Skip to content

Add check for incorrect length values in postgres DataRow parser#47872

Merged
fearful-symmetry merged 5 commits intoelastic:mainfrom
fearful-symmetry:pgsql-datarow-mailicious-packet-fix
Dec 3, 2025
Merged

Add check for incorrect length values in postgres DataRow parser#47872
fearful-symmetry merged 5 commits intoelastic:mainfrom
fearful-symmetry:pgsql-datarow-mailicious-packet-fix

Conversation

@fearful-symmetry
Copy link
Contributor

Proposed commit message

This fixes a bug where a PostgreSQL packed with a DataRow that specified a row count less than the actual count of rows would result in an out of bounds array access and panic. This just adds a length check, and a bit of error cleanup.

Checklist

  • My code follows the style guidelines of this project
  • I have commented my code, particularly in hard-to-understand areas
  • I have made corresponding changes to the documentation
  • I have made corresponding change to the default configuration files
  • I have added tests that prove my fix is effective or that my feature works. Where relevant, I have used the stresstest.sh script to run them under stress conditions and race detector to verify their stability.
  • I have added an entry in ./changelog/fragments using the changelog tool.
@fearful-symmetry fearful-symmetry self-assigned this Dec 2, 2025
@fearful-symmetry fearful-symmetry requested a review from a team as a code owner December 2, 2025 20:07
@botelastic botelastic bot added the needs_team Indicates that the issue/PR needs a Team:* label label Dec 2, 2025
@github-actions
Copy link
Contributor

github-actions bot commented Dec 2, 2025

🤖 GitHub comments

Just comment with:

  • run docs-build : Re-trigger the docs validation. (use unformatted text in the comment!)
@mergify
Copy link
Contributor

mergify bot commented Dec 2, 2025

This pull request does not have a backport label.
If this is a bug or security fix, could you label this PR @fearful-symmetry? 🙏.
For such, you'll need to label your PR with:

  • The upcoming major version of the Elastic Stack
  • The upcoming minor version of the Elastic Stack (if you're not pushing a breaking change)

To fixup this pull request, you need to add the backport labels for the needed
branches, such as:

  • backport-8./d is the label to automatically backport to the 8./d branch. /d is the digit
  • backport-active-all is the label that automatically backports to all active branches.
  • backport-active-8 is the label that automatically backports to all active minor branches for the 8 major.
  • backport-active-9 is the label that automatically backports to all active minor branches for the 9 major.
@pierrehilbert pierrehilbert added the Team:Security-Linux Platform Linux Platform Team in Security Solution label Dec 3, 2025
@elasticmachine
Copy link
Contributor

Pinging @elastic/sec-linux-platform (Team:Security-Linux Platform)

@botelastic botelastic bot removed the needs_team Indicates that the issue/PR needs a Team:* label label Dec 3, 2025
@fearful-symmetry fearful-symmetry merged commit ed2d884 into elastic:main Dec 3, 2025
46 checks passed
@marc-gr marc-gr added the backport-active-all Automated backport with mergify to all the active branches label Jan 12, 2026
@github-actions
Copy link
Contributor

@Mergifyio backport 8.19 9.1 9.2 9.3

@mergify
Copy link
Contributor

mergify bot commented Jan 12, 2026

backport 8.19 9.1 9.2 9.3

✅ Backports have been created

Details
mergify bot pushed a commit that referenced this pull request Jan 12, 2026
)

* add check for incorrect length values in postgres DataRow parser

* add changelog

* linter...

* linter....

* fix log message

(cherry picked from commit ed2d884)
mergify bot pushed a commit that referenced this pull request Jan 12, 2026
)

* add check for incorrect length values in postgres DataRow parser

* add changelog

* linter...

* linter....

* fix log message

(cherry picked from commit ed2d884)
mergify bot pushed a commit that referenced this pull request Jan 12, 2026
)

* add check for incorrect length values in postgres DataRow parser

* add changelog

* linter...

* linter....

* fix log message

(cherry picked from commit ed2d884)
marc-gr pushed a commit that referenced this pull request Jan 12, 2026
) (#48375)

* add check for incorrect length values in postgres DataRow parser

* add changelog

* linter...

* linter....

* fix log message

(cherry picked from commit ed2d884)

Co-authored-by: Alex K. <8418476+fearful-symmetry@users.noreply.github.com>
marc-gr pushed a commit that referenced this pull request Jan 12, 2026
) (#48373)

* add check for incorrect length values in postgres DataRow parser

* add changelog

* linter...

* linter....

* fix log message

(cherry picked from commit ed2d884)

Co-authored-by: Alex K. <8418476+fearful-symmetry@users.noreply.github.com>
fearful-symmetry added a commit that referenced this pull request Jan 12, 2026
) (#48374)

* add check for incorrect length values in postgres DataRow parser

* add changelog

* linter...

* linter....

* fix log message

(cherry picked from commit ed2d884)

Co-authored-by: Alex K. <8418476+fearful-symmetry@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport-active-all Automated backport with mergify to all the active branches Team:Security-Linux Platform Linux Platform Team in Security Solution

5 participants