agora inbox for pgsql-committers@postgresql.org  
help / color / mirror / Atom feed
From: Etsuro Fujita <efujita@postgresql.org>
To: pgsql-committers@lists.postgresql.org
Subject: pgsql: Fix privilege handling in postgres_fdw statistics import.
Date: Sat, 26 Sep 2026 11:36:38 +0000
Message-ID: <E1xAQhq-00000001LHk-3Bv7@gemulon.postgresql.org> (raw)

Fix privilege handling in postgres_fdw statistics import.

When ANALYZE imports statistics from a remote server, it fetched/stored
the statistics while still running as the user executing ANALYZE, not as
the foreign table's owner.  This is inconsistent with the sampling path,
and it causes a security issue: a role that owns a foreign table but has
no access to the underlying remote data (eg, no access privileges on the
remote server) could obtain that data by having a privileged user run
ANALYZE on the table; the imported statistics like most_common_vals then
expose sampled values from the remote data, as shown in the reproducer
on the discussion thread.

To fix, switch to the foreign table owner's userid in analyze_rel()
before calling the ImportForeignStatistics() routine, mirroring the
identity used by the sampling path.   This not only makes the privilege
handling consistent between the sampling/import paths, but also prevents
statistics import from disclosing data the table owner couldn't
otherwise obtain.

Oversight in commit 28972b6fc.

Reported-by: Fujii Masao <masao.fujii@gmail.com>
Reported-by: Osama Abdul Qader <osamaabdulqader.cs@gmail.com>
Reported-by: Noah Misch <noah@leadboat.com>
Author: Noah Misch <noah@leadboat.com>
Reviewed-by: Matheus Alcantara <matheusssilv97@gmail.com>
Reviewed-by: Etsuro Fujita <etsuro.fujita@gmail.com>
Discussion: https://postgr.es/m/CAPmGK16jVk+i2KMkkgR9ajoPdaUAinvcspkk5Bc6urbo2xYTMQ@mail.gmail.com
Backpatch-through: 19

Branch
------
master

Details
-------
https://git.postgresql.org/pg/commitdiff/7d47e41238004b6b8bce076d4bb76d858257b58d

Modified Files
--------------
contrib/postgres_fdw/postgres_fdw.c |  9 ++++-----
src/backend/commands/analyze.c      | 30 ++++++++++++++++++++++++++----
2 files changed, 30 insertions(+), 9 deletions(-)



view thread (2+ messages)  latest in thread

Message-ID: <E1xAQhq-00000001LHk-3Bv7@gemulon.postgresql.org>
Permalink:  ../E1xAQhq-00000001LHk-3Bv7@gemulon.postgresql.org/
Also on:    postgresql.org/message-id/E1xAQhq-00000001LHk-3Bv7@gemulon.postgresql.org

reply

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Reply to all the recipients using the --to and --cc options:
  reply via email

  To: pgsql-committers@postgresql.org
  Cc: efujita@postgresql.org, pgsql-committers@lists.postgresql.org
  Subject: Re: pgsql: Fix privilege handling in postgres_fdw statistics import.
  In-Reply-To: <E1xAQhq-00000001LHk-3Bv7@gemulon.postgresql.org>

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox