KB2950209 - FIX: Access violation when the start offset is larger than the string length in Substring function in SQL Server

Applies To
SQL Server 2012 Enterprise SQL Server 2012 Developer SQL Server 2012 Standard SQL Server 2014 Developer - duplicate (do not use) SQL Server 2014 Enterprise - duplicate (do not use) SQL Server 2014 Standard - duplicate (do not use)

Symptoms

Assume that you use the Substring (expression, start, length) function in Microsoft SQL Server 2012 Service Pack 1 (SP1) Cumulative Update 1 (CU1) and later versions or SQL Server 2014. When the length of expression is larger than 8000 and start is larger than the length of expression, an access violation occurs. Additionally, you receive the following error:

Note

A severe error occurred on the current command. The results, if any, should be discarded.

Resolution

The issue was first fixed in the following cumulative update of SQL Server.
After the hotfix is applied, a zero-length expression is returned when start is greater than the number of characters in the value expression.

Cumulative Update 1 for SQL Server 2012 SP2 /en-us/help/2976982

Cumulative Update 2 for SQL Server 2014 /en-us/help/2967546

Cumulative Update 10 for SQL Server 2012 SP1 /en-us/help/2954099

About cumulative updates for SQL Server

Each new cumulative update for SQL Server contains all the hotfixes and all the security fixes that were included with the previous cumulative update. Check out the latest cumulative updates for SQL Server:

      

Status

Microsoft has confirmed that this is a problem in the Microsoft products that are listed in the "Applies to" section.