postgresql/contrib/pageinspect
Thomas Munro d837fb0292 Replace pg_mblen() with bounds-checked versions.
A corrupted string could cause code that iterates with pg_mblen() to
overrun its buffer.  Fix, by converting all callers to one of the
following:

1. Callers with a null-terminated string now use pg_mblen_cstr(), which
raises an "illegal byte sequence" error if it finds a terminator in the
middle of the sequence.

2. Callers with a length or end pointer now use either
pg_mblen_with_len() or pg_mblen_range(), for the same effect, depending
on which of the two seems more convenient at each site.

3. A small number of cases pre-validate a string, and can use
pg_mblen_unbounded().

The traditional pg_mblen() function and COPYCHAR macro still exist for
backward compatibility, but are no longer used by core code and are
hereby deprecated.  The same applies to the t_isXXX() functions.

Security: CVE-2026-2006
Backpatch-through: 14
Co-authored-by: Thomas Munro <thomas.munro@gmail.com>
Co-authored-by: Noah Misch <noah@leadboat.com>
Reviewed-by: Heikki Linnakangas <hlinnaka@iki.fi>
Reported-by: Paul Gerste (as part of zeroday.cloud)
Reported-by: Moritz Sanft (as part of zeroday.cloud)
2026-02-09 12:29:15 +13:00
..
expected Fix contrib/pageinspect's test for sequences. 2024-09-13 10:16:40 -05:00
sql Fix contrib/pageinspect's test for sequences. 2024-09-13 10:16:40 -05:00
.gitignore pageinspect: Add tests 2016-11-01 14:02:16 -04:00
brinfuncs.c Show empty BRIN ranges in brin_page_items 2023-05-19 02:00:21 +02:00
btreefuncs.c Consolidate ItemPointer to Datum conversion functions 2023-02-13 09:57:15 +01:00
fsmfuncs.c Update copyright for 2023 2023-01-02 15:00:37 -05:00
ginfuncs.c Consolidate ItemPointer to Datum conversion functions 2023-02-13 09:57:15 +01:00
gistfuncs.c pageinspect: Fix gist_page_items() with included columns 2023-05-19 12:37:58 +09:00
hashfuncs.c pageinspect: Fix failure with hash_bitmap_info() for partitioned indexes 2023-12-19 18:19:15 +09:00
heapfuncs.c Replace pg_mblen() with bounds-checked versions. 2026-02-09 12:29:15 +13:00
Makefile Add bt_multi_page_stats() function to contrib/pageinspect. 2023-01-02 13:02:29 -05:00
meson.build Update copyright for 2023 2023-01-02 15:00:37 -05:00
pageinspect--1.0--1.1.sql Fix typos in some error messages thrown by extension scripts when fed to psql. 2014-08-25 18:30:37 +02:00
pageinspect--1.1--1.2.sql Fix typos in some error messages thrown by extension scripts when fed to psql. 2014-08-25 18:30:37 +02:00
pageinspect--1.2--1.3.sql pageinspect/BRIN: minor tweaks 2014-12-02 12:20:50 -03:00
pageinspect--1.3--1.4.sql Add forgotten file in commit d6061f83a1 2015-11-25 16:59:07 +03:00
pageinspect--1.4--1.5.sql Update pageinspect extension for parallel query. 2016-06-09 17:18:09 -04:00
pageinspect--1.5--1.6.sql pageinspect: Add bt_page_items function with bytea argument 2017-04-04 23:52:55 -04:00
pageinspect--1.5.sql Update pageinspect extension for parallel query. 2016-06-09 17:18:09 -04:00
pageinspect--1.6--1.7.sql Skip full index scan during cleanup of B-tree indexes when possible 2018-04-04 19:29:00 +03:00
pageinspect--1.7--1.8.sql pageinspect: Fix types used for bt_metap() columns. 2020-03-07 16:44:53 -08:00
pageinspect--1.8--1.9.sql Use full 64-bit XIDs in deleted nbtree pages. 2021-02-24 18:41:34 -08:00
pageinspect--1.9--1.10.sql pageinspect: Improve page_header() for pages of 32kB 2021-07-12 11:05:27 +09:00
pageinspect--1.10--1.11.sql Mark pageinspect's disk-accessing functions as parallel restricted. 2022-11-21 15:37:10 -05:00
pageinspect--1.11--1.12.sql Show empty BRIN ranges in brin_page_items 2023-05-19 02:00:21 +02:00
pageinspect.control Add bt_multi_page_stats() function to contrib/pageinspect. 2023-01-02 13:02:29 -05:00
pageinspect.h Update copyright for 2023 2023-01-02 15:00:37 -05:00
rawpage.c Update copyright for 2023 2023-01-02 15:00:37 -05:00