postgres-github.git / summary / log / commit / refs

commit    d388e1d7f0468db8d046f9101f972d1fa988b19a
Author:   Michael Paquier <michael@paquier.xyz>
Commit:   Noah Misch <noah@leadboat.com>
Date:     Mon May 11 12:13:46 2026 +0000

    Fix overflows with ts_headline()
    
    The options "StartSel", "StopSel" and "FragmentDelimiter" given by a
    caller of the SQL function ts_headline() have their lengths stored as
    int16.  When providing values larger than PG_INT16_MAX, it was possible
    to overflow the length values stored, leading to incorrect behaviors in
    generateHeadline(), in most cases translating to a crash.
    
    Attempting to use values for these options larger than PG_INT16_MAX is
    now blocked.  Some test cases are added to cover our tracks.
    
    Reported-by: Xint Code
    Author: Michael Paquier <michael@paquier.xyz>
    Backpatch-through: 14
    Security: CVE-2026-6473

[parent: 2f1b16e867e7]