mirror of https://github.com/postgres/postgres
A pointer to a C string was treated as a pointer to a "name" datum and passed to SPI_execute_plan(). This pointer would then end up being passed through datumCopy(), which would try to copy the entire 64 bytes of name data, thus running past the end of the C string. Fix by converting the string to a proper name structure. Found by LLVM AddressSanitizer.REL8_4_STABLE
parent
122ba5dadf
commit
240766a6ec
Loading…
Reference in new issue