pg.ddx.io pgsql-committers@postgresql.org mailing list archivehelp / color / mirror / Atom feed
pgsql: Make palloc_array() and friends safe against integer overflow. 6+ messages / 1 participants [nested] [flat]
* pgsql: Make palloc_array() and friends safe against integer overflow. @ 2026-05-11 12:19 Noah Misch <noah@leadboat.com> 0 siblings, 0 replies; 6+ messages in thread From: Noah Misch @ 2026-05-11 12:19 UTC (permalink / raw) To: pgsql-committers@lists.postgresql.org Make palloc_array() and friends safe against integer overflow. Sufficiently large "count" arguments could result in undetected overflow, causing the allocated memory chunk to be much smaller than what the caller will subsequently write into it. This is unlikely to be a hazard with 64-bit size_t but can sometimes happen on 32-bit builds, primarily where a function allocates workspace that's significantly larger than its input data. Rather than trying to patch the at-risk callers piecemeal, let's just redefine these macros so that they always check. To do that, move the longstanding add_size() and mul_size() functions into palloc.h and mcxt.c, and adjust them to not be specific to shared-memory allocation. Then invent palloc_mul(), palloc0_mul(), palloc_mul_extended() to use these functions. Actually, the latter use inlined copies to save one function call. repalloc_array() gets similar treatment. I didn't bother trying to inline the calls for repalloc0_array() though. In v14 and v15, this also adds repalloc_extended(), which previously was only available in v16 and up. We need copies of all this in fe_memutils.[hc] as well, since that module also provides palloc_array() etc. Reported-by: Xint Code Author: Tom Lane <tgl@sss.pgh.pa.us> Reviewed-by: Masahiko Sawada <sawada.mshk@gmail.com> Backpatch-through: 14 Security: CVE-2026-6473 Branch ------ master Details ------- https://git.postgresql.org/pg/commitdiff/46593aea0a5ca7ead0876833d99639c9a4bb5a9d Author: Tom Lane <tgl@sss.pgh.pa.us> Modified Files -------------- src/backend/storage/ipc/shmem.c | 31 ------- src/backend/utils/mmgr/mcxt.c | 129 +++++++++++++++++++++++++++ src/common/fe_memutils.c | 188 +++++++++++++++++++++++++++++++++++++++ src/include/common/fe_memutils.h | 28 ++++-- src/include/storage/shmem.h | 3 - src/include/utils/memutils.h | 2 +- src/include/utils/palloc.h | 22 ++++- 7 files changed, 358 insertions(+), 45 deletions(-) ^ permalink raw reply [nested|flat] 6+ messages in thread
* pgsql: Make palloc_array() and friends safe against integer overflow. @ 2026-05-11 12:19 Noah Misch <noah@leadboat.com> 0 siblings, 0 replies; 6+ messages in thread From: Noah Misch @ 2026-05-11 12:19 UTC (permalink / raw) To: pgsql-committers@lists.postgresql.org Make palloc_array() and friends safe against integer overflow. Sufficiently large "count" arguments could result in undetected overflow, causing the allocated memory chunk to be much smaller than what the caller will subsequently write into it. This is unlikely to be a hazard with 64-bit size_t but can sometimes happen on 32-bit builds, primarily where a function allocates workspace that's significantly larger than its input data. Rather than trying to patch the at-risk callers piecemeal, let's just redefine these macros so that they always check. To do that, move the longstanding add_size() and mul_size() functions into palloc.h and mcxt.c, and adjust them to not be specific to shared-memory allocation. Then invent palloc_mul(), palloc0_mul(), palloc_mul_extended() to use these functions. Actually, the latter use inlined copies to save one function call. repalloc_array() gets similar treatment. I didn't bother trying to inline the calls for repalloc0_array() though. In v14 and v15, this also adds repalloc_extended(), which previously was only available in v16 and up. We need copies of all this in fe_memutils.[hc] as well, since that module also provides palloc_array() etc. Reported-by: Xint Code Author: Tom Lane <tgl@sss.pgh.pa.us> Reviewed-by: Masahiko Sawada <sawada.mshk@gmail.com> Backpatch-through: 14 Security: CVE-2026-6473 Branch ------ REL_18_STABLE Details ------- https://git.postgresql.org/pg/commitdiff/e1c30458a10f769c10dc9cc38d4f577bb24b31a5 Author: Tom Lane <tgl@sss.pgh.pa.us> Modified Files -------------- src/backend/storage/ipc/shmem.c | 36 -------- src/backend/utils/mmgr/mcxt.c | 129 +++++++++++++++++++++++++++ src/common/fe_memutils.c | 188 +++++++++++++++++++++++++++++++++++++++ src/include/common/fe_memutils.h | 28 ++++-- src/include/storage/shmem.h | 2 - src/include/utils/memutils.h | 2 +- src/include/utils/palloc.h | 22 ++++- 7 files changed, 358 insertions(+), 49 deletions(-) ^ permalink raw reply [nested|flat] 6+ messages in thread
* pgsql: Make palloc_array() and friends safe against integer overflow. @ 2026-05-11 12:19 Noah Misch <noah@leadboat.com> 0 siblings, 0 replies; 6+ messages in thread From: Noah Misch @ 2026-05-11 12:19 UTC (permalink / raw) To: pgsql-committers@lists.postgresql.org Make palloc_array() and friends safe against integer overflow. Sufficiently large "count" arguments could result in undetected overflow, causing the allocated memory chunk to be much smaller than what the caller will subsequently write into it. This is unlikely to be a hazard with 64-bit size_t but can sometimes happen on 32-bit builds, primarily where a function allocates workspace that's significantly larger than its input data. Rather than trying to patch the at-risk callers piecemeal, let's just redefine these macros so that they always check. To do that, move the longstanding add_size() and mul_size() functions into palloc.h and mcxt.c, and adjust them to not be specific to shared-memory allocation. Then invent palloc_mul(), palloc0_mul(), palloc_mul_extended() to use these functions. Actually, the latter use inlined copies to save one function call. repalloc_array() gets similar treatment. I didn't bother trying to inline the calls for repalloc0_array() though. In v14 and v15, this also adds repalloc_extended(), which previously was only available in v16 and up. We need copies of all this in fe_memutils.[hc] as well, since that module also provides palloc_array() etc. Reported-by: Xint Code Author: Tom Lane <tgl@sss.pgh.pa.us> Reviewed-by: Masahiko Sawada <sawada.mshk@gmail.com> Backpatch-through: 14 Security: CVE-2026-6473 Branch ------ REL_17_STABLE Details ------- https://git.postgresql.org/pg/commitdiff/fe2720c450655a9986dd731a62e476ea3e1313b0 Author: Tom Lane <tgl@sss.pgh.pa.us> Modified Files -------------- src/backend/storage/ipc/shmem.c | 36 -------- src/backend/utils/mmgr/mcxt.c | 129 +++++++++++++++++++++++++++ src/common/fe_memutils.c | 188 +++++++++++++++++++++++++++++++++++++++ src/include/common/fe_memutils.h | 28 ++++-- src/include/storage/shmem.h | 2 - src/include/utils/memutils.h | 2 +- src/include/utils/palloc.h | 22 ++++- 7 files changed, 358 insertions(+), 49 deletions(-) ^ permalink raw reply [nested|flat] 6+ messages in thread
* pgsql: Make palloc_array() and friends safe against integer overflow. @ 2026-05-11 12:19 Noah Misch <noah@leadboat.com> 0 siblings, 0 replies; 6+ messages in thread From: Noah Misch @ 2026-05-11 12:19 UTC (permalink / raw) To: pgsql-committers@lists.postgresql.org Make palloc_array() and friends safe against integer overflow. Sufficiently large "count" arguments could result in undetected overflow, causing the allocated memory chunk to be much smaller than what the caller will subsequently write into it. This is unlikely to be a hazard with 64-bit size_t but can sometimes happen on 32-bit builds, primarily where a function allocates workspace that's significantly larger than its input data. Rather than trying to patch the at-risk callers piecemeal, let's just redefine these macros so that they always check. To do that, move the longstanding add_size() and mul_size() functions into palloc.h and mcxt.c, and adjust them to not be specific to shared-memory allocation. Then invent palloc_mul(), palloc0_mul(), palloc_mul_extended() to use these functions. Actually, the latter use inlined copies to save one function call. repalloc_array() gets similar treatment. I didn't bother trying to inline the calls for repalloc0_array() though. In v14 and v15, this also adds repalloc_extended(), which previously was only available in v16 and up. We need copies of all this in fe_memutils.[hc] as well, since that module also provides palloc_array() etc. Reported-by: Xint Code Author: Tom Lane <tgl@sss.pgh.pa.us> Reviewed-by: Masahiko Sawada <sawada.mshk@gmail.com> Backpatch-through: 14 Security: CVE-2026-6473 Branch ------ REL_16_STABLE Details ------- https://git.postgresql.org/pg/commitdiff/cfb610eaa02583fad12558af2eb36dab015cef02 Author: Tom Lane <tgl@sss.pgh.pa.us> Modified Files -------------- src/backend/storage/ipc/shmem.c | 36 -------- src/backend/utils/mmgr/mcxt.c | 129 +++++++++++++++++++++++++++ src/common/fe_memutils.c | 188 +++++++++++++++++++++++++++++++++++++++ src/include/common/fe_memutils.h | 28 ++++-- src/include/storage/shmem.h | 2 - src/include/utils/memutils.h | 2 +- src/include/utils/palloc.h | 22 ++++- 7 files changed, 358 insertions(+), 49 deletions(-) ^ permalink raw reply [nested|flat] 6+ messages in thread
* pgsql: Make palloc_array() and friends safe against integer overflow. @ 2026-05-11 12:19 Noah Misch <noah@leadboat.com> 0 siblings, 0 replies; 6+ messages in thread From: Noah Misch @ 2026-05-11 12:19 UTC (permalink / raw) To: pgsql-committers@lists.postgresql.org Make palloc_array() and friends safe against integer overflow. Sufficiently large "count" arguments could result in undetected overflow, causing the allocated memory chunk to be much smaller than what the caller will subsequently write into it. This is unlikely to be a hazard with 64-bit size_t but can sometimes happen on 32-bit builds, primarily where a function allocates workspace that's significantly larger than its input data. Rather than trying to patch the at-risk callers piecemeal, let's just redefine these macros so that they always check. To do that, move the longstanding add_size() and mul_size() functions into palloc.h and mcxt.c, and adjust them to not be specific to shared-memory allocation. Then invent palloc_mul(), palloc0_mul(), palloc_mul_extended() to use these functions. Actually, the latter use inlined copies to save one function call. repalloc_array() gets similar treatment. I didn't bother trying to inline the calls for repalloc0_array() though. In v14 and v15, this also adds repalloc_extended(), which previously was only available in v16 and up. We need copies of all this in fe_memutils.[hc] as well, since that module also provides palloc_array() etc. Reported-by: Xint Code Author: Tom Lane <tgl@sss.pgh.pa.us> Reviewed-by: Masahiko Sawada <sawada.mshk@gmail.com> Backpatch-through: 14 Security: CVE-2026-6473 Branch ------ REL_15_STABLE Details ------- https://git.postgresql.org/pg/commitdiff/bfc5cea76d25fa7d2a881699121a09eebc0d5ec6 Author: Tom Lane <tgl@sss.pgh.pa.us> Modified Files -------------- src/backend/storage/ipc/shmem.c | 36 ------- src/backend/utils/mmgr/mcxt.c | 196 ++++++++++++++++++++++++++++++++++----- src/common/fe_memutils.c | 188 +++++++++++++++++++++++++++++++++++++ src/include/common/fe_memutils.h | 28 ++++-- src/include/storage/shmem.h | 2 - src/include/utils/memutils.h | 1 + src/include/utils/palloc.h | 22 ++++- 7 files changed, 401 insertions(+), 72 deletions(-) ^ permalink raw reply [nested|flat] 6+ messages in thread
* pgsql: Make palloc_array() and friends safe against integer overflow. @ 2026-05-11 12:19 Noah Misch <noah@leadboat.com> 0 siblings, 0 replies; 6+ messages in thread From: Noah Misch @ 2026-05-11 12:19 UTC (permalink / raw) To: pgsql-committers@lists.postgresql.org Make palloc_array() and friends safe against integer overflow. Sufficiently large "count" arguments could result in undetected overflow, causing the allocated memory chunk to be much smaller than what the caller will subsequently write into it. This is unlikely to be a hazard with 64-bit size_t but can sometimes happen on 32-bit builds, primarily where a function allocates workspace that's significantly larger than its input data. Rather than trying to patch the at-risk callers piecemeal, let's just redefine these macros so that they always check. To do that, move the longstanding add_size() and mul_size() functions into palloc.h and mcxt.c, and adjust them to not be specific to shared-memory allocation. Then invent palloc_mul(), palloc0_mul(), palloc_mul_extended() to use these functions. Actually, the latter use inlined copies to save one function call. repalloc_array() gets similar treatment. I didn't bother trying to inline the calls for repalloc0_array() though. In v14 and v15, this also adds repalloc_extended(), which previously was only available in v16 and up. We need copies of all this in fe_memutils.[hc] as well, since that module also provides palloc_array() etc. Reported-by: Xint Code Author: Tom Lane <tgl@sss.pgh.pa.us> Reviewed-by: Masahiko Sawada <sawada.mshk@gmail.com> Backpatch-through: 14 Security: CVE-2026-6473 Branch ------ REL_14_STABLE Details ------- https://git.postgresql.org/pg/commitdiff/61a9b4b6e4f80725216b8234364acdaa7a72a1b1 Author: Tom Lane <tgl@sss.pgh.pa.us> Modified Files -------------- src/backend/storage/ipc/shmem.c | 36 ------- src/backend/utils/mmgr/mcxt.c | 196 ++++++++++++++++++++++++++++++++++----- src/common/fe_memutils.c | 188 +++++++++++++++++++++++++++++++++++++ src/include/common/fe_memutils.h | 28 ++++-- src/include/storage/shmem.h | 2 - src/include/utils/memutils.h | 1 + src/include/utils/palloc.h | 22 ++++- 7 files changed, 401 insertions(+), 72 deletions(-) ^ permalink raw reply [nested|flat] 6+ messages in thread
end of thread, other threads:[~2026-05-11 12:19 UTC | newest] Thread overview: 6+ messages (download: mbox mbox.gz follow: Atom feed) -- links below jump to the message on this page -- 2026-05-11 12:19 pgsql: Make palloc_array() and friends safe against integer overflow. Noah Misch <noah@leadboat.com> 2026-05-11 12:19 pgsql: Make palloc_array() and friends safe against integer overflow. Noah Misch <noah@leadboat.com> 2026-05-11 12:19 pgsql: Make palloc_array() and friends safe against integer overflow. Noah Misch <noah@leadboat.com> 2026-05-11 12:19 pgsql: Make palloc_array() and friends safe against integer overflow. Noah Misch <noah@leadboat.com> 2026-05-11 12:19 pgsql: Make palloc_array() and friends safe against integer overflow. Noah Misch <noah@leadboat.com> 2026-05-11 12:19 pgsql: Make palloc_array() and friends safe against integer overflow. Noah Misch <noah@leadboat.com>
This inbox is served by DDX for PostgreSQL; see mirroring instructions for how to clone and mirror all data and code used for this inbox