↑↓ select ↵ open ⌫ change scope Open full search

PG.CENTER connects PostgreSQL documentation, reference, and ecosystem knowledge. Maintained by Pigsty.

DocumentationVersion comparison

POSTGRESQL · VERSION COMPARE

PostgreSQL 9.5.4 release changes

All features, fixes, and compatibility notes in this release, with related records from other versions.

All changes in this release
All changes in this release

Includes changes after the source version through the target. A major version name means its initial release.

From PostgreSQL 9.0 onward: 17 major branches and 352 release notes. Updated 2026-09-26.

Complete release changes

9.5.4

2016-08-11

Export JSON
51changesFeatures, fixes, improvements
1releaseGrouped by release
2CVEsVulnerability IDs mentioned in these notes

9.5.4 HistoricalSupport ends 2021-02-11

Security records mentioned in this release 2 CVEs
CVEs mentioned in these notes, including possible follow-up fixes for earlier vulnerabilities
CVE / issueSeverityFixed version
CVE-2016-5424

Fix client programs' handling of special characters in database and role names

8.59.5.4
CVE-2016-5423

Fix possible mis-evaluation of nested CASE-WHEN expressions

4.39.5.4

PostgreSQL 9.5.4

Migration and compatibility

A dump/restore is not required for those running 9.5.X.

However, if you are upgrading from a version earlier than 9.5.2, see Section E.24.

SecurityFix possible mis-evaluation of nested CASE-WHEN expressions

Changes

Fix possible mis-evaluation of nested CASE-WHEN expressions (Heikki Linnakangas, Michael Paquier, Tom Lane)

A CASE expression appearing within the test value subexpression of another CASE could become confused about whether its own test value was null or not. Also, inlining of a SQL function implementing the equality operator used by a CASE expression could result in passing the wrong test value to functions called within a CASE expression in the SQL function's body. If the test values were of different data types, a crash might result; moreover such situations could be abused to allow disclosure of portions of server memory. (CVE-2016-5423)

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

SecurityFix client programs' handling of special characters in database and role names

Changes

Fix client programs' handling of special characters in database and role names (Noah Misch, Nathan Bossart, Michael Paquier)

Numerous places in vacuumdb and other client programs could become confused by database and role names containing double quotes or backslashes. Tighten up quoting rules to make that safe. Also, ensure that when a conninfo string is used as a database name parameter to these programs, it is correctly treated as such throughout.

Fix handling of paired double quotes in psql's \connect and \password commands to match the documentation.

Introduce a new -reuse-previous option in psql's \connect command to allow explicit control of whether to re-use connection parameters from a previous connection. (Without this, the choice is based on whether the database name looks like a conninfo string, as before.) This allows secure handling of database names containing special characters in pg_dumpall scripts.

pg_dumpall now refuses to deal with database and role names containing carriage returns or newlines, as it seems impractical to quote those characters safely on Windows. In future we may reject such names on the server side, but that step has not been taken yet.

These are considered security fixes because crafted object names containing special characters could have been used to execute commands with superuser privileges the next time a superuser executes pg_dumpall or other routine maintenance operations. (CVE-2016-5424)

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesFix corner-case misbehaviors for IS NULL/IS NOT NULL applied to nested composite values

Changes

Fix corner-case misbehaviors for IS NULL/IS NOT NULL applied to nested composite values (Andrew Gierth, Tom Lane)

The SQL standard specifies that IS NULL should return TRUE for a row of all null values (thus ROW(NULL,NULL) IS NULL yields TRUE), but this is not meant to apply recursively (thus ROW(NULL, ROW(NULL,NULL)) IS NULL yields FALSE). The core executor got this right, but certain planner optimizations treated the test as recursive (thus producing TRUE in both cases), and contrib/postgres_fdw could produce remote queries that misbehaved similarly.

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesFix "unrecognized node type" error for INSERT ... ON CONFLICT within a recursive CTE (a WITH item)

Changes

Fix "unrecognized node type" error for INSERT ... ON CONFLICT within a recursive CTE (a WITH item) (Peter Geoghegan)

Bug fixesFix INSERT ... ON CONFLICT to successfully match index expressions or index predicates that are simplified during the planner's expression preprocessing phase

Changes

Fix INSERT ... ON CONFLICT to successfully match index expressions or index predicates that are simplified during the planner's expression preprocessing phase (Tom Lane)

ImprovementsCorrectly handle violations of exclusion constraints that apply to the target table of an INSERT ... ON CONFLICT command, but are not one of the selected arbiter indexes

Changes

Correctly handle violations of exclusion constraints that apply to the target table of an INSERT ... ON CONFLICT command, but are not one of the selected arbiter indexes (Tom Lane)

Such a case should raise a normal constraint-violation error, but it got into an infinite loop instead.

Bug fixesFix INSERT ... ON CONFLICT to not fail if the target table has a unique index on OID

Changes

Fix INSERT ... ON CONFLICT to not fail if the target table has a unique index on OID (Tom Lane)

ImprovementsMake the inet and cidr data types properly reject IPv6 addresses with too many colon-separated fields

Changes

Make the inet and cidr data types properly reject IPv6 addresses with too many colon-separated fields (Tom Lane)

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesPrevent crash in close_ps() (the point ## lseg operator) for NaN input coordinates

Changes

Prevent crash in close_ps() (the point ## lseg operator) for NaN input coordinates (Tom Lane)

Make it return NULL instead of crashing.

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesAvoid possible crash in pg_get_expr() when inconsistent values are passed to it

Changes

Avoid possible crash in pg_get_expr() when inconsistent values are passed to it (Michael Paquier, Thomas Munro)

Related records (2)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesFix several one-byte buffer over-reads in to_number()

Changes

Fix several one-byte buffer over-reads in to_number() (Peter Eisentraut)

In several cases the to_number() function would read one more character than it should from the input string. There is a small chance of a crash, if the input happens to be adjacent to the end of memory.

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsDo not run the planner on the query contained in CREATE MATERIALIZED VIEW or CREATE TABLE AS when WITH NO DATA is specified

Changes

Do not run the planner on the query contained in CREATE MATERIALIZED VIEW or CREATE TABLE AS when WITH NO DATA is specified (Michael Paquier, Tom Lane)

This avoids some unnecessary failure conditions, for example if a stable function invoked by the materialized view depends on a table that doesn't exist yet.

Related records (2)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsAvoid unsafe intermediate state during expensive paths through heap_update()

Changes

Avoid unsafe intermediate state during expensive paths through heap_update() (Masahiko Sawada, Andres Freund)

Previously, these cases locked the target tuple (by setting its XMAX) but did not WAL-log that action, thus risking data integrity problems if the page were spilled to disk and then a database crash occurred before the tuple update could be completed.

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesFix hint bit update during WAL replay of row locking operations

Changes

Fix hint bit update during WAL replay of row locking operations (Andres Freund)

The only known consequence of this problem is that row locks held by a prepared, but uncommitted, transaction might fail to be enforced after a crash and restart.

Related records (2)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsAvoid unnecessary "could not serialize access" errors when acquiring FOR KEY SHARE row locks in serializable mode

Changes

Avoid unnecessary "could not serialize access" errors when acquiring FOR KEY SHARE row locks in serializable mode (Álvaro Herrera)

Related records (2)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsMake sure "expanded" datums returned by a plan node are read-only

Changes

Make sure "expanded" datums returned by a plan node are read-only (Tom Lane)

This avoids failures in some cases where the result of a lower plan node is referenced in multiple places in upper nodes. So far as core PostgreSQL is concerned, only array values returned by PL/pgSQL functions are at risk; but extensions might use expanded datums for other things.

Bug fixesAvoid crash in postgres -C when the specified variable has a null string value

Changes

Avoid crash in postgres -C when the specified variable has a null string value (Michael Paquier)

Related records (3)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsPrevent unintended waits for the receiver in WAL sender processes

Changes

Prevent unintended waits for the receiver in WAL sender processes (Kyotaro Horiguchi)

Bug fixesFix possible loss of large subtransactions in logical decoding

Changes

Fix possible loss of large subtransactions in logical decoding (Petru-Florin Mihancea)

Related records (1)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesFix failure of logical decoding when a subtransaction contains no actual changes

Changes

Fix failure of logical decoding when a subtransaction contains no actual changes (Marko Tiikkaja, Andrew Gierth)

Related records (1)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsEnsure that backends see up-to-date statistics for shared catalogs

Changes

Ensure that backends see up-to-date statistics for shared catalogs (Tom Lane)

The statistics collector failed to update the statistics file for shared catalogs after a request from a regular backend. This problem was partially masked because the autovacuum launcher regularly makes requests that did cause such updates; however, it became obvious with autovacuum disabled.

Related records (2)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsAvoid redundant writes of the statistics files when multiple backends request updates close together

Changes

Avoid redundant writes of the statistics files when multiple backends request updates close together (Tom Lane, Tomas Vondra)

Related records (2)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsAvoid consuming a transaction ID during VACUUM

Changes

Avoid consuming a transaction ID during VACUUM (Alexander Korotkov)

Some cases in VACUUM unnecessarily caused an XID to be assigned to the current transaction. Normally this is negligible, but if one is up against the XID wraparound limit, consuming more XIDs during anti-wraparound vacuums is a very bad thing.

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsPrevent possible failure when vacuuming multixact IDs in an installation that has been pg_upgrade'd from pre-9.3

Changes

Prevent possible failure when vacuuming multixact IDs in an installation that has been pg_upgrade'd from pre-9.3 (Andrew Gierth, Álvaro Herrera)

The usual symptom of this bug is errors like "MultiXactId NNN has not been created yet -- apparent wraparound".

Related records (2)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsWhen a manual ANALYZE specifies a column list, don't reset the table's changes_since_analyze counter

Changes

When a manual ANALYZE specifies a column list, don't reset the table's changes_since_analyze counter (Tom Lane)

If we're only analyzing some columns, we should not prevent routine auto-analyze from happening for the other columns.

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesFix ANALYZE's overestimation of n_distinct for a unique or nearly-unique column with many null entries

Changes

Fix ANALYZE's overestimation of n_distinct for a unique or nearly-unique column with many null entries (Tom Lane)

The nulls could get counted as though they were themselves distinct values, leading to serious planner misestimates in some types of queries.

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsPrevent autovacuum from starting multiple workers for the same shared catalog

Changes

Prevent autovacuum from starting multiple workers for the same shared catalog (Álvaro Herrera)

Normally this isn't much of a problem because the vacuum doesn't take long anyway; but in the case of a severely bloated catalog, it could result in all but one worker uselessly waiting instead of doing useful work on other tables.

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesFix bug in b-tree mark/restore processing

Changes

Fix bug in b-tree mark/restore processing (Kevin Grittner)

This error could lead to incorrect join results or assertion failures in a merge join whose inner source node is a b-tree indexscan.

ImprovementsAvoid duplicate buffer lock release when abandoning a b-tree index page deletion attempt

Changes

Avoid duplicate buffer lock release when abandoning a b-tree index page deletion attempt (Tom Lane)

This mistake prevented VACUUM from completing in some cases involving corrupt b-tree indexes.

Related records (1)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesFix building of large (bigger than shared_buffers) hash indexes

Changes

Fix building of large (bigger than shared_buffers) hash indexes (Tom Lane)

The code path used for large indexes contained a bug causing incorrect hash values to be inserted into the index, so that subsequent index searches always failed, except for tuples inserted into the index after the initial build.

ImprovementsPrevent infinite loop in GiST index build for geometric columns containing NaN component values

Changes

Prevent infinite loop in GiST index build for geometric columns containing NaN component values (Tom Lane)

Related records (3)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesFix possible crash during a nearest-neighbor (ORDER BY distance) indexscan on a contrib/btree_gist index on an interval column

Changes

Fix possible crash during a nearest-neighbor (ORDER BY distance) indexscan on a contrib/btree_gist index on an interval column (Peter Geoghegan)

Bug fixesFix "PANIC: failed to add BRIN tuple" error when attempting to update a BRIN index entry

Changes

Fix "PANIC: failed to add BRIN tuple" error when attempting to update a BRIN index entry (Álvaro Herrera)

Bug fixesFix possible crash during background worker shutdown

Changes

Fix possible crash during background worker shutdown (Dmitry Ivanov)

Bug fixesFix PL/pgSQL's handling of the INTO clause within IMPORT FOREIGN SCHEMA commands

Changes

Fix PL/pgSQL's handling of the INTO clause within IMPORT FOREIGN SCHEMA commands (Tom Lane)

Bug fixesFix contrib/btree_gin to handle the smallest possible bigint value correctly

Changes

Fix contrib/btree_gin to handle the smallest possible bigint value correctly (Peter Eisentraut)

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsTeach libpq to correctly decode server version from future servers

Changes

Teach libpq to correctly decode server version from future servers (Peter Eisentraut)

It's planned to switch to two-part instead of three-part server version numbers for releases after 9.6. Make sure that PQserverVersion() returns the correct value for such cases.

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesFix ecpg's code for unsigned long long array elements

Changes

Fix ecpg's code for unsigned long long array elements (Michael Meskes)

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsIn pg_dump with both -c and -C options, avoid emitting an unwanted CREATE SCHEMA public command

Changes

In pg_dump with both -c and -C options, avoid emitting an unwanted CREATE SCHEMA public command (David Johnston, Tom Lane)

Related records (3)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsImprove handling of SIGTERM/control-C in parallel pg_dump and pg_restore

Changes

Improve handling of SIGTERM/control-C in parallel pg_dump and pg_restore (Tom Lane)

Make sure that the worker processes will exit promptly, and also arrange to send query-cancel requests to the connected backends, in case they are doing something long-running such as a CREATE INDEX.

Related records (2)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesFix error reporting in parallel pg_dump and pg_restore

Changes

Fix error reporting in parallel pg_dump and pg_restore (Tom Lane)

Previously, errors reported by pg_dump or pg_restore worker processes might never make it to the user's console, because the messages went through the master process, and there were various deadlock scenarios that would prevent the master process from passing on the messages. Instead, just print everything to stderr. In some cases this will result in duplicate messages (for instance, if all the workers report a server shutdown), but that seems better than no message.

Related records (2)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsEnsure that parallel pg_dump or pg_restore on Windows will shut down properly after an error

Changes

Ensure that parallel pg_dump or pg_restore on Windows will shut down properly after an error (Kyotaro Horiguchi)

Previously, it would report the error, but then just sit until manually stopped by the user.

Related records (2)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsMake parallel pg_dump fail cleanly when run against a standby server

Changes

Make parallel pg_dump fail cleanly when run against a standby server (Magnus Hagander)

This usage is not supported unless --no-synchronized-snapshots is specified, but the error was not handled very well.

ImprovementsMake pg_dump behave better when built without zlib support

Changes

Make pg_dump behave better when built without zlib support (Kyotaro Horiguchi)

It didn't work right for parallel dumps, and emitted some rather pointless warnings in other cases.

Related records (2)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsMake pg_basebackup accept -Z 0 as specifying no compression

Changes

Make pg_basebackup accept -Z 0 as specifying no compression (Fujii Masao)

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesFix makefiles' rule for building AIX shared libraries to be safe for parallel make

Changes

Fix makefiles' rule for building AIX shared libraries to be safe for parallel make (Noah Misch)

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesFix TAP tests and MSVC scripts to work when build directory's path name contains spaces

Changes

Fix TAP tests and MSVC scripts to work when build directory's path name contains spaces (Michael Paquier, Kyotaro Horiguchi)

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsBe more predictable about reporting "statement timeout" versus "lock timeout"

Changes

Be more predictable about reporting "statement timeout" versus "lock timeout" (Tom Lane)

On heavily loaded machines, the regression tests sometimes failed due to reporting "lock timeout" even though the statement timeout should have occurred first.

Related records (2)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsMake regression tests safe for Danish and Welsh locales

Changes

Make regression tests safe for Danish and Welsh locales (Jeff Janes, Tom Lane)

Change some test data that triggered the unusual sorting rules of these locales.

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsUpdate our copy of the timezone code to match IANA's tzcode release 2016c

Changes

Update our copy of the timezone code to match IANA's tzcode release 2016c (Tom Lane)

This is needed to cope with anticipated future changes in the time zone data files. It also fixes some corner-case bugs in coping with unusual time zones.

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsUpdate time zone data files to tzdata release 2016f for DST law changes in Kemerovo and Novosibirsk, plus historical corrections for Azerbaijan, Belarus, and Morocco.

Changes

Update time zone data files to tzdata release 2016f for DST law changes in Kemerovo and Novosibirsk, plus historical corrections for Azerbaijan, Belarus, and Morocco.

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

How is this comparison generated?

The comparison follows PostgreSQL release notes from just after the source through the target version. For a major upgrade, maintenance releases from each older branch are included only up to the next major release date, and never after the target date. A major version such as 18 means its initial release, 18.0. Previews and development snapshots are labeled separately.

Entries come from the original English manuals. Release coverage and commit evidence are verified against upstream sources. Every entry retains its complete explanation and source link. Categories aid browsing; read the full notes for impact, conditions, and migration steps.

Fixes can be backported to several branches. Confirmed duplicates are merged conservatively, with every branch explanation retained. A note describing several independent fixes is excluded only when all are already present in the source. Major-release features remain distinct from related maintenance patches unless their complete original descriptions match. Uncertain matches are retained. This is a release-note history, not an exhaustive comparison of compiled binaries.

CVE results are calculated independently from the PostgreSQL security registry and vulnerability records. A CVE counts as gained protection only when the source is affected and the target is fixed or unaffected. Remaining vulnerabilities are listed separately. Security entries and distinct CVEs are counted separately.

Interaction inspired by pgversions.com and pgversionreport. Content comes from PostgreSQL release notes. See the release notes archive.