Return nulls honestly in aggregate "combine" functions.

numeric_combine() and several other state-combining functions for
aggregates cheated for the case of both inputs being NULL: they
returned a null pointer without bothering to mark it as a SQL NULL.
This was harmless in the expected usage where the result would be
passed to the same combine function or a related aggregate final
function.  But it's bad news from a security standpoint, because
now that value can be passed to an internal-accepting function
even if said function is strict.  While a previous patch prevented
such queries from being issued, it seems like good defense-in-depth
to expend the few additional lines of code needed to do this properly.
Comparable functions such as array_agg_combine() already do so.

Reported-by: Amy Burnett (OpenAI Codex Security)
Author: Tom Lane <[email protected]>
Backpatch-through: 14
Security: CVE-2026-14680

Branch
------
REL_17_STABLE

Details
-------
https://git.postgresql.org/pg/commitdiff/83d0a083f178f22c60814b93d17ecacdcce76eac
Author: Tom Lane <[email protected]>

Modified Files
--------------
src/backend/utils/adt/numeric.c   | 32 ++++++++++++++++++++++++++++++++
src/backend/utils/adt/timestamp.c |  8 ++++++++
2 files changed, 40 insertions(+)

Reply via email to