agora inbox for pgsql-bugs@postgresql.org
help / color / mirror / Atom feedFrom: PG Bug reporting form <noreply@postgresql.org>
To: pgsql-bugs@lists.postgresql.org
Cc: imchifan@163.com
Subject: BUG #19714: pgcrypto pgp_sym_encrypt accepts nonnumeric s2k-mode as mode 0
Date: Tue, 22 Sep 2026 16:05:30 +0000
Message-ID: <19714-2c7439b39f73bde9@postgresql.org> (raw)
The following bug has been logged on the website:
Bug reference: 19714
Logged by: Qifan Liu
Email address: imchifan@163.com
PostgreSQL version: 18.6
Operating system: Linux on amd64
Description:
pgp_sym_encrypt accepts the malformed option s2k-mode=not_a_number and
produces usable ciphertext. The documented s2k-mode values are numeric modes
0, 1, and 3, so nonnumeric text should be rejected rather than silently
selecting mode 0. This can cause encryption to use a different string-to-key
mode than the caller specified. The impact is localized to pgcrypto option
validation.
Steps to reproduce
------------------
CREATE EXTENSION pgcrypto;
SELECT pgp_sym_decrypt(
pgp_sym_encrypt('payload',
'key',
's2k-mode=not_a_number'),
'key') = 'payload' AS malformed_s2k_mode_accepted;
Actual result
-------------
malformed_s2k_mode_accepted
-----------------------------
t
(1 row)
The malformed value is accepted, and the produced ciphertext decrypts
successfully.
Expected result
---------------
pgp_sym_encrypt should reject s2k-mode=not_a_number with an error because
s2k-mode accepts only the documented numeric values. It should not interpret
malformed text as mode 0 or produce ciphertext.
Additional information
----------------------
The issue was reproduced on PostgreSQL 20devel, PostgreSQL 18.6, and
PostgreSQL 17.11.
Inference: the behavior is consistent with numeric conversion that maps text
without a valid numeric prefix to zero before validating the resulting mode.
view thread (2+ messages) latest in thread
Message-ID: <19714-2c7439b39f73bde9@postgresql.org>
Permalink: ../19714-2c7439b39f73bde9@postgresql.org/
Also on: postgresql.org/message-id/19714-2c7439b39f73bde9@postgresql.org
reply
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Reply to all the recipients using the --to and --cc options:
reply via email
To: pgsql-bugs@postgresql.org
Cc: noreply@postgresql.org, pgsql-bugs@lists.postgresql.org, imchifan@163.com
Subject: Re: BUG #19714: pgcrypto pgp_sym_encrypt accepts nonnumeric s2k-mode as mode 0
In-Reply-To: <19714-2c7439b39f73bde9@postgresql.org>
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox