agora inbox for pgsql-committers@postgresql.org  
help / color / mirror / Atom feed
pgsql: Guard against overly-long numeric formatting symbols from locale
6+ messages / 1 participants
[nested] [flat]

* pgsql: Guard against overly-long numeric formatting symbols from locale
@ 2026-04-22 16:41  Tom Lane <tgl@sss.pgh.pa.us>
  0 siblings, 0 replies; 6+ messages in thread

From: Tom Lane @ 2026-04-22 16:41 UTC (permalink / raw)
  To: pgsql-committers@lists.postgresql.org

Guard against overly-long numeric formatting symbols from locale.

to_char() allocates its output buffer with 8 bytes per formatting
code in the pattern.  If the locale's currency symbol, thousands
separator, or decimal or sign symbol is more than 8 bytes long,
in principle we could overrun the output buffer.  No such locales
exist in the real world, so it seems sufficient to truncate the
symbol if we do see it's too long.

Reported-by: Xint Code
Author: Tom Lane <tgl@sss.pgh.pa.us>
Discussion: https://postgr.es/m/638232.1776790821@sss.pgh.pa.us
Backpatch-through: 14

Branch
------
REL_16_STABLE

Details
-------
https://git.postgresql.org/pg/commitdiff/e1e60f148a3aa937f1bf92dd50bb4b24051fd0e2

Modified Files
--------------
src/backend/utils/adt/formatting.c | 61 +++++++++++++++++++++++++++-----------
1 file changed, 43 insertions(+), 18 deletions(-)



^ permalink  raw  reply  [nested|flat] 6+ messages in thread

* pgsql: Guard against overly-long numeric formatting symbols from locale
@ 2026-04-22 16:41  Tom Lane <tgl@sss.pgh.pa.us>
  0 siblings, 0 replies; 6+ messages in thread

From: Tom Lane @ 2026-04-22 16:41 UTC (permalink / raw)
  To: pgsql-committers@lists.postgresql.org

Guard against overly-long numeric formatting symbols from locale.

to_char() allocates its output buffer with 8 bytes per formatting
code in the pattern.  If the locale's currency symbol, thousands
separator, or decimal or sign symbol is more than 8 bytes long,
in principle we could overrun the output buffer.  No such locales
exist in the real world, so it seems sufficient to truncate the
symbol if we do see it's too long.

Reported-by: Xint Code
Author: Tom Lane <tgl@sss.pgh.pa.us>
Discussion: https://postgr.es/m/638232.1776790821@sss.pgh.pa.us
Backpatch-through: 14

Branch
------
REL_18_STABLE

Details
-------
https://git.postgresql.org/pg/commitdiff/580e7be88ce2b5d15df83da6496b3f23a81e3163

Modified Files
--------------
src/backend/utils/adt/formatting.c | 61 +++++++++++++++++++++++++++-----------
1 file changed, 43 insertions(+), 18 deletions(-)



^ permalink  raw  reply  [nested|flat] 6+ messages in thread

* pgsql: Guard against overly-long numeric formatting symbols from locale
@ 2026-04-22 16:41  Tom Lane <tgl@sss.pgh.pa.us>
  0 siblings, 0 replies; 6+ messages in thread

From: Tom Lane @ 2026-04-22 16:41 UTC (permalink / raw)
  To: pgsql-committers@lists.postgresql.org

Guard against overly-long numeric formatting symbols from locale.

to_char() allocates its output buffer with 8 bytes per formatting
code in the pattern.  If the locale's currency symbol, thousands
separator, or decimal or sign symbol is more than 8 bytes long,
in principle we could overrun the output buffer.  No such locales
exist in the real world, so it seems sufficient to truncate the
symbol if we do see it's too long.

Reported-by: Xint Code
Author: Tom Lane <tgl@sss.pgh.pa.us>
Discussion: https://postgr.es/m/638232.1776790821@sss.pgh.pa.us
Backpatch-through: 14

Branch
------
REL_15_STABLE

Details
-------
https://git.postgresql.org/pg/commitdiff/f60d25986288f453360cb5d1902945d9417d0da0

Modified Files
--------------
src/backend/utils/adt/formatting.c | 61 +++++++++++++++++++++++++++-----------
1 file changed, 43 insertions(+), 18 deletions(-)



^ permalink  raw  reply  [nested|flat] 6+ messages in thread

* pgsql: Guard against overly-long numeric formatting symbols from locale
@ 2026-04-22 16:41  Tom Lane <tgl@sss.pgh.pa.us>
  0 siblings, 0 replies; 6+ messages in thread

From: Tom Lane @ 2026-04-22 16:41 UTC (permalink / raw)
  To: pgsql-committers@lists.postgresql.org

Guard against overly-long numeric formatting symbols from locale.

to_char() allocates its output buffer with 8 bytes per formatting
code in the pattern.  If the locale's currency symbol, thousands
separator, or decimal or sign symbol is more than 8 bytes long,
in principle we could overrun the output buffer.  No such locales
exist in the real world, so it seems sufficient to truncate the
symbol if we do see it's too long.

Reported-by: Xint Code
Author: Tom Lane <tgl@sss.pgh.pa.us>
Discussion: https://postgr.es/m/638232.1776790821@sss.pgh.pa.us
Backpatch-through: 14

Branch
------
master

Details
-------
https://git.postgresql.org/pg/commitdiff/a50777680f6678bae39ffa04d01633bd023a5f48

Modified Files
--------------
src/backend/utils/adt/formatting.c | 61 +++++++++++++++++++++++++++-----------
1 file changed, 43 insertions(+), 18 deletions(-)



^ permalink  raw  reply  [nested|flat] 6+ messages in thread

* pgsql: Guard against overly-long numeric formatting symbols from locale
@ 2026-04-22 16:41  Tom Lane <tgl@sss.pgh.pa.us>
  0 siblings, 0 replies; 6+ messages in thread

From: Tom Lane @ 2026-04-22 16:41 UTC (permalink / raw)
  To: pgsql-committers@lists.postgresql.org

Guard against overly-long numeric formatting symbols from locale.

to_char() allocates its output buffer with 8 bytes per formatting
code in the pattern.  If the locale's currency symbol, thousands
separator, or decimal or sign symbol is more than 8 bytes long,
in principle we could overrun the output buffer.  No such locales
exist in the real world, so it seems sufficient to truncate the
symbol if we do see it's too long.

Reported-by: Xint Code
Author: Tom Lane <tgl@sss.pgh.pa.us>
Discussion: https://postgr.es/m/638232.1776790821@sss.pgh.pa.us
Backpatch-through: 14

Branch
------
REL_14_STABLE

Details
-------
https://git.postgresql.org/pg/commitdiff/8a6f08c0c7c3769ba32e302c95c7950179e5b87e

Modified Files
--------------
src/backend/utils/adt/formatting.c | 61 +++++++++++++++++++++++++++-----------
1 file changed, 43 insertions(+), 18 deletions(-)



^ permalink  raw  reply  [nested|flat] 6+ messages in thread

* pgsql: Guard against overly-long numeric formatting symbols from locale
@ 2026-04-22 16:41  Tom Lane <tgl@sss.pgh.pa.us>
  0 siblings, 0 replies; 6+ messages in thread

From: Tom Lane @ 2026-04-22 16:41 UTC (permalink / raw)
  To: pgsql-committers@lists.postgresql.org

Guard against overly-long numeric formatting symbols from locale.

to_char() allocates its output buffer with 8 bytes per formatting
code in the pattern.  If the locale's currency symbol, thousands
separator, or decimal or sign symbol is more than 8 bytes long,
in principle we could overrun the output buffer.  No such locales
exist in the real world, so it seems sufficient to truncate the
symbol if we do see it's too long.

Reported-by: Xint Code
Author: Tom Lane <tgl@sss.pgh.pa.us>
Discussion: https://postgr.es/m/638232.1776790821@sss.pgh.pa.us
Backpatch-through: 14

Branch
------
REL_17_STABLE

Details
-------
https://git.postgresql.org/pg/commitdiff/c97a2861851d3f92fb235ec80bd426b3f5a3d28c

Modified Files
--------------
src/backend/utils/adt/formatting.c | 61 +++++++++++++++++++++++++++-----------
1 file changed, 43 insertions(+), 18 deletions(-)



^ permalink  raw  reply  [nested|flat] 6+ messages in thread


end of thread, other threads:[~2026-04-22 16:41 UTC | newest]

Thread overview: 6+ messages (download: mbox mbox.gz follow: Atom feed)
-- links below jump to the message on this page --
2026-04-22 16:41 pgsql: Guard against overly-long numeric formatting symbols from locale Tom Lane <tgl@sss.pgh.pa.us>
2026-04-22 16:41 pgsql: Guard against overly-long numeric formatting symbols from locale Tom Lane <tgl@sss.pgh.pa.us>
2026-04-22 16:41 pgsql: Guard against overly-long numeric formatting symbols from locale Tom Lane <tgl@sss.pgh.pa.us>
2026-04-22 16:41 pgsql: Guard against overly-long numeric formatting symbols from locale Tom Lane <tgl@sss.pgh.pa.us>
2026-04-22 16:41 pgsql: Guard against overly-long numeric formatting symbols from locale Tom Lane <tgl@sss.pgh.pa.us>
2026-04-22 16:41 pgsql: Guard against overly-long numeric formatting symbols from locale Tom Lane <tgl@sss.pgh.pa.us>

This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox