postgres.git / summary / log / commit / refs

commit    bf1bb7e29cb1eddb0fad7422c032abb2b756c281
Author:   Michael Paquier <michael@paquier.xyz>
Commit:   Noah Misch <noah@leadboat.com>
Date:     Mon Aug 10 13:38:05 2026 +0000

    Reject GSSEncRequest after direct SSL connection
    
    When a direct SSL connection was established, ProcessStartupPacket()
    still accepted GSSEncRequest messages.  The GSSAPI negotiation would
    then use raw writes and reads, bypassing the TLS encryption layer.
    After the GSS encryption was established, the connection continued to
    use TLS.  This could betray the HBA rules so as the backend does
    protocol exchanges inconsistent with the connection policies in place,
    with TLS taking priority over GSS in the backend.
    
    The SSL negotiation path already guarded against attempts to request
    SSL after a direct SSL request has been processed.  The GSS path is now
    guarded the same way when receiving a startup packet.
    
    Reported-by: p4p3r <kbfanta@naver.com>
    Author: Michael Paquier <michael@paquier.xyz>
    Reviewed-by: Jacob Champion <champion.p@gmail.com>
    Backpatch-through: 17
    Security: CVE-2026-14681


src/backend/tcop/backend_startup.c | 9 +++++++-- 1 file changed, 7 insertions(+), 2 deletions(-) diff --git a/src/backend/tcop/backend_startup.c b/src/backend/tcop/backend_startup.c index 25205cee0fa..912ad7dc957 100644 --- a/src/backend/tcop/backend_startup.c +++ b/src/backend/tcop/backend_startup.c @@ -659,8 +659,13 @@ retry: char GSSok = 'N'; #ifdef ENABLE_GSS - /* No GSSAPI encryption when on Unix socket */ - if (port->laddr.addr.ss_family != AF_UNIX) + + /* + * No GSSAPI encryption when on Unix socket. + * + * Also no GSS negotiation if we already have a direct SSL connection. + */ + if (port->laddr.addr.ss_family != AF_UNIX && !port->ssl_in_use) GSSok = 'G'; #endif [parent: 457b8737ab29]