postgres.git / summary / log / commit / refs

commit    b99b74144f9f37f39c38ca43b94a5ad46bb24a43
Author:   Michael Paquier <michael@paquier.xyz>
Date:     Thu Aug 20 00:38:23 2026 +0000

    Reject too many arguments in CREATE TRIGGER
    
    The number of trigger arguments is stored as a smallint, but there was
    no check that the number of arguments fits with the catalog data type.
    This could result in an invalid negative value being stored once one
    defined more than INT16_MAX arguments, with an overflowed value stored
    in the catalogs.
    
    Looking at other catalogs that store a number of arguments, we have
    similar protections already in place (aggregates, functions, etc.).
    
    Reported-by: Xingwang Xiang <v3rdant.xiang@gmail.com>
    Author: Kyotaro Horiguchi <horikyota.ntt@gmail.com>
    Discussion: https://postgr.es/m/19627-5b72a57e332e2b3f@postgresql.org
    Backpatch-through: 14


src/backend/commands/trigger.c | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) diff --git a/src/backend/commands/trigger.c b/src/backend/commands/trigger.c index b7881bf4a29..8e1338d2c21 100644 --- a/src/backend/commands/trigger.c +++ b/src/backend/commands/trigger.c @@ -897,9 +897,16 @@ CreateTriggerFiringOn(const CreateTrigStmt *stmt, const char *queryString, { ListCell *le; char *args; - int16 nargs = list_length(stmt->args); + int nargs = list_length(stmt->args); int len = 0; + Assert(nargs >= 0); + if (nargs > PG_INT16_MAX) + ereport(ERROR, + errcode(ERRCODE_TOO_MANY_ARGUMENTS), + errmsg("triggers cannot have more than %d arguments", + PG_INT16_MAX)); + foreach(le, stmt->args) { char *ar = strVal(lfirst(le));