agora inbox for pgsql-committers@postgresql.org  
help / color / mirror / Atom feed
From: Andrew Dunstan <andrew@dunslane.net>
To: pgsql-committers@lists.postgresql.org
Subject: pgsql: Fix heap-buffer-overflow in pglz_decompress() on corrupt input.
Date: Fri, 10 Apr 2026 14:39:44 +0000
Message-ID: <E1wBD1L-000Jfl-1b@gemulon.postgresql.org> (raw)

Fix heap-buffer-overflow in pglz_decompress() on corrupt input.

When decoding a match tag, pglz_decompress() reads 2 bytes (or 3
for extended-length matches) from the source buffer before checking
whether enough data remains.  The existing bounds check (sp > srcend)
occurs after the reads, so truncated compressed data that ends
mid-tag causes a read past the allocated buffer.

Fix by validating that sufficient source bytes are available before
reading each part of the match tag.  The post-read sp > srcend
check is no longer needed and is removed.

Found by fuzz testing with libFuzzer and AddressSanitizer.

Backpatch-through: 14

Branch
------
REL_18_STABLE

Details
-------
https://git.postgresql.org/pg/commitdiff/c3e436b1cb6090195f843daacd83b59258e1bcac

Modified Files
--------------
src/common/pg_lzcompress.c | 27 +++++++++++++++++++--------
1 file changed, 19 insertions(+), 8 deletions(-)



view thread (6+ messages)  latest in thread

Message-ID: <E1wBD1L-000Jfl-1b@gemulon.postgresql.org>
Permalink:  ../E1wBD1L-000Jfl-1b@gemulon.postgresql.org/
Also on:    postgresql.org/message-id/E1wBD1L-000Jfl-1b@gemulon.postgresql.org

reply

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Reply to all the recipients using the --to and --cc options:
  reply via email

  To: pgsql-committers@postgresql.org
  Cc: andrew@dunslane.net, pgsql-committers@lists.postgresql.org
  Subject: Re: pgsql: Fix heap-buffer-overflow in pglz_decompress() on corrupt input.
  In-Reply-To: <E1wBD1L-000Jfl-1b@gemulon.postgresql.org>

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox