github pganalyze/libpg_query 17-6.2.4

latest releases: 18.1.0, 17-6.2.5
3 hours ago
  • Security fix: Heap out-of-bounds write and read in pg_query_normalize (GHSA-6ggm-xmc9-8ffg)
    • When normalizing certain utility statements (e.g. DO ... LANGUAGE, statements with
      string options, or CREATE/ALTER SUBSCRIPTION ... CONNECTION), pg_query_normalize
      searched the query text for the location of string constants, which could yield
      wrong locations for crafted input. This could cause out-of-bounds writes and reads
      on the heap, leaking process memory in the normalized output or crashing the process.
    • Constant locations are now recorded by the parser instead, and the normalizer checks
      at runtime that constant locations never overlap
    • This adds new location fields to the parse tree output (DefElem.arg_location,
      NotifyStmt.payload_location, CreateSubscriptionStmt.conninfo_location and
      AlterSubscriptionStmt.conninfo_location). Like other location fields, these are
      ignored for fingerprinting.
    • Applications that normalize untrusted query text should upgrade
    • Reported by Paul Gerste (Cure53)
  • Deparser: Add strict checking for unexpected pointer values
    • This ensures that a bad input parse tree doesn't cause the deparser to crash, and
      instead returns an error
    • Use cases that do not work with user input can define PG_QUERY_DEPARSE_NO_STRICT_CHECKS
      to turn off the most detailed checks, for slightly better performance
    • Reported by Paul Gerste (Cure53)
  • pg_query_normalize:
    • Add support for NOTIFY statements #340
    • Avoid undefined behaviour for overly large parameter references #346
% shasum -a 256 libpg_query-17-6.2.4* 
47e782f6d8277962396d9a020db576fecf3d77f4de3cd224be258f910342d907  libpg_query-17-6.2.4.tar.gz
85254e378e54e901fb7f6887df584a88213c33b3dd9f1ba422ce423297a81bb2  libpg_query-17-6.2.4.zip

Don't miss a new libpg_query release

NewReleases is sending notifications on new releases.