agora inbox for pgsql-committers@postgresql.org  
help / color / mirror / Atom feed
pgsql: Fix heap-buffer-overflow in pglz_decompress() on corrupt input.
6+ messages / 1 participants
[nested] [flat]

* pgsql: Fix heap-buffer-overflow in pglz_decompress() on corrupt input.
@ 2026-04-10 13:32 Andrew Dunstan <andrew@dunslane.net>
  0 siblings, 0 replies; 6+ messages in thread

From: Andrew Dunstan @ 2026-04-10 13:32 UTC (permalink / raw)
  To: pgsql-committers@lists.postgresql.org

Fix heap-buffer-overflow in pglz_decompress() on corrupt input.

When decoding a match tag, pglz_decompress() reads 2 bytes (or 3
for extended-length matches) from the source buffer before checking
whether enough data remains.  The existing bounds check (sp > srcend)
occurs after the reads, so truncated compressed data that ends
mid-tag causes a read past the allocated buffer.

Fix by validating that sufficient source bytes are available before
reading each part of the match tag.  The post-read sp > srcend
check is no longer needed and is removed.

Found by fuzz testing with libFuzzer and AddressSanitizer.

Branch
------
master

Details
-------
https://git.postgresql.org/pg/commitdiff/2b5ba2a0a141f621f61cb732d776dc78269f879b

Modified Files
--------------
src/common/pg_lzcompress.c | 27 +++++++++++++++++++--------
1 file changed, 19 insertions(+), 8 deletions(-)



^ permalink  raw  reply  [nested|flat] 6+ messages in thread

* pgsql: Fix heap-buffer-overflow in pglz_decompress() on corrupt input.
@ 2026-04-10 14:39 Andrew Dunstan <andrew@dunslane.net>
  0 siblings, 0 replies; 6+ messages in thread

From: Andrew Dunstan @ 2026-04-10 14:39 UTC (permalink / raw)
  To: pgsql-committers@lists.postgresql.org

Fix heap-buffer-overflow in pglz_decompress() on corrupt input.

When decoding a match tag, pglz_decompress() reads 2 bytes (or 3
for extended-length matches) from the source buffer before checking
whether enough data remains.  The existing bounds check (sp > srcend)
occurs after the reads, so truncated compressed data that ends
mid-tag causes a read past the allocated buffer.

Fix by validating that sufficient source bytes are available before
reading each part of the match tag.  The post-read sp > srcend
check is no longer needed and is removed.

Found by fuzz testing with libFuzzer and AddressSanitizer.

Backpatch-through: 14

Branch
------
REL_18_STABLE

Details
-------
https://git.postgresql.org/pg/commitdiff/c3e436b1cb6090195f843daacd83b59258e1bcac

Modified Files
--------------
src/common/pg_lzcompress.c | 27 +++++++++++++++++++--------
1 file changed, 19 insertions(+), 8 deletions(-)



^ permalink  raw  reply  [nested|flat] 6+ messages in thread

* pgsql: Fix heap-buffer-overflow in pglz_decompress() on corrupt input.
@ 2026-04-10 14:39 Andrew Dunstan <andrew@dunslane.net>
  0 siblings, 0 replies; 6+ messages in thread

From: Andrew Dunstan @ 2026-04-10 14:39 UTC (permalink / raw)
  To: pgsql-committers@lists.postgresql.org

Fix heap-buffer-overflow in pglz_decompress() on corrupt input.

When decoding a match tag, pglz_decompress() reads 2 bytes (or 3
for extended-length matches) from the source buffer before checking
whether enough data remains.  The existing bounds check (sp > srcend)
occurs after the reads, so truncated compressed data that ends
mid-tag causes a read past the allocated buffer.

Fix by validating that sufficient source bytes are available before
reading each part of the match tag.  The post-read sp > srcend
check is no longer needed and is removed.

Found by fuzz testing with libFuzzer and AddressSanitizer.

Backpatch-through: 14

Branch
------
REL_17_STABLE

Details
-------
https://git.postgresql.org/pg/commitdiff/c05c3baf169f353914ed34fcabd057be1d25f9b4

Modified Files
--------------
src/common/pg_lzcompress.c | 27 +++++++++++++++++++--------
1 file changed, 19 insertions(+), 8 deletions(-)



^ permalink  raw  reply  [nested|flat] 6+ messages in thread

* pgsql: Fix heap-buffer-overflow in pglz_decompress() on corrupt input.
@ 2026-04-10 14:39 Andrew Dunstan <andrew@dunslane.net>
  0 siblings, 0 replies; 6+ messages in thread

From: Andrew Dunstan @ 2026-04-10 14:39 UTC (permalink / raw)
  To: pgsql-committers@lists.postgresql.org

Fix heap-buffer-overflow in pglz_decompress() on corrupt input.

When decoding a match tag, pglz_decompress() reads 2 bytes (or 3
for extended-length matches) from the source buffer before checking
whether enough data remains.  The existing bounds check (sp > srcend)
occurs after the reads, so truncated compressed data that ends
mid-tag causes a read past the allocated buffer.

Fix by validating that sufficient source bytes are available before
reading each part of the match tag.  The post-read sp > srcend
check is no longer needed and is removed.

Found by fuzz testing with libFuzzer and AddressSanitizer.

Backpatch-through: 14

Branch
------
REL_16_STABLE

Details
-------
https://git.postgresql.org/pg/commitdiff/e630f65d03047ccab67ebb0e20faa7f3f24b526b

Modified Files
--------------
src/common/pg_lzcompress.c | 27 +++++++++++++++++++--------
1 file changed, 19 insertions(+), 8 deletions(-)



^ permalink  raw  reply  [nested|flat] 6+ messages in thread

* pgsql: Fix heap-buffer-overflow in pglz_decompress() on corrupt input.
@ 2026-04-10 14:39 Andrew Dunstan <andrew@dunslane.net>
  0 siblings, 0 replies; 6+ messages in thread

From: Andrew Dunstan @ 2026-04-10 14:39 UTC (permalink / raw)
  To: pgsql-committers@lists.postgresql.org

Fix heap-buffer-overflow in pglz_decompress() on corrupt input.

When decoding a match tag, pglz_decompress() reads 2 bytes (or 3
for extended-length matches) from the source buffer before checking
whether enough data remains.  The existing bounds check (sp > srcend)
occurs after the reads, so truncated compressed data that ends
mid-tag causes a read past the allocated buffer.

Fix by validating that sufficient source bytes are available before
reading each part of the match tag.  The post-read sp > srcend
check is no longer needed and is removed.

Found by fuzz testing with libFuzzer and AddressSanitizer.

Backpatch-through: 14

Branch
------
REL_15_STABLE

Details
-------
https://git.postgresql.org/pg/commitdiff/c88ad3a2122eae875b77eb5cba3b7bda5c92f251

Modified Files
--------------
src/common/pg_lzcompress.c | 27 +++++++++++++++++++--------
1 file changed, 19 insertions(+), 8 deletions(-)



^ permalink  raw  reply  [nested|flat] 6+ messages in thread

* pgsql: Fix heap-buffer-overflow in pglz_decompress() on corrupt input.
@ 2026-04-10 14:39 Andrew Dunstan <andrew@dunslane.net>
  0 siblings, 0 replies; 6+ messages in thread

From: Andrew Dunstan @ 2026-04-10 14:39 UTC (permalink / raw)
  To: pgsql-committers@lists.postgresql.org

Fix heap-buffer-overflow in pglz_decompress() on corrupt input.

When decoding a match tag, pglz_decompress() reads 2 bytes (or 3
for extended-length matches) from the source buffer before checking
whether enough data remains.  The existing bounds check (sp > srcend)
occurs after the reads, so truncated compressed data that ends
mid-tag causes a read past the allocated buffer.

Fix by validating that sufficient source bytes are available before
reading each part of the match tag.  The post-read sp > srcend
check is no longer needed and is removed.

Found by fuzz testing with libFuzzer and AddressSanitizer.

Backpatch-through: 14

Branch
------
REL_14_STABLE

Details
-------
https://git.postgresql.org/pg/commitdiff/de32a01e7bb905b455d1a001b011433bd41dfb6a

Modified Files
--------------
src/common/pg_lzcompress.c | 27 +++++++++++++++++++--------
1 file changed, 19 insertions(+), 8 deletions(-)



^ permalink  raw  reply  [nested|flat] 6+ messages in thread


end of thread, other threads:[~2026-04-10 14:39 UTC | newest]

Thread overview: 6+ messages (download: mbox mbox.gz follow: Atom feed)
-- links below jump to the message on this page --
2026-04-10 13:32 pgsql: Fix heap-buffer-overflow in pglz_decompress() on corrupt input. Andrew Dunstan <andrew@dunslane.net>
2026-04-10 14:39 pgsql: Fix heap-buffer-overflow in pglz_decompress() on corrupt input. Andrew Dunstan <andrew@dunslane.net>
2026-04-10 14:39 pgsql: Fix heap-buffer-overflow in pglz_decompress() on corrupt input. Andrew Dunstan <andrew@dunslane.net>
2026-04-10 14:39 pgsql: Fix heap-buffer-overflow in pglz_decompress() on corrupt input. Andrew Dunstan <andrew@dunslane.net>
2026-04-10 14:39 pgsql: Fix heap-buffer-overflow in pglz_decompress() on corrupt input. Andrew Dunstan <andrew@dunslane.net>
2026-04-10 14:39 pgsql: Fix heap-buffer-overflow in pglz_decompress() on corrupt input. Andrew Dunstan <andrew@dunslane.net>

This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox