Return nulls honestly in aggregate "combine" functions. numeric_combine() and several other state-combining functions for aggregates cheated for the case of both inputs being NULL: they returned a null pointer without bothering to mark it as a SQL NULL. This was harmless in the expected usage where the result would be passed to the same combine function or a related aggregate final function. But it's bad news from a security standpoint, because now that value can be passed to an internal-accepting function even if said function is strict. While a previous patch prevented such queries from being issued, it seems like good defense-in-depth to expend the few additional lines of code needed to do this properly. Comparable functions such as array_agg_combine() already do so.
Reported-by: Amy Burnett (OpenAI Codex Security) Author: Tom Lane <[email protected]> Backpatch-through: 14 Security: CVE-2026-14680 Branch ------ REL_15_STABLE Details ------- https://git.postgresql.org/pg/commitdiff/d6e861e19ab668b5e3567318bbded59b3359b79d Author: Tom Lane <[email protected]> Modified Files -------------- src/backend/utils/adt/numeric.c | 32 ++++++++++++++++++++++++++++++++ 1 file changed, 32 insertions(+)
