pgsql: Harden PL/Perl code against "tied" Perl arrays and hashes.

Поиск
Список
Период
Сортировка
Искать
От
Noah Misch
Тема
pgsql: Harden PL/Perl code against "tied" Perl arrays and hashes.
Дата
в 16:41:27
Msg-id
E1wtQFr-00000000yC2-05Re@gemulon.postgresql.org
Список
Harden PL/Perl code against "tied" Perl arrays and hashes.

Tied arrays might report different sizes each time they are inspected.
To avoid generating a corrupt result array, fix plperl_array_to_datum()
to read av_len() of each input array only once.  If the input does
appear to get shorter, we'll fill nulls for the now-missing entries,
which seems fine.  Conversely, if it gets longer, we'll ignore the new
entries.

plperl_to_hstore() assumed that Perl's hv_iterinit() returns the
number of entries in the given Perl hash.  Usually that's true,
but per the Perl docs, "the return value is currently only meaningful
for hashes without tie magic".  That could potentially end in a memory
stomp.  We don't depend on that result value anywhere else, so don't
do so here either.

Reported-by: Hcamael 
Author: Tom Lane 
Reviewed-by: Andrew Dunstan 
Backpatch-through: 14
Security: CVE-2026-14670

Branch
------
REL_17_STABLE

Details
-------
https://git.postgresql.org/pg/commitdiff/2d78c34f8257d00f5fc65b8092c43dc77e246939
Author: Tom Lane 

Modified Files
--------------
contrib/hstore_plperl/hstore_plperl.c | 11 +++++++++--
src/pl/plperl/plperl.c                |  6 +++++-
2 files changed, 14 insertions(+), 3 deletions(-)

В списке pgsql-committers по дате отправления
От: Noah Misch
Дата:
От: Noah Misch
Дата:
FAQ