[PostGIS] #6118: Out-of-bounds read in geometry_type_from_string() on an empty type modifier
PostGIS
trac at osgeo.org
Mon Aug 31 08:55:29 PDT 2026
#6118: Out-of-bounds read in geometry_type_from_string() on an empty type modifier
-----------------------------+---------------------------
Reporter: eivkov | Owner: pramsey
Type: defect | Status: new
Priority: critical | Milestone: PostGIS 3.6.5
Component: postgis | Version: master
Keywords: buffer overflow |
-----------------------------+---------------------------
geometry_type_from_string() computes the last-character position as
strlen(str) - 1 without checking for an empty string. tmpendpos and i are
size_t, so for str == "" the subtraction wraps to SIZE_MAX and the
trailing-space loop immediately dereferences str[SIZE_MAX].
There is no length check on the caller side either: postgis_typmod_in()
hands the typmod cstring straight to this function, so the empty string is
reachable from SQL by any user.
Reproducer: SELECT geometry_typmod_in('{""}'); — the same entry point is
already exercised with a bad type name at
regress/core/lwgeom_regress.sql:223, which returns a clean "Invalid
geometry type modifier" error; the empty element does not.
PR ready: https://github.com/postgis/postgis/pull/1176
--
Ticket URL: <https://trac.osgeo.org/postgis/ticket/6118>
PostGIS <http://trac.osgeo.org/postgis/>
The PostGIS Trac is used for bug, enhancement & task tracking, a user and developer wiki, and a view into the subversion code repository of PostGIS project.
More information about the postgis-tickets
mailing list