I'm sending you an updated patch. A test has been added to 
src/interfaces/ecpg/test/pgtypeslib/dt_test2.pgc. It works without compiling 
AddressSanitizer.

Test result before patch:
...
interval_copy[5]: @ 1 year 59 mins
Error parsing interval 6
free(): invalid next size (fast)
Aborted (core dumped)

After patch:
...
interval_copy[5]: @ 1 year 59 mins
Error parsing interval 6
Success parsing large string

--
Maria Sivirilova

-----Original Message-----
From: Daniel Gustafsson <[email protected]> 
Sent: Wednesday, August 19, 2026 3:12 PM
To: Сивирилова Мария Константиновна <[email protected]>
Cc: [email protected]
Subject: Re: [PATCH] Fix heap-buffer-overflow in PGTYPEStimestamp_defmt_scan()

> On 19 Aug 2026, at 08:55, Sivirilova Marija <[email protected]> wrote:
> 
> Hello, hackers!
>  We used the Clang Static Analyzer and found a heap-buffer-overflow in the 
> PGTYPEStimestamp_defmt_scan() function inside 
> src/interfaces/ecpg/pgtypeslib/dt_common.c. When processing template tokens 
> like '%D', '%r', '%R', or '%T', the code allocates a temporary buffer based 
> on the length of the remaining input string (pstr). However, it later 
> concatenates the remaining format string (pfmt) into this buffer using 
> strcat(). If an application attempts to parse a short or truncated time 
> string using a longer, complex format pattern, the format string suffix will 
> exceed the allocated memory, causing a heap-buffer-overflow.
>  The issue can be reproduced with a minimal test case (compiling this with 
> AddressSanitizer):

Can you please add testcases to the patch, to make sure we cover these 
edgecases in the regression tests.

--
Daniel Gustafsson



Attachment: Fix-heap-buffer-overflow.patch
Description: Fix-heap-buffer-overflow.patch

Reply via email to