This is an automated email from the ASF dual-hosted git repository.

leborchuk pushed a commit to branch REL_2_STABLE
in repository https://gitbox.apache.org/repos/asf/cloudberry.git

commit c0482b2cac41da06bfaeb7259503560d3072948e
Author: Daniel Gustafsson <[email protected]>
AuthorDate: Tue Jan 30 11:15:46 2024 +0100

    pgcrypto: Fix check for buffer size
    
    The code copying the PGP block into the temp buffer failed to
    account for the extra 2 bytes in the buffer which are needed
    for the prefix. If the block was oversized, subsequent checks
    of the prefix would have exceeded the buffer size.  Since the
    block sizes are hardcoded in the list of supported ciphers it
    can be verified that there is no live bug here. Backpatch all
    the way for consistency though, as this bug is old.
    
    Author: Mikhail Gribkov <[email protected]>
    Discussion: 
https://postgr.es/m/camev5_uwvcmcmdrfdsjlz2q8g16hea9xwyfrkr+fymmfjha...@mail.gmail.com
    Backpatch-through: v12
    (cherry picked from commit 54717fcaad759312b2ff8588e146977f529e7798)
---
 contrib/pgcrypto/pgp-decrypt.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/contrib/pgcrypto/pgp-decrypt.c b/contrib/pgcrypto/pgp-decrypt.c
index d03b097d79d..887fbc19278 100644
--- a/contrib/pgcrypto/pgp-decrypt.c
+++ b/contrib/pgcrypto/pgp-decrypt.c
@@ -250,7 +250,8 @@ prefix_init(void **priv_p, void *arg, PullFilter *src)
        uint8           tmpbuf[PGP_MAX_BLOCK + 2];
 
        len = pgp_get_cipher_block_size(ctx->cipher_algo);
-       if (len > sizeof(tmpbuf))
+       /* Make sure we have space for prefix */
+       if (len > PGP_MAX_BLOCK)
                return PXE_BUG;
 
        res = pullf_read_max(src, len + 2, &buf, tmpbuf);


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to