Use palloc_array() in pltcl and plperl to avoid overflow Some of these could overflow on 32-bit systems with the right input. Convert all cases where we called palloc() with multiplication to fix them. Not all of them were bugs, but it's better to be safe than sorry.
Reported-by: Tulya Project, Team Dhiutsa, Bitecope Technologies Private Ltd Backpatch-through: 14 Security: CVE-2026-14677 Branch ------ REL_15_STABLE Details ------- https://git.postgresql.org/pg/commitdiff/1eb0d53804a42b9d2bcc645bbd4ec75fd7c5291a Author: Heikki Linnakangas <[email protected]> Modified Files -------------- src/pl/plperl/SPI.xs | 6 +++--- src/pl/plperl/plperl.c | 38 +++++++++++++++++++------------------- src/pl/tcl/pltcl.c | 20 ++++++++++---------- 3 files changed, 32 insertions(+), 32 deletions(-)
