Avoid overflow in Levenshtein distance calculations. levenshtein() and levenshtein_less_equal() let the caller specify the insertion, deletion, and substitution costs, and fuzzystrmatch's corresponding SQL functions accept any 32-bit integer for each. Since the distances are calculated with 32-bit arithmetic, large costs can cause overflows, thereby producing nonsensical results. Certain inputs to levenshtein_less_equal() can even cause out-of-bounds writes. To fix, use 64-bit arithmetic instead, and error whenever the final result won't fit in the returned 32-bit integer.
We may want to teach these functions to reject negative costs, too, but that didn't seem appropriate for a security fix, and therefore it is left as a future exercise. Reported-by: Ben Morris in collaboration with Claude and Anthropic Research Author: Nathan Bossart <[email protected]> Reviewed-by: Dean Rasheed <[email protected]> Security: CVE-2026-15742 Backpatch-through: 14 Branch ------ REL_14_STABLE Details ------- https://git.postgresql.org/pg/commitdiff/9505175f2a782bb63acd11d8d473a0ccedb719ea Author: Nathan Bossart <[email protected]> Modified Files -------------- contrib/fuzzystrmatch/expected/fuzzystrmatch.out | 14 ++++ contrib/fuzzystrmatch/sql/fuzzystrmatch.sql | 3 + src/backend/utils/adt/levenshtein.c | 89 ++++++++++++------------ src/backend/utils/adt/varlena.c | 14 ++++ 4 files changed, 77 insertions(+), 43 deletions(-)
