Skip to content

security: DuckDB memory_limit interpolated directly into SQL without validation #363

Description

@xe-nvdk

Summary

In internal/compaction/subprocess.go:93, the memory limit config value is interpolated directly into a DuckDB SET statement:

```go
db.Exec(fmt.Sprintf("SET memory_limit='%s'", config.MemoryLimit))
```

While DuckDB's SET is not exploitable for data access, a malformed value could: trigger misleading error logs that expose other config context, or be used to DoS compaction by setting an extremely low limit.

Fix

Validate the format before use with a strict regex:

```go
var validMemoryLimit = regexp.MustCompile(^\d+(\.\d+)?\s*(KB|MB|GB|TB)$)
if !validMemoryLimit.MatchString(config.MemoryLimit) {
logger.Error().Str("limit", config.MemoryLimit).Msg("Invalid memory_limit format, skipping")
} else {
db.Exec(fmt.Sprintf("SET memory_limit='%s'", config.MemoryLimit))
}
```

Severity

Medium — no direct data access risk, but validates untrusted config input before SQL use.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingsecuritySecurity vulnerability or hardening

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions