agora inbox for pgsql-committers@postgresql.org  
help / color / mirror / Atom feed
From: Noah Misch <noah@leadboat.com>
To: pgsql-committers@lists.postgresql.org
Subject: pgsql: Guard against unsafe conditions in usage of pg_strftime().
Date: Mon, 11 May 2026 12:19:38 +0000
Message-ID: <E1wMPbm-0002Xx-1i@gemulon.postgresql.org> (raw)

Guard against unsafe conditions in usage of pg_strftime().

Although pg_strftime() has defined error conditions, no callers bother
to check for errors.  This is problematic because the output string is
very likely not null-terminated if an error occurs, so that blindly
using it is unsafe.  Rather than trusting that we can find and fix all
the callers, let's alter the function's API spec slightly: make it
guarantee a null-terminated result so long as maxsize > 0.

Furthermore, if we do get an error, let's make that null-terminated
result be an empty string.  We could instead truncate at the buffer
length, but that risks producing mis-encoded output if the tz_name
string contains multibyte characters.  It doesn't seem reasonable for
src/timezone/ to make use of our encoding-aware truncation logic.
Also, the only really likely source of a failure is a user-supplied
timezone name that is intentionally trying to overrun our buffers.
I don't feel a need to be particularly friendly about that case.

Author: Tom Lane <tgl@sss.pgh.pa.us>
Reviewed-by: John Naylor <johncnaylorls@gmail.com>
Backpatch-through: 14
Security: CVE-2026-6474

Branch
------
REL_17_STABLE

Details
-------
https://git.postgresql.org/pg/commitdiff/a386d14feb210cd9c6c9b68cd8782e089f4d5b62
Author: Tom Lane <tgl@sss.pgh.pa.us>

Modified Files
--------------
src/timezone/strftime.c | 11 +++++++++++
1 file changed, 11 insertions(+)



view thread (6+ messages)  latest in thread

Message-ID: <E1wMPbm-0002Xx-1i@gemulon.postgresql.org>
Permalink:  ../E1wMPbm-0002Xx-1i@gemulon.postgresql.org/
Also on:    postgresql.org/message-id/E1wMPbm-0002Xx-1i@gemulon.postgresql.org

reply

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Reply to all the recipients using the --to and --cc options:
  reply via email

  To: pgsql-committers@postgresql.org
  Cc: noah@leadboat.com, pgsql-committers@lists.postgresql.org
  Subject: Re: pgsql: Guard against unsafe conditions in usage of pg_strftime().
  In-Reply-To: <E1wMPbm-0002Xx-1i@gemulon.postgresql.org>

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox