[PostGIS] #6118: Out-of-bounds read in geometry_type_from_string() on an empty type modifier

PostGIS trac at osgeo.org
Mon Aug 31 09:04:14 PDT 2026


#6118: Out-of-bounds read in geometry_type_from_string() on an empty type modifier
-----------------------+-----------------------------
  Reporter:  eivkov    |      Owner:  pramsey
      Type:  defect    |     Status:  new
  Priority:  critical  |  Milestone:  PostGIS 3.6.5
 Component:  postgis   |    Version:  master
Resolution:            |   Keywords:  buffer overflow
-----------------------+-----------------------------
Description changed by eivkov:

Old description:

> geometry_type_from_string() computes the last-character position as
> strlen(str) - 1 without checking for an empty string. tmpendpos and i are
> size_t, so for str == "" the subtraction wraps to SIZE_MAX and the
> trailing-space loop immediately dereferences str[SIZE_MAX].
>
> There is no length check on the caller side either: postgis_typmod_in()
> hands the typmod cstring straight to this function, so the empty string
> is reachable from SQL by any user.
>
> Reproducer: SELECT geometry_typmod_in('{""}'); — the same entry point is
> already exercised with a bad type name at
> regress/core/lwgeom_regress.sql:223, which returns a clean "Invalid
> geometry type modifier" error; the empty element does not.
>
> PR ready: https://github.com/postgis/postgis/pull/1176

New description:

 geometry_type_from_string() computes the last-character position as
 strlen(str) - 1 without checking for an empty string. tmpendpos and i are
 size_t, so for str == "" the subtraction wraps to SIZE_MAX and the
 trailing-space loop immediately dereferences str[SIZE_MAX].

 There is no length check on the caller side either: postgis_typmod_in()
 hands the typmod cstring straight to this function, so the empty string is
 reachable from SQL by any user.

 Reproducer: SELECT geometry_typmod_in('{""}'); - the same entry point is
 already exercised with a bad type name at
 regress/core/lwgeom_regress.sql:223, which returns a clean "Invalid
 geometry type modifier" error; the empty element does not.

 PR ready: https://github.com/postgis/postgis/pull/1176

--
-- 
Ticket URL: <https://trac.osgeo.org/postgis/ticket/6118#comment:1>
PostGIS <http://trac.osgeo.org/postgis/>
The PostGIS Trac is used for bug, enhancement & task tracking, a user and developer wiki, and a view into the subversion code repository of PostGIS project.


More information about the postgis-tickets mailing list