Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.98.2) (envelope-from ) id 1x937n-00000001iIT-0kjF for pgsql-bugs@arkaria.postgresql.org; Tue, 22 Sep 2026 16:13:43 +0000 Received: from localhost ([127.0.0.1] helo=malur.postgresql.org) by malur.postgresql.org with esmtp (Exim 4.98.2) (envelope-from ) id 1x937m-0000000HLxP-0iU0 for pgsql-bugs@arkaria.postgresql.org; Tue, 22 Sep 2026 16:13:42 +0000 Received: from magus.postgresql.org ([2a02:c0:301:0:ffff::29]) by malur.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.98.2) (envelope-from ) id 1x930W-0000000HCCT-1otS for pgsql-bugs@lists.postgresql.org; Tue, 22 Sep 2026 16:06:12 +0000 Received: from mahout.postgresql.org ([2001:4800:3e1:1::227]) by magus.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.98.2) (envelope-from ) id 1x930Q-00000000j69-3Mpd for pgsql-bugs@lists.postgresql.org; Tue, 22 Sep 2026 16:06:12 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=postgresql.org; s=20171124; h=Message-ID:Date:Reply-To:Cc:From:To:Subject: Content-Transfer-Encoding:MIME-Version:Content-Type:Sender:Content-ID: Content-Description:In-Reply-To:References; bh=27rJo7iYTuX8dFyh3EG6FCkml5vm+H1+Wyv8c4WG4Fc=; b=AlBKJlfJWMkXLmUHKRkdOP3s6y fcUIejv9vTK0Do3+xkrqLIn3aiXuKxZT/iDuEuOqEXtVQQVCLXkPw7ZXAkWrSOn7gneaKniWB1LrJ IwbO5cnHxOXzd5T+qYoln8Rm8d78Ehl3yhcE33ZhkqoYPPLARwJvsWIiD7mtq4WsFzmRfENuSKWPS Z92/yXxZMv5TMt7573A2EGk4EAZWuCFDP+KAt4K5AkKuunLomddTjfRzjxbciBzMNTiABvJikWiGZ rGfLT+mbA3Ax3dYp42tTxg79292JIlgT/iFEjriC/pciJ+MYomQ33drpgdKvrSMb6R/BocHjPH7sa jhH2bRVw==; Received: from wrigleys.postgresql.org ([2a02:16a8:dc51::60]) by mahout.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1x930O-00281Y-22 for pgsql-bugs@lists.postgresql.org; Tue, 22 Sep 2026 16:06:05 +0000 Received: from localhost ([127.0.0.1] helo=wrigleys.postgresql.org) by wrigleys.postgresql.org with esmtp (Exim 4.98.2) (envelope-from ) id 1x930M-00000005xOA-32es for pgsql-bugs@lists.postgresql.org; Tue, 22 Sep 2026 16:06:03 +0000 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Subject: BUG #19714: pgcrypto pgp_sym_encrypt accepts nonnumeric s2k-mode as mode 0 To: pgsql-bugs@lists.postgresql.org From: PG Bug reporting form Cc: imchifan@163.com Reply-To: imchifan@163.com, pgsql-bugs@lists.postgresql.org Date: Tue, 22 Sep 2026 16:05:30 +0000 Message-ID: <19714-2c7439b39f73bde9@postgresql.org> X-Auto-Response-Suppress: All Auto-Submitted: auto-generated List-Id: List-Help: List-Subscribe: List-Post: List-Owner: List-Archive: Archived-At: Precedence: bulk The following bug has been logged on the website: Bug reference: 19714 Logged by: Qifan Liu Email address: imchifan@163.com PostgreSQL version: 18.6 Operating system: Linux on amd64 Description: =20 pgp_sym_encrypt accepts the malformed option s2k-mode=3Dnot_a_number and produces usable ciphertext. The documented s2k-mode values are numeric modes 0, 1, and 3, so nonnumeric text should be rejected rather than silently selecting mode 0. This can cause encryption to use a different string-to-key mode than the caller specified. The impact is localized to pgcrypto option validation. Steps to reproduce ------------------ CREATE EXTENSION pgcrypto; SELECT pgp_sym_decrypt( pgp_sym_encrypt('payload', 'key', 's2k-mode=3Dnot_a_number'), 'key') =3D 'payload' AS malformed_s2k_mode_accepted; Actual result ------------- malformed_s2k_mode_accepted ----------------------------- t (1 row) The malformed value is accepted, and the produced ciphertext decrypts successfully. Expected result --------------- pgp_sym_encrypt should reject s2k-mode=3Dnot_a_number with an error because s2k-mode accepts only the documented numeric values. It should not interpret malformed text as mode 0 or produce ciphertext. Additional information ---------------------- The issue was reproduced on PostgreSQL 20devel, PostgreSQL 18.6, and PostgreSQL 17.11. Inference: the behavior is consistent with numeric conversion that maps text without a valid numeric prefix to zero before validating the resulting mode.