- Security fix: Heap out-of-bounds write and read in pg_query_normalize (GHSA-6ggm-xmc9-8ffg)
- When normalizing certain utility statements (e.g.
DO ... LANGUAGE, statements with
string options, orCREATE/ALTER SUBSCRIPTION ... CONNECTION), pg_query_normalize
searched the query text for the location of string constants, which could yield
wrong locations for crafted input. This could cause out-of-bounds writes and reads
on the heap, leaking process memory in the normalized output or crashing the process. - Constant locations are now recorded by the parser instead, and the normalizer checks
at runtime that constant locations never overlap - This adds new location fields to the parse tree output (
DefElem.arg_location,
NotifyStmt.payload_location,CreateSubscriptionStmt.conninfo_locationand
AlterSubscriptionStmt.conninfo_location). Like other location fields, these are
ignored for fingerprinting. - Applications that normalize untrusted query text should upgrade
- Reported by Paul Gerste (Cure53)
- When normalizing certain utility statements (e.g.
- Deparser: Add strict checking for unexpected pointer values
- This ensures that a bad input parse tree doesn't cause the deparser to crash, and
instead returns an error - Use cases that do not work with user input can define
PG_QUERY_DEPARSE_NO_STRICT_CHECKS
to turn off the most detailed checks, for slightly better performance - Reported by Paul Gerste (Cure53)
- This ensures that a bad input parse tree doesn't cause the deparser to crash, and
- pg_query_normalize:
% shasum -a 256 libpg_query-17-6.2.4*
47e782f6d8277962396d9a020db576fecf3d77f4de3cd224be258f910342d907 libpg_query-17-6.2.4.tar.gz
85254e378e54e901fb7f6887df584a88213c33b3dd9f1ba422ce423297a81bb2 libpg_query-17-6.2.4.zip