Harden PL/Perl code against "tied" Perl arrays and hashes. Tied arrays might report different sizes each time they are inspected. To avoid generating a corrupt result array, fix plperl_array_to_datum() to read av_len() of each input array only once. If the input does appear to get shorter, we'll fill nulls for the now-missing entries, which seems fine. Conversely, if it gets longer, we'll ignore the new entries.
plperl_to_hstore() assumed that Perl's hv_iterinit() returns the number of entries in the given Perl hash. Usually that's true, but per the Perl docs, "the return value is currently only meaningful for hashes without tie magic". That could potentially end in a memory stomp. We don't depend on that result value anywhere else, so don't do so here either. Reported-by: Hcamael <[email protected]> Author: Tom Lane <[email protected]> Reviewed-by: Andrew Dunstan <[email protected]> Backpatch-through: 14 Security: CVE-2026-14670 Branch ------ REL_14_STABLE Details ------- https://git.postgresql.org/pg/commitdiff/d7fcfead3da81843a800f8bb046d4cb09d1c662d Author: Tom Lane <[email protected]> Modified Files -------------- contrib/hstore_plperl/hstore_plperl.c | 11 +++++++++-- src/pl/plperl/plperl.c | 6 +++++- 2 files changed, 14 insertions(+), 3 deletions(-)
