pgsql: Make pg_regexec() robust against out-of-range search_start.

Поиск
Список
Период
Сортировка
От Tom Lane
Тема pgsql: Make pg_regexec() robust against out-of-range search_start.
Дата
Msg-id E1mP8Yg-00047k-Nk@gemulon.postgresql.org
обсуждение исходный текст
Список pgsql-committers
Make pg_regexec() robust against out-of-range search_start.

If search_start is greater than the length of the string, we should just
return REG_NOMATCH immediately.  (Note that the equality case should
*not* be rejected, since the pattern might be able to match zero
characters.)  This guards various internal assumptions that the min of a
range of string positions is not more than the max.  Violation of those
assumptions could allow an attempt to fetch string[search_start-1],
possibly causing a crash.

Jaime Casanova pointed out that this situation is reachable with the
new regexp_xxx functions that accept a user-specified start position.
I don't believe it's reachable via any in-core call site in v14 and
below.  However, extensions could possibly call pg_regexec with an
out-of-range search_start, so let's back-patch the fix anyway.

Discussion: https://postgr.es/m/20210911180357.GA6870@ahch-to

Branch
------
REL_14_STABLE

Details
-------
https://git.postgresql.org/pg/commitdiff/b33283cbd336adbf982c21aac1399130c8ffaaa9

Modified Files
--------------
src/backend/regex/regexec.c | 2 ++
1 file changed, 2 insertions(+)


В списке pgsql-committers по дате отправления:

Предыдущее
От: Tom Lane
Дата:
Сообщение: pgsql: Fix some anomalies with NO SCROLL cursors.
Следующее
От: Michael Paquier
Дата:
Сообщение: pgsql: Refactor the syslogger pipe protocol to use a bitmask for its op