postgres-github.git / summary / log / commit / refs

commit    a1063eecedf379de5dad73f9bd6e856ad5c114fb
Author:   Michael Paquier <michael@paquier.xyz>
Commit:   Noah Misch <noah@leadboat.com>
Date:     Mon May 11 12:13:47 2026 +0000

    Prevent path traversal in pg_basebackup and pg_rewind
    
    pg_rewind and pg_basebackup could be fed paths from rogue endpoints that
    could overwrite the contents of the client when received, achieving path
    traversal.
    
    There were two areas in the tree that were sensitive to this problem:
    - pg_basebackup, through the astreamer code, where no validation was
    performed before building an output path when streaming tar data.  This
    is an issue in v15 and newer versions.
    - pg_rewind file operations for paths received through libpq, for all
    the stable branches supported.
    
    In order to address this problem, this commit adds a helper function in
    path.c, that reuses path_is_relative_and_below_cwd() after applying
    canonicalize_path().  This can be used to validate the paths received
    from a connection point.  A path is considered invalid if any of the two
    following conditions is satisfied:
    - The path is absolute.
    - The path includes a direct parent-directory reference.
    
    Reported-by: XlabAI Team of Tencent Xuanwu Lab
    Reported-by: Valery Gubanov <valerygubanov95@gmail.com>
    Author: Michael Paquier <michael@paquier.xyz>
    Reviewed-by: Amit Kapila <amit.kapila16@gmail.com>
    Backpatch-through: 14
    Security: CVE-2026-6475

[parent: 6a985e71e921]