From: Michael Paquier Date: Tue, 14 Jan 2025 06:13:20 +0000 (+0900) Subject: Fix potential integer overflow in bringetbitmap() X-Git-Tag: REL_13_19~38 X-Git-Url: http://git.postgresql.org/gitweb/?a=commitdiff_plain;h=332023e2d032743ce487b47f6d5f43111ca3fc0c;p=postgresql.git Fix potential integer overflow in bringetbitmap() This function expects an "int64" as result and stores the number of pages to add to the index scan bitmap as an "int", multiplying its final result by 10. For a relation large enough, this can theoretically overflow if counting more than (INT32_MAX / 10) pages, knowing that the number of pages is upper-bounded by MaxBlockNumber. To avoid the overflow, this commit redefines "totalpages", used to calculate the result, to be an "int64" rather than an "int". Reported-by: Evgeniy Gorbanyov Author: James Hunter Discussion: https://www.postgresql.org/message-id/07704817-6fa0-460c-b1cf-cd18f7647041@basealt.ru Backpatch-through: 13 --- diff --git a/src/backend/access/brin/brin.c b/src/backend/access/brin/brin.c index b5146c25dd0..3cc1384916e 100644 --- a/src/backend/access/brin/brin.c +++ b/src/backend/access/brin/brin.c @@ -422,7 +422,7 @@ bringetbitmap(IndexScanDesc scan, TIDBitmap *tbm) BrinOpaque *opaque; BlockNumber nblocks; BlockNumber heapBlk; - int totalpages = 0; + int64 totalpages = 0; FmgrInfo *consistentFn; MemoryContext oldcxt; MemoryContext perRangeCxt;