agora inbox for pgsql-committers@postgresql.orghelp / color / mirror / Atom feed
pgsql: Fix privilege handling in postgres_fdw statistics import. 2+ messages / 1 participants [nested] [flat]
* pgsql: Fix privilege handling in postgres_fdw statistics import. @ 2026-09-26 11:36 Etsuro Fujita <efujita@postgresql.org> 0 siblings, 0 replies; 2+ messages in thread From: Etsuro Fujita @ 2026-09-26 11:36 UTC (permalink / raw) To: pgsql-committers@lists.postgresql.org Fix privilege handling in postgres_fdw statistics import. When ANALYZE imports statistics from a remote server, it fetched/stored the statistics while still running as the user executing ANALYZE, not as the foreign table's owner. This is inconsistent with the sampling path, and it causes a security issue: a role that owns a foreign table but has no access to the underlying remote data (eg, no access privileges on the remote server) could obtain that data by having a privileged user run ANALYZE on the table; the imported statistics like most_common_vals then expose sampled values from the remote data, as shown in the reproducer on the discussion thread. To fix, switch to the foreign table owner's userid in analyze_rel() before calling the ImportForeignStatistics() routine, mirroring the identity used by the sampling path. This not only makes the privilege handling consistent between the sampling/import paths, but also prevents statistics import from disclosing data the table owner couldn't otherwise obtain. Oversight in commit 28972b6fc. Reported-by: Fujii Masao <masao.fujii@gmail.com> Reported-by: Osama Abdul Qader <osamaabdulqader.cs@gmail.com> Reported-by: Noah Misch <noah@leadboat.com> Author: Noah Misch <noah@leadboat.com> Reviewed-by: Matheus Alcantara <matheusssilv97@gmail.com> Reviewed-by: Etsuro Fujita <etsuro.fujita@gmail.com> Discussion: https://postgr.es/m/CAPmGK16jVk+i2KMkkgR9ajoPdaUAinvcspkk5Bc6urbo2xYTMQ@mail.gmail.com Backpatch-through: 19 Branch ------ master Details ------- https://git.postgresql.org/pg/commitdiff/7d47e41238004b6b8bce076d4bb76d858257b58d Modified Files -------------- contrib/postgres_fdw/postgres_fdw.c | 9 ++++----- src/backend/commands/analyze.c | 30 ++++++++++++++++++++++++++---- 2 files changed, 30 insertions(+), 9 deletions(-) ^ permalink raw reply [nested|flat] 2+ messages in thread
* pgsql: Fix privilege handling in postgres_fdw statistics import. @ 2026-09-26 11:36 Etsuro Fujita <efujita@postgresql.org> 0 siblings, 0 replies; 2+ messages in thread From: Etsuro Fujita @ 2026-09-26 11:36 UTC (permalink / raw) To: pgsql-committers@lists.postgresql.org Fix privilege handling in postgres_fdw statistics import. When ANALYZE imports statistics from a remote server, it fetched/stored the statistics while still running as the user executing ANALYZE, not as the foreign table's owner. This is inconsistent with the sampling path, and it causes a security issue: a role that owns a foreign table but has no access to the underlying remote data (eg, no access privileges on the remote server) could obtain that data by having a privileged user run ANALYZE on the table; the imported statistics like most_common_vals then expose sampled values from the remote data, as shown in the reproducer on the discussion thread. To fix, switch to the foreign table owner's userid in analyze_rel() before calling the ImportForeignStatistics() routine, mirroring the identity used by the sampling path. This not only makes the privilege handling consistent between the sampling/import paths, but also prevents statistics import from disclosing data the table owner couldn't otherwise obtain. Oversight in commit 28972b6fc. Reported-by: Fujii Masao <masao.fujii@gmail.com> Reported-by: Osama Abdul Qader <osamaabdulqader.cs@gmail.com> Reported-by: Noah Misch <noah@leadboat.com> Author: Noah Misch <noah@leadboat.com> Reviewed-by: Matheus Alcantara <matheusssilv97@gmail.com> Reviewed-by: Etsuro Fujita <etsuro.fujita@gmail.com> Discussion: https://postgr.es/m/CAPmGK16jVk+i2KMkkgR9ajoPdaUAinvcspkk5Bc6urbo2xYTMQ@mail.gmail.com Backpatch-through: 19 Branch ------ REL_19_STABLE Details ------- https://git.postgresql.org/pg/commitdiff/18c04668f781715614527aa85210026df2e49ed5 Modified Files -------------- contrib/postgres_fdw/postgres_fdw.c | 9 ++++----- src/backend/commands/analyze.c | 30 ++++++++++++++++++++++++++---- 2 files changed, 30 insertions(+), 9 deletions(-) ^ permalink raw reply [nested|flat] 2+ messages in thread
end of thread, other threads:[~2026-09-26 11:36 UTC | newest] Thread overview: 2+ messages (download: mbox mbox.gz follow: Atom feed) -- links below jump to the message on this page -- 2026-09-26 11:36 pgsql: Fix privilege handling in postgres_fdw statistics import. Etsuro Fujita <efujita@postgresql.org> 2026-09-26 11:36 pgsql: Fix privilege handling in postgres_fdw statistics import. Etsuro Fujita <efujita@postgresql.org>
This inbox is served by agora; see mirroring instructions for how to clone and mirror all data and code used for this inbox