agora inbox for pgsql-committers@postgresql.orghelp / color / mirror / Atom feed
pgsql: Fix heap-buffer-overflow in pglz_decompress() on corrupt input. 6+ messages / 1 participants [nested] [flat]
* pgsql: Fix heap-buffer-overflow in pglz_decompress() on corrupt input. @ 2026-04-10 13:32 Andrew Dunstan <andrew@dunslane.net> 0 siblings, 0 replies; 6+ messages in thread From: Andrew Dunstan @ 2026-04-10 13:32 UTC (permalink / raw) To: pgsql-committers@lists.postgresql.org Fix heap-buffer-overflow in pglz_decompress() on corrupt input. When decoding a match tag, pglz_decompress() reads 2 bytes (or 3 for extended-length matches) from the source buffer before checking whether enough data remains. The existing bounds check (sp > srcend) occurs after the reads, so truncated compressed data that ends mid-tag causes a read past the allocated buffer. Fix by validating that sufficient source bytes are available before reading each part of the match tag. The post-read sp > srcend check is no longer needed and is removed. Found by fuzz testing with libFuzzer and AddressSanitizer. Branch ------ master Details ------- https://git.postgresql.org/pg/commitdiff/2b5ba2a0a141f621f61cb732d776dc78269f879b Modified Files -------------- src/common/pg_lzcompress.c | 27 +++++++++++++++++++-------- 1 file changed, 19 insertions(+), 8 deletions(-) ^ permalink raw reply [nested|flat] 6+ messages in thread
* pgsql: Fix heap-buffer-overflow in pglz_decompress() on corrupt input. @ 2026-04-10 14:39 Andrew Dunstan <andrew@dunslane.net> 0 siblings, 0 replies; 6+ messages in thread From: Andrew Dunstan @ 2026-04-10 14:39 UTC (permalink / raw) To: pgsql-committers@lists.postgresql.org Fix heap-buffer-overflow in pglz_decompress() on corrupt input. When decoding a match tag, pglz_decompress() reads 2 bytes (or 3 for extended-length matches) from the source buffer before checking whether enough data remains. The existing bounds check (sp > srcend) occurs after the reads, so truncated compressed data that ends mid-tag causes a read past the allocated buffer. Fix by validating that sufficient source bytes are available before reading each part of the match tag. The post-read sp > srcend check is no longer needed and is removed. Found by fuzz testing with libFuzzer and AddressSanitizer. Backpatch-through: 14 Branch ------ REL_18_STABLE Details ------- https://git.postgresql.org/pg/commitdiff/c3e436b1cb6090195f843daacd83b59258e1bcac Modified Files -------------- src/common/pg_lzcompress.c | 27 +++++++++++++++++++-------- 1 file changed, 19 insertions(+), 8 deletions(-) ^ permalink raw reply [nested|flat] 6+ messages in thread
* pgsql: Fix heap-buffer-overflow in pglz_decompress() on corrupt input. @ 2026-04-10 14:39 Andrew Dunstan <andrew@dunslane.net> 0 siblings, 0 replies; 6+ messages in thread From: Andrew Dunstan @ 2026-04-10 14:39 UTC (permalink / raw) To: pgsql-committers@lists.postgresql.org Fix heap-buffer-overflow in pglz_decompress() on corrupt input. When decoding a match tag, pglz_decompress() reads 2 bytes (or 3 for extended-length matches) from the source buffer before checking whether enough data remains. The existing bounds check (sp > srcend) occurs after the reads, so truncated compressed data that ends mid-tag causes a read past the allocated buffer. Fix by validating that sufficient source bytes are available before reading each part of the match tag. The post-read sp > srcend check is no longer needed and is removed. Found by fuzz testing with libFuzzer and AddressSanitizer. Backpatch-through: 14 Branch ------ REL_17_STABLE Details ------- https://git.postgresql.org/pg/commitdiff/c05c3baf169f353914ed34fcabd057be1d25f9b4 Modified Files -------------- src/common/pg_lzcompress.c | 27 +++++++++++++++++++-------- 1 file changed, 19 insertions(+), 8 deletions(-) ^ permalink raw reply [nested|flat] 6+ messages in thread
* pgsql: Fix heap-buffer-overflow in pglz_decompress() on corrupt input. @ 2026-04-10 14:39 Andrew Dunstan <andrew@dunslane.net> 0 siblings, 0 replies; 6+ messages in thread From: Andrew Dunstan @ 2026-04-10 14:39 UTC (permalink / raw) To: pgsql-committers@lists.postgresql.org Fix heap-buffer-overflow in pglz_decompress() on corrupt input. When decoding a match tag, pglz_decompress() reads 2 bytes (or 3 for extended-length matches) from the source buffer before checking whether enough data remains. The existing bounds check (sp > srcend) occurs after the reads, so truncated compressed data that ends mid-tag causes a read past the allocated buffer. Fix by validating that sufficient source bytes are available before reading each part of the match tag. The post-read sp > srcend check is no longer needed and is removed. Found by fuzz testing with libFuzzer and AddressSanitizer. Backpatch-through: 14 Branch ------ REL_16_STABLE Details ------- https://git.postgresql.org/pg/commitdiff/e630f65d03047ccab67ebb0e20faa7f3f24b526b Modified Files -------------- src/common/pg_lzcompress.c | 27 +++++++++++++++++++-------- 1 file changed, 19 insertions(+), 8 deletions(-) ^ permalink raw reply [nested|flat] 6+ messages in thread
* pgsql: Fix heap-buffer-overflow in pglz_decompress() on corrupt input. @ 2026-04-10 14:39 Andrew Dunstan <andrew@dunslane.net> 0 siblings, 0 replies; 6+ messages in thread From: Andrew Dunstan @ 2026-04-10 14:39 UTC (permalink / raw) To: pgsql-committers@lists.postgresql.org Fix heap-buffer-overflow in pglz_decompress() on corrupt input. When decoding a match tag, pglz_decompress() reads 2 bytes (or 3 for extended-length matches) from the source buffer before checking whether enough data remains. The existing bounds check (sp > srcend) occurs after the reads, so truncated compressed data that ends mid-tag causes a read past the allocated buffer. Fix by validating that sufficient source bytes are available before reading each part of the match tag. The post-read sp > srcend check is no longer needed and is removed. Found by fuzz testing with libFuzzer and AddressSanitizer. Backpatch-through: 14 Branch ------ REL_15_STABLE Details ------- https://git.postgresql.org/pg/commitdiff/c88ad3a2122eae875b77eb5cba3b7bda5c92f251 Modified Files -------------- src/common/pg_lzcompress.c | 27 +++++++++++++++++++-------- 1 file changed, 19 insertions(+), 8 deletions(-) ^ permalink raw reply [nested|flat] 6+ messages in thread
* pgsql: Fix heap-buffer-overflow in pglz_decompress() on corrupt input. @ 2026-04-10 14:39 Andrew Dunstan <andrew@dunslane.net> 0 siblings, 0 replies; 6+ messages in thread From: Andrew Dunstan @ 2026-04-10 14:39 UTC (permalink / raw) To: pgsql-committers@lists.postgresql.org Fix heap-buffer-overflow in pglz_decompress() on corrupt input. When decoding a match tag, pglz_decompress() reads 2 bytes (or 3 for extended-length matches) from the source buffer before checking whether enough data remains. The existing bounds check (sp > srcend) occurs after the reads, so truncated compressed data that ends mid-tag causes a read past the allocated buffer. Fix by validating that sufficient source bytes are available before reading each part of the match tag. The post-read sp > srcend check is no longer needed and is removed. Found by fuzz testing with libFuzzer and AddressSanitizer. Backpatch-through: 14 Branch ------ REL_14_STABLE Details ------- https://git.postgresql.org/pg/commitdiff/de32a01e7bb905b455d1a001b011433bd41dfb6a Modified Files -------------- src/common/pg_lzcompress.c | 27 +++++++++++++++++++-------- 1 file changed, 19 insertions(+), 8 deletions(-) ^ permalink raw reply [nested|flat] 6+ messages in thread
end of thread, other threads:[~2026-04-10 14:39 UTC | newest] Thread overview: 6+ messages (download: mbox mbox.gz follow: Atom feed) -- links below jump to the message on this page -- 2026-04-10 13:32 pgsql: Fix heap-buffer-overflow in pglz_decompress() on corrupt input. Andrew Dunstan <andrew@dunslane.net> 2026-04-10 14:39 pgsql: Fix heap-buffer-overflow in pglz_decompress() on corrupt input. Andrew Dunstan <andrew@dunslane.net> 2026-04-10 14:39 pgsql: Fix heap-buffer-overflow in pglz_decompress() on corrupt input. Andrew Dunstan <andrew@dunslane.net> 2026-04-10 14:39 pgsql: Fix heap-buffer-overflow in pglz_decompress() on corrupt input. Andrew Dunstan <andrew@dunslane.net> 2026-04-10 14:39 pgsql: Fix heap-buffer-overflow in pglz_decompress() on corrupt input. Andrew Dunstan <andrew@dunslane.net> 2026-04-10 14:39 pgsql: Fix heap-buffer-overflow in pglz_decompress() on corrupt input. Andrew Dunstan <andrew@dunslane.net>
This inbox is served by agora; see mirroring instructions for how to clone and mirror all data and code used for this inbox