postgres-github.git / summary / log / commit / refs

commit    ec8ded4b327f9d121811f43bf0177d0f289c3949
Author:   Tom Lane <tgl@sss.pgh.pa.us>
Commit:   Noah Misch <noah@leadboat.com>
Date:     Mon May 11 12:13:46 2026 +0000

    Guard against unsafe conditions in usage of pg_strftime().
    
    Although pg_strftime() has defined error conditions, no callers bother
    to check for errors.  This is problematic because the output string is
    very likely not null-terminated if an error occurs, so that blindly
    using it is unsafe.  Rather than trusting that we can find and fix all
    the callers, let's alter the function's API spec slightly: make it
    guarantee a null-terminated result so long as maxsize > 0.
    
    Furthermore, if we do get an error, let's make that null-terminated
    result be an empty string.  We could instead truncate at the buffer
    length, but that risks producing mis-encoded output if the tz_name
    string contains multibyte characters.  It doesn't seem reasonable for
    src/timezone/ to make use of our encoding-aware truncation logic.
    Also, the only really likely source of a failure is a user-supplied
    timezone name that is intentionally trying to overrun our buffers.
    I don't feel a need to be particularly friendly about that case.
    
    Author: Tom Lane <tgl@sss.pgh.pa.us>
    Reviewed-by: John Naylor <johncnaylorls@gmail.com>
    Backpatch-through: 14
    Security: CVE-2026-6474

[parent: 76ab76f875a8]