
+ ereport(ERROR,
+ (errcode(ERRCODE_PROTOCOL_VIOLATION),
+ errmsg("logical replication column %d not found in tuple: only %d column(s) received",
+ remoteattnum + 1, tupleData->ncols)));
- Assert(remoteattnum < tupleData->ncols);
+ colvalue = &tupleData->colvalues[remoteattnum];
errarg.remote_attnum = remoteattnum;
@@ -677,7 +683,11 @@ slot_modify_data(TupleTableSlot *slot, TupleTableSlot *srcslot,
if (remoteattnum < 0)
continue;
- Assert(remoteattnum < tupleData->ncols);
+ if (remoteattnum >= tupleData->ncols)
+ ereport(ERROR,
+ (errcode(ERRCODE_PROTOCOL_VIOLATION),
+ errmsg("logical replication column %d not found in tuple: only %d column(s) received",
+ remoteattnum + 1, tupleData->ncols)));
if (tupleData->colstatus[remoteattnum] != LOGICALREP_COLUMN_UNCHANGED)
{
@@ -1421,7 +1431,12 @@ apply_handle_update(StringInfo s)
if (!att->attisdropped && remoteattnum >= 0)
{
- Assert(remoteattnum < newtup.ncols);
+ if (remoteattnum >= newtup.ncols)
+ ereport(ERROR,
+ (errcode(ERRCODE_PROTOCOL_VIOLATION),
+ errmsg("logical replication column %d not found in tuple: only %d column(s) received",
+ remoteattnum + 1, newtup.ncols)));
+
if (newtup.colstatus[remoteattnum] != LOGICALREP_COLUMN_UNCHANGED)
target_rte->updatedCols =
bms_add_member(target_rte->updatedCols,
[parent: 4c35d93e49ef]