↑↓ select ↵ open ⌫ change scope Open full search

PG.CENTER connects PostgreSQL documentation, reference, and ecosystem knowledge. Maintained by Pigsty.

DocumentationVersion comparison

POSTGRESQL · VERSION COMPARE

PostgreSQL 9.2.22 release changes

All features, fixes, and compatibility notes in this release, with related records from other versions.

All changes in this release
All changes in this release

Includes changes after the source version through the target. A major version name means its initial release.

From PostgreSQL 9.0 onward: 17 major branches and 352 release notes. Updated 2026-09-26.

Complete release changes

9.2.22

2017-08-10

Export JSON
32changesFeatures, fixes, improvements
1releaseGrouped by release
3CVEsVulnerability IDs mentioned in these notes

9.2.22 HistoricalSupport ends 2017-11-09

Security records mentioned in this release 3 CVEs
CVEs mentioned in these notes, including possible follow-up fixes for earlier vulnerabilities
CVE / issueSeverityFixed version
CVE-2017-7547

Further restrict visibility of pg_user_mappings.umoptions, to protect passwords stored as user mapping options

8.59.2.22
CVE-2017-7486

Further restrict visibility of pg_user_mappings.umoptions, to protect passwords stored as user mapping options

8.59.2.21
CVE-2017-7546

Disallow empty passwords in all password-based authentication methods

8.19.2.22

PostgreSQL 9.2.22

Migration and compatibility

A dump/restore is not required for those running 9.2.X.

However, if you use foreign data servers that make use of user passwords for authentication, see the first changelog entry below.

Also, if you are upgrading from a version earlier than 9.2.20, see Section E.5.

SecurityFurther restrict visibility of pg_user_mappings.umoptions, to protect passwords stored as user mapping options

Changes

Further restrict visibility of pg_user_mappings.umoptions, to protect passwords stored as user mapping options (Noah Misch)

The fix for CVE-2017-7486 was incorrect: it allowed a user to see the options in her own user mapping, even if she did not have USAGE permission on the associated foreign server. Such options might include a password that had been provided by the server owner rather than the user herself. Since information_schema.user_mapping_options does not show the options in such cases, pg_user_mappings should not either. (CVE-2017-7547)

By itself, this patch will only fix the behavior in newly initdb'd databases. If you wish to apply this change in an existing database, you will need to do the following:

  1. Restart the postmaster after adding allow_system_table_mods = true to postgresql.conf. (In versions supporting ALTER SYSTEM, you can use that to make the configuration change, but you'll still need a restart.)

  2. In each database of the cluster, run the following commands as superuser:

    SET search_path = pg_catalog;
    CREATE OR REPLACE VIEW pg_user_mappings AS
        SELECT
            U.oid       AS umid,
            S.oid       AS srvid,
            S.srvname   AS srvname,
            U.umuser    AS umuser,
            CASE WHEN U.umuser = 0 THEN
                'public'
            ELSE
                A.rolname
            END AS usename,
            CASE WHEN (U.umuser <> 0 AND A.rolname = current_user
                         AND (pg_has_role(S.srvowner, 'USAGE')
                              OR has_server_privilege(S.oid, 'USAGE')))
                        OR (U.umuser = 0 AND pg_has_role(S.srvowner, 'USAGE'))
                        OR (SELECT rolsuper FROM pg_authid WHERE rolname = current_user)
                        THEN U.umoptions
                     ELSE NULL END AS umoptions
        FROM pg_user_mapping U
             LEFT JOIN pg_authid A ON (A.oid = U.umuser) JOIN
            pg_foreign_server S ON (U.umserver = S.oid);
    
  3. Do not forget to include the template0 and template1 databases, or the vulnerability will still exist in databases you create later. To fix template0, you'll need to temporarily make it accept connections. In PostgreSQL 9.5 and later, you can use

    ALTER DATABASE template0 WITH ALLOW_CONNECTIONS true;
    

    and then after fixing template0, undo that with

    ALTER DATABASE template0 WITH ALLOW_CONNECTIONS false;
    

    In prior versions, instead use

    UPDATE pg_database SET datallowconn = true WHERE datname = 'template0';
    UPDATE pg_database SET datallowconn = false WHERE datname = 'template0';
    
  4. Finally, remove the allow_system_table_mods configuration setting, and again restart the postmaster.

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

SecurityDisallow empty passwords in all password-based authentication methods

Changes

Disallow empty passwords in all password-based authentication methods (Heikki Linnakangas)

libpq ignores empty password specifications, and does not transmit them to the server. So, if a user's password has been set to the empty string, it's impossible to log in with that password via psql or other libpq-based clients. An administrator might therefore believe that setting the password to empty is equivalent to disabling password login. However, with a modified or non-libpq-based client, logging in could be possible, depending on which authentication method is configured. In particular the most common method, md5, accepted empty passwords. Change the server to reject empty passwords in all cases. (CVE-2017-7546)

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsOn Windows, retry process creation if we fail to reserve the address range for our shared memory in the new process

Changes

On Windows, retry process creation if we fail to reserve the address range for our shared memory in the new process (Tom Lane, Amit Kapila)

This is expected to fix infrequent child-process-launch failures that are probably due to interference from antivirus products.

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesFix low-probability corruption of shared predicate-lock hash table in Windows builds

Changes

Fix low-probability corruption of shared predicate-lock hash table in Windows builds (Thomas Munro, Tom Lane)

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsAvoid logging clean closure of an SSL connection as though it were a connection reset

Changes

Avoid logging clean closure of an SSL connection as though it were a connection reset (Michael Paquier)

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsPrevent sending SSL session tickets to clients

Changes

Prevent sending SSL session tickets to clients (Tom Lane)

This fix prevents reconnection failures with ticket-aware client-side SSL code.

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesFix code for setting tcp_keepalives_idle on Solaris

Changes

Fix code for setting tcp_keepalives_idle on Solaris (Tom Lane)

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesFix statistics collector to honor inquiry messages issued just after a postmaster shutdown and immediate restart

Changes

Fix statistics collector to honor inquiry messages issued just after a postmaster shutdown and immediate restart (Tom Lane)

Statistics inquiries issued within half a second of the previous postmaster shutdown were effectively ignored.

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsEnsure that the statistics collector's receive buffer size is at least 100KB

Changes

Ensure that the statistics collector's receive buffer size is at least 100KB (Tom Lane)

This reduces the risk of dropped statistics data on older platforms whose default receive buffer size is less than that.

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesFix possible creation of an invalid WAL segment when a standby is promoted just after it processes an XLOG_SWITCH WAL record

Changes

Fix possible creation of an invalid WAL segment when a standby is promoted just after it processes an XLOG_SWITCH WAL record (Andres Freund)

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesFix SIGHUP and SIGUSR1 handling in walsender processes

Changes

Fix SIGHUP and SIGUSR1 handling in walsender processes (Petr Jelinek, Andres Freund)

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesFix unnecessarily slow restarts of walreceiver processes due to race condition in postmaster

Changes

Fix unnecessarily slow restarts of walreceiver processes due to race condition in postmaster (Tom Lane)

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesFix cases where an INSERT or UPDATE assigns to more than one element of a column that is of domain-over-array type

Changes

Fix cases where an INSERT or UPDATE assigns to more than one element of a column that is of domain-over-array type (Tom Lane)

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsMove autogenerated array types out of the way during ALTER ... RENAME

Changes

Move autogenerated array types out of the way during ALTER ... RENAME (Vik Fearing)

Previously, we would rename a conflicting autogenerated array type out of the way during CREATE; this fix extends that behavior to renaming operations.

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsEnsure that ALTER USER ... SET accepts all the syntax variants that ALTER ROLE ... SET does

Changes

Ensure that ALTER USER ... SET accepts all the syntax variants that ALTER ROLE ... SET does (Peter Eisentraut)

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesProperly update dependency info when changing a datatype I/O function's argument or return type from opaque to the correct type

Changes

Properly update dependency info when changing a datatype I/O function's argument or return type from opaque to the correct type (Heikki Linnakangas)

CREATE TYPE updates I/O functions declared in this long-obsolete style, but it forgot to record a dependency on the type, allowing a subsequent DROP TYPE to leave broken function definitions behind.

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsReduce memory usage when ANALYZE processes a tsvector column

Changes

Reduce memory usage when ANALYZE processes a tsvector column (Heikki Linnakangas)

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesFix unnecessary precision loss and sloppy rounding when multiplying or dividing money values by integers or floats

Changes

Fix unnecessary precision loss and sloppy rounding when multiplying or dividing money values by integers or floats (Tom Lane)

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsTighten checks for whitespace in functions that parse identifiers, such as regprocedurein()

Changes

Tighten checks for whitespace in functions that parse identifiers, such as regprocedurein() (Tom Lane)

Depending on the prevailing locale, these functions could misinterpret fragments of multibyte characters as whitespace.

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsUse relevant #define symbols from Perl while compiling PL/Perl

Changes

Use relevant #define symbols from Perl while compiling PL/Perl (Ashutosh Sharma, Tom Lane)

This avoids portability problems, typically manifesting as a "handshake" mismatch during library load, when working with recent Perl versions.

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesIn psql, fix failure when COPY FROM STDIN is ended with a keyboard EOF signal and then another COPY FROM STDIN is attempted

Changes

In psql, fix failure when COPY FROM STDIN is ended with a keyboard EOF signal and then another COPY FROM STDIN is attempted (Thomas Munro)

This misbehavior was observed on BSD-derived platforms (including macOS), but not on most others.

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesFix pg_dump to not emit invalid SQL for an empty operator class

Changes

Fix pg_dump to not emit invalid SQL for an empty operator class (Daniel Gustafsson)

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesFix pg_dump output to stdout on Windows

Changes

Fix pg_dump output to stdout on Windows (Kuntal Ghosh)

A compressed plain-text dump written to stdout would contain corrupt data due to failure to put the file descriptor into binary mode.

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesFix pg_get_ruledef() to print correct output for the ON SELECT rule of a view whose columns have been renamed

Changes

Fix pg_get_ruledef() to print correct output for the ON SELECT rule of a view whose columns have been renamed (Tom Lane)

In some corner cases, pg_dump relies on pg_get_ruledef() to dump views, so that this error could result in dump/reload failures.

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesFix dumping of function expressions in the FROM clause in cases where the expression does not deparse into something that looks like a function call

Changes

Fix dumping of function expressions in the FROM clause in cases where the expression does not deparse into something that looks like a function call (Tom Lane)

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesFix pg_basebackup output to stdout on Windows

Changes

Fix pg_basebackup output to stdout on Windows (Haribabu Kommi)

A backup written to stdout would contain corrupt data due to failure to put the file descriptor into binary mode.

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesFix pg_upgrade to ensure that the ending WAL record does not have wal_level = minimum

Changes

Fix pg_upgrade to ensure that the ending WAL record does not have wal_level = minimum (Bruce Momjian)

This condition could prevent upgraded standby servers from reconnecting.

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsAlways use -fPIC, not -fpic, when building shared libraries with gcc

Changes

Always use -fPIC, not -fpic, when building shared libraries with gcc (Tom Lane)

This supports larger extension libraries on platforms where it makes a difference.

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesFix unescaped-braces issue in our build scripts for Microsoft MSVC, to avoid a warning or error from recent Perl versions

Changes

Fix unescaped-braces issue in our build scripts for Microsoft MSVC, to avoid a warning or error from recent Perl versions (Andrew Dunstan)

Related records (3)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsIn MSVC builds, handle the case where the openssl library is not within a VC subdirectory

Changes

In MSVC builds, handle the case where the openssl library is not within a VC subdirectory (Andrew Dunstan)

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsIn MSVC builds, add proper include path for libxml2 header files

Changes

In MSVC builds, add proper include path for libxml2 header files (Andrew Dunstan)

This fixes a former need to move things around in standard Windows installations of libxml2.

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsIn MSVC builds, recognize a Tcl library that is named tcl86.lib

Changes

In MSVC builds, recognize a Tcl library that is named tcl86.lib (Noah Misch)

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

How is this comparison generated?

The comparison follows PostgreSQL release notes from just after the source through the target version. For a major upgrade, maintenance releases from each older branch are included only up to the next major release date, and never after the target date. A major version such as 18 means its initial release, 18.0. Previews and development snapshots are labeled separately.

Entries come from the original English manuals. Release coverage and commit evidence are verified against upstream sources. Every entry retains its complete explanation and source link. Categories aid browsing; read the full notes for impact, conditions, and migration steps.

Fixes can be backported to several branches. Confirmed duplicates are merged conservatively, with every branch explanation retained. A note describing several independent fixes is excluded only when all are already present in the source. Major-release features remain distinct from related maintenance patches unless their complete original descriptions match. Uncertain matches are retained. This is a release-note history, not an exhaustive comparison of compiled binaries.

CVE results are calculated independently from the PostgreSQL security registry and vulnerability records. A CVE counts as gained protection only when the source is affected and the target is fixed or unaffected. Remaining vulnerabilities are listed separately. Security entries and distinct CVEs are counted separately.

Interaction inspired by pgversions.com and pgversionreport. Content comes from PostgreSQL release notes. See the release notes archive.