| pgpool-II 4.7.3 Documentation | |||
|---|---|---|---|
| Prev | Up | Appendix A. Release Notes | Next |
Release Date: 2026-09-29
This release contains security fixes for the following vulnerabilities.
A vulnerability in watchdog message processing during failover in Pgpool-II allows an attacker to write an arbitrary 32-bit value to an arbitrary memory address by sending a malformed message. (CVE-2026-92867)
An attacker can send a malformed failover request message to watchdog in Pgpool-II, causing a value to be written to an unintended memory address and resulting in memory corruption.
All versions of Pgpool-II in the 3.5 through 4.2 series, 4.3.0 to 4.3.20, 4.4.0 to 4.4.17, 4.5.0 to 4.5.12, 4.6.0 to 4.6.7, and 4.7.0 to 4.7.2 are affected. We strongly recommend upgrading to Pgpool-II 4.7.3, 4.6.8, 4.5.13, 4.4.18, or 4.3.21, or a later release in the corresponding series. The unsupported 3.5 through 4.2 series will not receive fixes. Users of these versions should upgrade to a supported version containing the fix.
Alternatively, disable watchdog (use_watchdog = off) or restrict access to watchdog to trusted networks only.
The Pgpool-II project thanks Emond Papegaaij for reporting this problem.
When a client connects to Pgpool-II using certificate authentication, Pgpool-II does not properly handle NUL bytes (\0) in the domain name in the Common Name (CN) field of the client's X.509 certificate. This vulnerability allows a malicious client to connect to the Pgpool-II server as another user without a password. (CVE-2026-92868)
Client certificate authentication compares the Common Name (CN) extracted from the client certificate with the connection username. However, crafted certificates containing an embedded NUL byte (\0) in the CN were not properly validated, allowing a CN that does not actually match the username to be treated as a valid match. By presenting such a certificate, an attacker may be authenticated as a legitimate user when authentication should have been rejected.
All versions of Pgpool-II in the 4.0 through 4.2 series, 4.3.0 to 4.3.20, 4.4.0 to 4.4.17, 4.5.0 to 4.5.12, 4.6.0 to 4.6.7, and 4.7.0 to 4.7.2 are affected. We strongly recommend upgrading to Pgpool-II 4.7.3, 4.6.8, 4.5.13, 4.4.18, or 4.3.21, or a later release in the corresponding series. The unsupported 4.0 through 4.2 series will not receive fixes. Users of these versions should upgrade to a supported version containing the fix.
Alternatively, use an authentication method other than client certificate authentication.
The Pgpool-II project thanks Emond Papegaaij for reporting this problem.
A vulnerability in watchdog message processing in Pgpool-II allows an attacker to overwrite memory beyond the boundaries of fixed-size arrays by sending a malformed message. (CVE-2026-92869)
An out-of-bounds write vulnerability exists in the watchdog message parsing code that processes configuration information received from watchdog peers in Pgpool-II. Upper-bound checks on the lengths of the backend_desc and wd_nodes JSON arrays received from watchdog peers are insufficient. Processing a crafted message may therefore cause writes beyond fixed-size arrays. Exploiting this vulnerability may cause a Pgpool-II process to crash or corrupt its memory.
All versions of Pgpool-II in the 3.5 through 4.2 series, 4.3.0 to 4.3.20, 4.4.0 to 4.4.17, 4.5.0 to 4.5.12, 4.6.0 to 4.6.7, and 4.7.0 to 4.7.2 are affected. We strongly recommend upgrading to Pgpool-II 4.7.3, 4.6.8, 4.5.13, 4.4.18, or 4.3.21, or a later release in the corresponding series. The unsupported 3.5 through 4.2 series will not receive fixes. Users of these versions should upgrade to a supported version containing the fix.
Alternatively, disable watchdog (use_watchdog = off) or restrict access to watchdog to trusted networks only.
The Pgpool-II project thanks Emond Papegaaij for reporting this problem.
A vulnerability in the handling of failover messages by watchdog in Pgpool-II allows writes of arbitrary-length data to corrupt the stack and crash a Pgpool-II process. (CVE-2026-92870)
When wd_authkey is not configured, an attacker can send a malformed failover message to watchdog in Pgpool-II and write arbitrary-length data to the stack of the Pgpool-II main process, causing the Pgpool-II process to crash.
All versions of Pgpool-II in the 3.5 through 4.2 series, 4.3.0 to 4.3.20, 4.4.0 to 4.4.17, 4.5.0 to 4.5.12, 4.6.0 to 4.6.7, and 4.7.0 to 4.7.2 are affected. We strongly recommend upgrading to Pgpool-II 4.7.3, 4.6.8, 4.5.13, 4.4.18, or 4.3.21, or a later release in the corresponding series. The unsupported 3.5 through 4.2 series will not receive fixes. Users of these versions should upgrade to a supported version containing the fix.
Alternatively, disable watchdog (use_watchdog = off) or restrict access to watchdog to trusted networks only.
The Pgpool-II project thanks Emond Papegaaij for reporting this problem.
A NULL pointer dereference vulnerability exists in watchdog inter-node authentication in Pgpool-II. When an authentication key is configured, crafted watchdog messages that omit authentication information are not handled correctly. (CVE-2026-92871)
An attacker who can connect to the watchdog port may cause the watchdog process on the target node to crash by sending a crafted watchdog message that omits authentication information.
All versions of Pgpool-II in the 3.5 through 4.2 series, 4.3.0 to 4.3.20, 4.4.0 to 4.4.17, 4.5.0 to 4.5.12, 4.6.0 to 4.6.7, and 4.7.0 to 4.7.2 are affected. We strongly recommend upgrading to Pgpool-II 4.7.3, 4.6.8, 4.5.13, 4.4.18, or 4.3.21, or a later release in the corresponding series. The unsupported 3.5 through 4.2 series will not receive fixes. Users of these versions should upgrade to a supported version containing the fix.
Alternatively, disable watchdog (use_watchdog = off) or restrict access to watchdog to trusted networks only.
The Pgpool-II project thanks Emond Papegaaij for reporting this problem.
An information disclosure vulnerability exists in the heartbeat receiver process of Pgpool-II. (CVE-2026-92872)
When the heartbeat receiver process of Pgpool-II receives a malformed message, it may disclose information from stack memory through log files.
All versions of Pgpool-II in the 3.5 through 4.2 series, 4.3.0 to 4.3.20, 4.4.0 to 4.4.17, 4.5.0 to 4.5.12, 4.6.0 to 4.6.7, and 4.7.0 to 4.7.2 are affected. We strongly recommend upgrading to Pgpool-II 4.7.3, 4.6.8, 4.5.13, 4.4.18, or 4.3.21, or a later release in the corresponding series. The unsupported 3.5 through 4.2 series will not receive fixes. Users of these versions should upgrade to a supported version containing the fix.
Alternatively, disable watchdog (use_watchdog = off) or use query-based life checking (wd_lifecheck_method = 'query') instead of heartbeat.
The Pgpool-II project thanks Emond Papegaaij for reporting this problem.
A vulnerability in watchdog promotion processing in Pgpool-II allows an attacker to bypass authentication key checks and promote a watchdog node of their choice to leader. (CVE-2026-92873)
In the promotion processing of watchdog, the cluster management module of Pgpool-II, an attacker can bypass authentication key checks and promote a watchdog node of their choice to leader.
All versions of Pgpool-II in the 3.5 through 4.2 series, 4.3.0 to 4.3.20, 4.4.0 to 4.4.17, 4.5.0 to 4.5.12, 4.6.0 to 4.6.7, and 4.7.0 to 4.7.2 are affected. We strongly recommend upgrading to Pgpool-II 4.7.3, 4.6.8, 4.5.13, 4.4.18, or 4.3.21, or a later release in the corresponding series. The unsupported 3.5 through 4.2 series will not receive fixes. Users of these versions should upgrade to a supported version containing the fix.
Alternatively, disable watchdog (use_watchdog = off) or restrict access to watchdog to trusted networks only.
The Pgpool-II project thanks Emond Papegaaij for reporting this problem.
Fix premature Sync during extended-query pipelines. (Taiki Koshino)
Prevent internal Sync messages from prematurely committing an implicit transaction while an extended-query pipeline is still in progress. Also coordinate errors and transaction completion across backend nodes so that an error later in a pipeline rolls back earlier changes.
Discussion: Pgpool injects Sync before a pipelined Parse and drops temporary tables #174
Fix a hang on deferred constraint errors in pipeline mode. (Taiki Koshino)
Keep the pending Sync message when a backend returns an ErrorResponse, allowing processing to continue through ReadyForQuery. Previously, a deferred constraint violation at commit time could make Pgpool-II wait indefinitely for a Sync that the frontend had already sent.
Discussion: [PATCH v1] Fix hang on deferred constraint errors in pipeline mode
Fix inconsistent internal transaction handling in Parse. (Taiki Koshino)
Restrict internal transaction creation in
Parse() to replication mode, matching
Bind(). Previously, an autocommitted
extended-protocol UPDATE in raw mode could leave the connection
in a transaction.
Discussion: Pgpool leaves an internal transaction open after autocommitted extended-protocol DML #172
Fix response buffer pointer advancement in do_error_execute_command(). (Taiki Koshino)
Advance the saved-response buffer pointer by the actual response body length rather than the size of the length field. This prevents corruption of subsequent saved responses, including after a zero-length response, in both protocol v2 and v3.
Discussion: Fix response buffer pointer advancement in do_error_execute_command
Check that a parse tree exists in handle_query_context(). (Tatsuo Ishii)
Check that a parse tree exists before accessing it in
handle_query_context(). This issue was
identified by Coverity.
Make the PCP worker shutdown signal handler only set flags. (Taiki Koshino)
Move PCP worker shutdown processing out of the signal handler and into the main loop. The handler now records the shutdown request only, avoiding unsafe logging and cleanup while other operations are in progress.
Problem reported by Emond Papegaaij.
Discussion: Convert pcp_worker die handler to flag-only.
Make PCP parent signal handlers only set flags. (Taiki Koshino)
Move PCP parent shutdown and wakeup processing into the main loop. Signal handlers now set flags rather than traversing or modifying the worker list, preventing races that could cause crashes or signals to be sent to reused process IDs.
Problem reported by Emond Papegaaij.
Discussion: Convert pcp_exit_handler and wakeup_handler_parent to flag-only.
Move idle-connection cleanup from the signal handler to the main loop. (Taiki Koshino)
Make the child process SIGUSR1 handler record an idle-connection cleanup request and perform the cleanup in the main loop. This prevents connection and startup-packet memory from being freed while the interrupted code is using it.
Problem reported by Emond Papegaaij.
Discussion: Convert close_idle_connection (SIGUSR1) to flag-only handler with main-loop processing.
Make the lifecheck exit signal handler only set flags. (Taiki Koshino)
Move watchdog lifecheck child termination, memory cleanup, and process exit out of the signal handler. The handler now records the signal and sets flags while preserving errno, avoiding unsafe operations in signal context.
Problem reported by Emond Papegaaij.
Discussion: Convert pcp_exit_handler and wakeup_handler_parent to flag-only.
Add separators to query-cache keys to prevent collisions. (Taiki Koshino)
Insert NUL separators between the user, query, and database fields when constructing query-cache keys, and hash the complete buffer. Previously, concatenating these fields without separators could produce identical keys for different inputs and return cached results across users or databases.
Problem reported by Emond Papegaaij.
Discussion: Delimit query-cache key to prevent collisions
Fix unsigned integer underflow in inject_cached_message(). (Taiki Koshino)
Validate cached message lengths before subtracting the header
size in inject_cached_message(). A length
smaller than the header could otherwise underflow to a large
unsigned value and terminate the session through a failed memory
allocation.
Problem reported by Emond Papegaaij.
Discussion: Fix unsigned underflow in inject_cached_message
Fix an out-of-bounds buffer access in pgproto. (Tatsuo Ishii)
Check the input buffer length before testing for a continuation line in pgproto. This prevents an out-of-bounds access detected by AddressSanitizer.
Reset removed configuration parameters to their defaults. (Taiki Koshino)
Reset reloadable parameters to their defaults when they are removed or commented out in pgpool.conf. Previously, configuration reload retained their old values. Values not loaded from the configuration file are left unchanged.
Discussion: reload config issue #164
Revert "Fix do_query to send sync rather than flush." (Tatsuo Ishii)
Revert the change that made do_query() send
Sync instead of Flush. That
change could prematurely commit an implicit pipeline transaction,
leaving earlier changes committed even when a later statement
failed.
Discussion: Re: low level protocol, implicit transactions , "idle in transaction" issue
Lower the debug message level to DEBUG5 in get_health_check_stats(). (Tatsuo Ishii)
Change an accidentally retained debug message in
get_health_check_stats() from LOG to DEBUG5.
Problem reported by seoktai-chun.
Discussion: Leftover debug log "status_changed_time" floods the log in pool_process_reporting.c #171
Lower the debug message level to DEBUG5 in pool_temp_tables_delete(). (Tatsuo Ishii)
Change an accidentally retained debug message in
pool_temp_tables_delete() from LOG to
DEBUG5.
Fix notice forwarding during authentication. (Tatsuo Ishii)
Forward backend notices safely during authentication, before the session context is established. This fixes a FATAL error triggered by the MD5 authentication notice emitted by PostgreSQL 19 and later.
Problem reported by harudini.
Discussion: Regression test failures against PostgreSQL 19 beta #168
Reverted change: make do_query send Sync rather than Flush. (Tatsuo Ishii)
This change attempted to close implicit transactions created by internal queries by sending Sync instead of Flush. It was subsequently reverted by commit 44e454142 because it broke pipeline transaction semantics; this behavior is not part of the final release.
Discussion: low level protocol, implicit transactions , "idle in transaction" issue
Add missing volatile qualifiers. (Tatsuo Ishii)
Add the missing volatile qualifiers to shared backend-status accesses through my_backend_status. This prevents compiler optimizations from causing stale status values to be used.
Discussion: Adding volatile qualifier
Reject invalid ErrorResponse lengths in read_kind_from_backend(). (Tatsuo Ishii)
Reject backend ErrorResponse lengths smaller
than the length field in
read_kind_from_backend(). This prevents a
heap buffer overwrite and unsigned underflow when handling
malformed responses.
Problem reported by Emond Papegaaij.
Discussion: Reject sub-minimum ErrorResponse length in read_kind_from_backend.
Fix a segmentation fault in pool_do_auth(). (Tatsuo Ishii)
Derive the local main node ID from the copied backend statuses
rather than independently copying the shared main node ID. This
prevents inconsistent state during failover from causing a NULL
connection dereference in pool_do_auth().
Also add volatile qualifiers for shared-memory reads.
Discussion: [PATCH] Segfault in pool_do_auth() when failover races with a new connection
Avoid unsafe operations in the Pgpool-II main process signal handler. (Tatsuo Ishii)
Move main-process shutdown work out of the SIGTERM, SIGINT, and SIGQUIT handler. The handler now records the request and wakes the main loop, which performs shutdown in normal process context. This avoids crashes, hangs, or memory corruption caused by unsafe operations in the signal handler.
Problem reported by Emond Papegaaij.
Discussion: Fix signal handler in pgpool main
Fix a query context use-after-free after a backend node shutdown. (Tatsuo Ishii)
Allocate query contexts in the session memory context so they remain valid for the session-scoped sent and pending message lists. Previously, a backend shutdown could cause the query-processing loop to free contexts still referenced by these lists, leading to a use-after-free and crash.
Discussion: Use-after-free crash
Fix a COPY IN hang in extended query mode. (Tatsuo Ishii)
Wait for the backend CopyInResponse before forwarding COPY data, and allow the frontend Sync to be processed after CopyDone. This fixes a hang when COPY FROM STDIN is executed using the extended query protocol in streaming replication mode.
Problem reported by liujinyang-highgo.
Discussion: use QGis import data cause pgpool hang. #162
Prevent pcp_node_info from hanging. (Tatsuo Ishii)
Copy the shared replication-state strings into local buffers before calculating and sending a PCP node-info response. Concurrent updates could otherwise make the declared packet length differ from its payload and cause pcp_node_info to hang.
Discussion: Race condition in pcp_node_info can cause it to hang
Fix a typo in a read_kind_from_backend() comment. (Tatsuo Ishii)
Discussion: Fix comment for read_kind_from_backend
Fix query-cache handling with disable_load_balance_on_write. (Tatsuo Ishii)
Track actual writes separately from the state used by disable_load_balance_on_write. This fixes incorrect query-cache use when the parameter is set to trans_transaction, dml_adaptive, or always.
Doc: Fix incorrect links. (Bo Peng)
Test: enhance the 018.detach_primary regression test. (Tatsuo Ishii)
Wait explicitly for watchdog quorum in 018.detach_primary before testing the detachment of an invalid streaming replication primary node.
Test: stabilize the 006.memqcache regression test. (Tatsuo Ishii)
Use synchronous replication in the streaming replication tests in 006.memqcache. This avoids intermittent failures caused by replication delay, such as a newly created role not yet being available on a standby.
Test: fix regress.sh to use a numeric PostgreSQL version number. (Tatsuo Ishii)
Remove nonnumeric suffixes from the PostgreSQL version used by regression scripts, so development version strings such as 20devel can be used in numeric comparisons.
Test: increase the test timeout from 300 to 360 seconds. (Tatsuo Ishii)
Increase the regression test timeout from 300 to 360 seconds to accommodate longer runs of 006.memqcache.
Test: use wait_for_pgpool_startup instead of sleep. (Tatsuo Ishii)
Use wait_for_pgpool_startup() instead of a
fixed one-second sleep in 110.memory_leak and
111.cancel_query, avoiding intermittent
startup-related test failures.