pgsql: Guard against overlength time zone abbreviations in to_char(). - Mailing list pgsql-committers

From Noah Misch
Subject pgsql: Guard against overlength time zone abbreviations in to_char().
Date
Msg-id E1wtQFl-00000000y2k-1wji@gemulon.postgresql.org
Whole thread
List pgsql-committers
Guard against overlength time zone abbreviations in to_char().

While typical abbreviations are only a few bytes long, a user-supplied
time_zone setting could specify a much longer abbreviation, enough to
overflow to_char's allocation of 12 bytes per format character. If so,
throw an error in the same style as commit 9241c84cb (CVE-2015-0241).

Reported-by: Hcamael <baiyjrh@gmail.com>
Reported-by: Amjad Shahzad <amjadshahzad2000@gmail.com>
Reported-by: Tan Zhen of AntAISecurityLab <TanZhen.AntAI@outlook.com>
Reported-by: Tomer Fichman <tomer@irregular.com>
Reported-by: Zheng Yu <zheng@depthfirst.com>
Reported-by: Amy Burnett (OpenAI Codex Security)
Reported-by: Rick de Jager <rick@v12.sh>
Reported-by: Heewon Song <asteria121@78researchlab.com>
Reported-by: Sylvie Mayer <smayer@cloudflare.com>
Reported-by: Aleksander Alekseev <aleksander@tigerdata.com>
Reported-by: Hillai Ben Sasson <hillai.bensasson@wiz.io>
Author: Tom Lane <tgl@sss.pgh.pa.us>
Backpatch-through: 14
Security: CVE-2026-14669

Branch
------
REL_19_STABLE

Details
-------
https://git.postgresql.org/pg/commitdiff/3294ab83947270a44f680a1725383e6521315b70
Author: Tom Lane <tgl@sss.pgh.pa.us>

Modified Files
--------------
src/backend/utils/adt/formatting.c | 21 ++++++++++++++++++---
1 file changed, 18 insertions(+), 3 deletions(-)


pgsql-committers by date:

Previous
From: Noah Misch
Date:
Subject: pgsql: Cross-check the type of a portal running EXECUTE or FETCH.
Next
From: Noah Misch
Date:
Subject: pgsql: Return nulls honestly in aggregate "combine" functions.