↑↓ select ↵ open ⌫ change scope Open full search

PG.CENTER connects PostgreSQL documentation, reference, and ecosystem knowledge. Maintained by Pigsty.

DocumentationVersion comparison

POSTGRESQL · VERSION COMPARE

PostgreSQL 14.7 release changes

All features, fixes, and compatibility notes in this release, with related records from other versions.

All changes in this release
All changes in this release

Includes changes after the source version through the target. A major version name means its initial release.

From PostgreSQL 9.0 onward: 17 major branches and 352 release notes. Updated 2026-09-26.

Complete release changes

14.7

2023-02-09

Export JSON
47changesFeatures, fixes, improvements
1releaseGrouped by release
1CVEVulnerability IDs mentioned in these notes

14.7 SupportedSupport ends 2026-11-12

Security records mentioned in this release 1 CVE
CVEs mentioned in these notes, including possible follow-up fixes for earlier vulnerabilities
CVE / issueSeverityFixed version
CVE-2022-41862

libpq can leak memory contents after GSSAPI transport encryption initiation fails

3.714.7

PostgreSQL 14.7

Migration and compatibility

A dump/restore is not required for those running 14.X.

However, if you are upgrading from a version earlier than 14.4, see Section E.21.

Securitylibpq can leak memory contents after GSSAPI transport encryption initiation fails

Changes

libpq can leak memory contents after GSSAPI transport encryption initiation fails (Jacob Champion) §

A modified server, or an unauthenticated man-in-the-middle, can send a not-zero-terminated error message during setup of GSSAPI (Kerberos) transport encryption. libpq will then copy that string, as well as following bytes in application memory up to the next zero byte, to its error report. Depending on what the calling application does with the error report, this could result in disclosure of application memory contents. There is also a small probability of a crash due to reading beyond the end of memory. Fix by properly zero-terminating the server message. (CVE-2022-41862)

Related records (3)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesFix calculation of which GENERATED columns need to be updated in child tables during an UPDATE on a partitioned table or inheritance tree

Changes

Fix calculation of which GENERATED columns need to be updated in child tables during an UPDATE on a partitioned table or inheritance tree (Amit Langote, Tom Lane) § §

This fixes failure to update GENERATED columns that do not exist in the parent table, or that have different dependencies than are in the parent column's generation expression.

Related records (2)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsAllow a WITH RECURSIVE ... CYCLE CTE to access its output column

Changes

Allow a WITH RECURSIVE ... CYCLE CTE to access its output column (Tom Lane) §

A reference to the SET column from within the CTE would fail with “cache lookup failed for type 0”.

Related records (1)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesFix handling of pending inserts when doing a bulk insertion to a foreign table

Changes

Fix handling of pending inserts when doing a bulk insertion to a foreign table (Etsuro Fujita) § §

In some cases pending insertions were not flushed to the FDW soon enough, leading to logical inconsistencies, for example BEFORE ROW triggers not seeing rows they should be able to see.

Related records (1)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsAllow REPLICA IDENTITY to be set on an index that's not (yet) valid

Changes

Allow REPLICA IDENTITY to be set on an index that's not (yet) valid (Tom Lane) §

When pg_dump dumps a partitioned index that's marked REPLICA IDENTITY, it generates a command sequence that applies REPLICA IDENTITY before the partitioned index has been marked valid, causing restore to fail. There seems no very good reason to prohibit doing it in that order, so allow it. The marking will have no effect anyway until the index becomes valid.

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesFix handling of DEFAULT markers in rules that perform an INSERT from a multi-row VALUES list

Changes

Fix handling of DEFAULT markers in rules that perform an INSERT from a multi-row VALUES list (Dean Rasheed) §

In some cases a DEFAULT marker would not get replaced with the proper default-value expression, leading to an “unrecognized node type” error.

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsReject uses of undefined variables in jsonpath existence checks

Changes

Reject uses of undefined variables in jsonpath existence checks (Alexander Korotkov, David G. Johnston) §

While jsonpath match operators threw an error for an undefined variable in the path pattern, the existence operators silently treated it as a match.

Related records (3)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesFix jsonb subscripting to cope with toasted subscript values

Changes

Fix jsonb subscripting to cope with toasted subscript values (Tom Lane, David G. Johnston) §

Using a text value fetched directly from a table as a jsonb subscript was likely to fail. Fetches would usually not find any matching element. Assignments could store the value with a garbage key, although keys long enough to cause that problem are probably rare in the field.

Related records (1)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesFix edge-case data corruption in parallel hash joins

Changes

Fix edge-case data corruption in parallel hash joins (Dmitry Astapov) §

If the final chunk of a large tuple being written out to a temporary file was exactly 32760 bytes, it would be corrupted due to a fencepost bug. The query would typically fail later with corrupted-data symptoms.

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsHonor non-default settings of checkpoint_completion_target

Changes

Honor non-default settings of checkpoint_completion_target (Bharath Rupireddy) §

Internal state was not updated after a change in checkpoint_completion_target, possibly resulting in performing checkpoint I/O faster or slower than desired, especially if that setting was changed on-the-fly.

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesLog the correct ending timestamp in recovery_target_xid mode

Changes

Log the correct ending timestamp in recovery_target_xid mode (Tom Lane) §

When ending recovery based on the recovery_target_xid setting with recovery_target_inclusive = off, we printed an incorrect timestamp (always 2000-01-01) in the “recovery stopping before ... transaction” log message.

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsImprove error reporting for some buffered file read failures

Changes

Improve error reporting for some buffered file read failures (Peter Eisentraut) §

Correctly report a short read, giving the numbers of bytes desired and actually read, instead of reporting an irrelevant error code. Most places got this right already, but some recently-written replication logic did not.

Related records (2)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsIn extended query protocol, avoid an immediate commit after ANALYZE if we're running a pipeline

Changes

In extended query protocol, avoid an immediate commit after ANALYZE if we're running a pipeline (Tom Lane) §

If there's not been an explicit BEGIN TRANSACTION, ANALYZE would take it on itself to commit, which should not happen within a pipelined series of commands.

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsReject cancel request packets having the wrong length

Changes

Reject cancel request packets having the wrong length (Andrey Borodin) §

The server would process a cancel request even if its length word was too small. This led to reading beyond the end of the allocated buffer. In theory that could cause a segfault, but it seems quite unlikely to happen in practice, since the buffer would have to be very close to the end of memory. The more likely outcome was a bogus log message about wrong backend PID or cancel code. Complain about the wrong length, instead.

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsAdd recursion and looping defenses in subquery pullup

Changes

Add recursion and looping defenses in subquery pullup (Tom Lane) §

A contrived query can result in deep recursion and unreasonable amounts of time spent trying to flatten subqueries. A proper fix for that seems unduly invasive for a back-patch, but we can at least add stack depth checks and an interrupt check to allow the query to be cancelled.

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesFix planner issues when combining Memoize nodes with partitionwise joins or parameterized nestloops

Changes

Fix planner issues when combining Memoize nodes with partitionwise joins or parameterized nestloops (Richard Guo) § §

These errors could lead to not using Memoize in contexts where it would be useful, or possibly to wrong query plans.

Related records (1)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesFix partitionwise-join code to tolerate failure to produce a plan for each partition

Changes

Fix partitionwise-join code to tolerate failure to produce a plan for each partition (Tom Lane) §

This could result in “could not devise a query plan for the given query” errors.

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsLimit the amount of cleanup work done by get_actual_variable_range

Changes

Limit the amount of cleanup work done by get_actual_variable_range (Simon Riggs) §

Planner runs occurring just after deletion of a large number of tuples appearing at the end of an index could expend significant amounts of work setting the “killed” bits for those index entries. Limit the amount of work done in any one query by giving up on this process after examining 100 heap pages. All the cleanup will still happen eventually, but without so large a performance hiccup.

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesFix under-parenthesized display of AT TIME ZONE constructs

Changes

Fix under-parenthesized display of AT TIME ZONE constructs (Tom Lane) §

This could result in dump/restore failures for rules or views in which an argument of AT TIME ZONE is itself an expression.

Related records (1)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsPrevent clobbering of cached parsetrees for utility statements in SQL functions

Changes

Prevent clobbering of cached parsetrees for utility statements in SQL functions (Tom Lane, Daniel Gustafsson) §

If a SQL-language function executes the same utility command more than once within a single calling query, it could crash or report strange errors such as “unrecognized node type”.

Related records (1)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsEnsure that execution of full-text-search queries can be cancelled while they are performing phrase matches

Changes

Ensure that execution of full-text-search queries can be cancelled while they are performing phrase matches (Tom Lane) §

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesFix memory leak in hashing strings with nondeterministic collations

Changes

Fix memory leak in hashing strings with nondeterministic collations (Jeff Davis) §

Related records (3)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesFix deadlock between DROP DATABASE and logical replication worker process

Changes

Fix deadlock between DROP DATABASE and logical replication worker process (Hou Zhijie) §

This was caused by an ill-advised choice to block interrupts while creating a logical replication slot in the worker. In version 15 that could lead to an undetected deadlock. In version 14, no deadlock has been observed, but it's still a bad idea to block interrupts while waiting for network I/O.

Related records (1)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsClean up the libpq connection object after a failed replication connection attempt

Changes

Clean up the libpq connection object after a failed replication connection attempt (Andres Freund) §

The previous coding leaked the connection object. In background code paths that's pretty harmless because the calling process will give up and exit. But in commands such as CREATE SUBSCRIPTION, such a failure resulted in a small session-lifespan memory leak.

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsIn hot-standby servers, reduce processing effort for tracking XIDs known to be active on the primary

Changes

In hot-standby servers, reduce processing effort for tracking XIDs known to be active on the primary (Simon Riggs, Michail Nikolaev) §

Insufficiently-aggressive cleanup of the KnownAssignedXids array could lead to poor performance, particularly when max_connections is set to a large value on the standby.

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsIgnore invalidated logical-replication slots while determining oldest catalog xmin

Changes

Ignore invalidated logical-replication slots while determining oldest catalog xmin (Sirisha Chamarthi) §

A replication slot could prevent cleanup of dead tuples in the system catalogs even after it becomes invalidated due to exceeding max_slot_wal_keep_size. Thus, failure of a replication consumer could lead to indefinitely-large catalog bloat.

Related records (2)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsIn logical decoding, notify the remote node when a transaction is detected to have crashed

Changes

In logical decoding, notify the remote node when a transaction is detected to have crashed (Hou Zhijie) §

After a server restart, we'll re-stream the changes for transactions occurring shortly before the restart. Some of these transactions probably never completed; when we realize that one didn't we throw away the relevant decoding state locally, but we neglected to tell the subscriber about it. That led to the subscriber keeping useless streaming files until it's next restarted.

Related records (1)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesFix uninitialized-memory usage in logical decoding

Changes

Fix uninitialized-memory usage in logical decoding (Masahiko Sawada) §

In certain cases, resumption of logical decoding could try to re-use XID data that had already been freed, leading to unpredictable behavior.

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsAvoid rare “failed to acquire cleanup lock” panic during WAL replay of hash-index page split operations

Changes

Avoid rare “failed to acquire cleanup lock” panic during WAL replay of hash-index page split operations (Robert Haas) §

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsAdvance a heap page's LSN when setting its all-visible bit during WAL replay

Changes

Advance a heap page's LSN when setting its all-visible bit during WAL replay (Jeff Davis) §

Failure to do this left the page possibly different on standby servers than the primary, and violated some other expectations about when the LSN changes. This seems only a theoretical hazard so far as PostgreSQL itself is concerned, but it could upset third-party tools.

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsPrevent unsafe usage of a relation cache entry's rd_smgr pointer

Changes

Prevent unsafe usage of a relation cache entry's rd_smgr pointer (Amul Sul) §

Remove various assumptions that rd_smgr would stay valid over a series of operations, by wrapping all uses of it in a function that will recompute it if needed. This prevents bugs occurring when an unexpected cache flush occurs partway through such a series.

Related records (3)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesFix int64_div_fast_to_numeric() to work for a wider range of inputs

Changes

Fix int64_div_fast_to_numeric() to work for a wider range of inputs (Dean Rasheed) §

This function misbehaved with some values of its second argument. No such usages exist in core PostgreSQL, but it's clearly a hazard for external modules, so repair.

Related records (1)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesFix latent buffer-overrun problem in WaitEventSet logic

Changes

Fix latent buffer-overrun problem in WaitEventSet logic (Thomas Munro) §

The epoll-based and kqueue-based implementations could ask the kernel for too many events if the size of their internal buffer was different from the size of the caller's output buffer. That case is not known to occur in released PostgreSQL versions, but this error is a hazard for external modules and future bug fixes.

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsAvoid nominally-undefined behavior when accessing shared memory in 32-bit builds

Changes

Avoid nominally-undefined behavior when accessing shared memory in 32-bit builds (Andres Freund) §

clang's undefined-behavior sanitizer complained about use of a pointer that was less aligned than it should be. It's very unlikely that this would cause a problem in non-debug builds, but it's worth fixing for testing purposes.

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesFix assertion failure in BRIN minmax-multi opclasses

Changes

Fix assertion failure in BRIN minmax-multi opclasses (Tomas Vondra) §

The assertion was overly strict, so this mistake was harmless in non-assert builds.

Related records (1)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsRemove faulty assertion in useless-RESULT-RTE optimization logic

Changes

Remove faulty assertion in useless-RESULT-RTE optimization logic (Tom Lane) §

Related records (3)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesFix copy-and-paste errors in cache-lookup-failure messages for ACL checks

Changes

Fix copy-and-paste errors in cache-lookup-failure messages for ACL checks (Justin Pryzby) §

In principle these errors should never be reached. But if they are, some of them reported the wrong type of object.

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsIn pg_dump, avoid calling unsafe server functions before we have locks on the tables to be examined

Changes

In pg_dump, avoid calling unsafe server functions before we have locks on the tables to be examined (Tom Lane, Gilles Darold) § §

pg_dump uses certain server functions that can fail if examining a table that gets dropped concurrently. Avoid this type of failure by ensuring that we obtain access share lock before inquiring too deeply into a table's properties, and that we don't apply such functions to tables we don't intend to dump at all.

Related records (3)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesFix psql's \sf and \ef commands to handle SQL-language functions that have SQL-standard function bodies

Changes

Fix psql's \sf and \ef commands to handle SQL-language functions that have SQL-standard function bodies (Tom Lane) §

These commands misidentified the start of the function body when it used new-style syntax.

Related records (1)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesFix tab completion of ALTER FUNCTION/PROCEDURE/ROUTINE ... SET SCHEMA

Changes

Fix tab completion of ALTER FUNCTION/PROCEDURE/ROUTINE ... SET SCHEMA (Dean Rasheed) §

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesFix contrib/seg to not crash or print garbage if an input number has more than 127 digits

Changes

Fix contrib/seg to not crash or print garbage if an input number has more than 127 digits (Tom Lane) §

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesFix build on Microsoft Visual Studio 2013

Changes

Fix build on Microsoft Visual Studio 2013 (Tom Lane) §

A previous patch supposed that all platforms of interest have snprintf(), but MSVC 2013 isn't quite there yet. Revert to using sprintf() on that platform.

Related records (3)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesFix compile failure in building PL/Perl with MSVC when using Strawberry Perl

Changes

Fix compile failure in building PL/Perl with MSVC when using Strawberry Perl (Andrew Dunstan) §

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesFix mismatch of PL/Perl built with MSVC versus a Perl library built with gcc

Changes

Fix mismatch of PL/Perl built with MSVC versus a Perl library built with gcc (Andrew Dunstan) §

Such combinations could previously fail with “loadable library and perl binaries are mismatched” errors.

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsSuppress compiler warnings from Perl's header files

Changes

Suppress compiler warnings from Perl's header files (Andres Freund) §

Our preferred compiler options provoke warnings about constructs appearing in recent versions of Perl's header files. When using gcc, we can suppress these warnings with a pragma.

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesFix pg_waldump to build on compilers that don't discard unused static-inline functions

Changes

Fix pg_waldump to build on compilers that don't discard unused static-inline functions (Tom Lane) §

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsUpdate time zone data files to tzdata release 2022g for DST law changes in Greenland and Mexico, plus historical corrections for northern Canada, Colombia, and Singapore.

Changes

Update time zone data files to tzdata release 2022g for DST law changes in Greenland and Mexico, plus historical corrections for northern Canada, Colombia, and Singapore. (Tom Lane) §

Notably, a new timezone America/Ciudad_Juarez has been split off from America/Ojinaga.

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

How is this comparison generated?

The comparison follows PostgreSQL release notes from just after the source through the target version. For a major upgrade, maintenance releases from each older branch are included only up to the next major release date, and never after the target date. A major version such as 18 means its initial release, 18.0. Previews and development snapshots are labeled separately.

Entries come from the original English manuals. Release coverage and commit evidence are verified against upstream sources. Every entry retains its complete explanation and source link. Categories aid browsing; read the full notes for impact, conditions, and migration steps.

Fixes can be backported to several branches. Confirmed duplicates are merged conservatively, with every branch explanation retained. A note describing several independent fixes is excluded only when all are already present in the source. Major-release features remain distinct from related maintenance patches unless their complete original descriptions match. Uncertain matches are retained. This is a release-note history, not an exhaustive comparison of compiled binaries.

CVE results are calculated independently from the PostgreSQL security registry and vulnerability records. A CVE counts as gained protection only when the source is affected and the target is fixed or unaffected. Remaining vulnerabilities are listed separately. Security entries and distinct CVEs are counted separately.

Interaction inspired by pgversions.com and pgversionreport. Content comes from PostgreSQL release notes. See the release notes archive.