Reject GSSEncRequest after direct SSL connection When a direct SSL connection was established, ProcessStartupPacket() still accepted GSSEncRequest messages. The GSSAPI negotiation would then use raw writes and reads, bypassing the TLS encryption layer. After the GSS encryption was established, the connection continued to use TLS. This could betray the HBA rules so as the backend does protocol exchanges inconsistent with the connection policies in place, with TLS taking priority over GSS in the backend.
The SSL negotiation path already guarded against attempts to request SSL after a direct SSL request has been processed. The GSS path is now guarded the same way when receiving a startup packet. Reported-by: p4p3r <[email protected]> Author: Michael Paquier <[email protected]> Reviewed-by: Jacob Champion <[email protected]> Backpatch-through: 17 Security: CVE-2026-14681 Branch ------ REL_19_STABLE Details ------- https://git.postgresql.org/pg/commitdiff/bf1bb7e29cb1eddb0fad7422c032abb2b756c281 Author: Michael Paquier <[email protected]> Modified Files -------------- src/backend/tcop/backend_startup.c | 9 +++++++-- 1 file changed, 7 insertions(+), 2 deletions(-)
