PostgreSQL 10
Read the English manualEnd of life · Recorded build 10.23 · 2022-11-10
This major branch is no longer supported. These records describe its history; the absence of newer security records does not establish that it is safe to run.
- First stable release
- 2017-10-05
- Support end
- 2022-11-10
- Indexed releases
- 24
- Original release-note entries
- 1140
Manuals & provenance
PostgreSQL 10 English manual · 1085 loaded pages.
Manual loaded 2026-09-27T00:10:47.078613.
Release entries: 2026-09-26. Security evidence: 2026-09-26. PDF links use the verified English manifest and locally available files. Lifecycle: PostgreSQL versioning policy.
Upgrade considerations
Major upgrades need a migration method such as dump/reload or pg_upgrade. Read the intervening major-release notes and the target manual. Minor updates can also require extra steps; review the specific release's migration notes. Official upgrade policy.
Compatibility notes for 10.0 · Changes from the initial release through 10.23
Original migration guidance for 10.0
A dump/restore using pg_dumpall or use of pg_upgrade or logical replication is required for those wishing to migrate data from any previous release. See Section 18.6 for general information on migrating to new major releases.
Version 10 contains a number of changes that may affect compatibility with previous releases. Observe the following incompatibilities:
Release history
Every indexed release keeps its original occurrences. CVE counts below are mentions in its notes, including follow-up corrections; they do not count newly fixed vulnerabilities.
| Release | Date / snapshot cutoff | All changes | Bug fixes | Migration entries | CVE mentions |
|---|---|---|---|---|---|
| 10.23 | 2022-11-10 | 29 | 13 | 0 | 0 |
| 10.22 | 2022-08-11 | 34 | 11 | 0 | 2 |
| 10.21 | 2022-05-12 | 29 | 14 | 0 | 1 |
| 10.20 | 2022-02-10 | 28 | 13 | 0 | 0 |
| 10.19 | 2021-11-11 | 50 | 21 | 0 | 2 |
| 10.18 | 2021-08-12 | 52 | 17 | 0 | 2 |
| 10.17 | 2021-05-13 | 30 | 15 | 0 | 2 |
| 10.16 | 2021-02-11 | 40 | 18 | 0 | 0 |
| 10.15 | 2020-11-12 | 40 | 14 | 0 | 3 |
| 10.14 | 2020-08-13 | 35 | 17 | 0 | 3 |
| 10.13 | 2020-05-14 | 45 | 19 | 0 | 0 |
| 10.12 | 2020-02-13 | 46 | 24 | 0 | 1 |
| 10.11 | 2019-11-14 | 59 | 26 | 0 | 0 |
| 10.10 | 2019-08-08 | 31 | 13 | 0 | 2 |
| 10.9 | 2019-06-20 | 22 | 13 | 0 | 1 |
| 10.8 | 2019-05-09 | 43 | 27 | 0 | 2 |
| 10.7 | 2019-02-14 | 54 | 26 | 0 | 0 |
| 10.6 | 2018-11-08 | 71 | 34 | 0 | 1 |
| 10.5 | 2018-08-09 | 47 | 22 | 0 | 2 |
| 10.4 | 2018-05-10 | 53 | 30 | 0 | 1 |
| 10.3 | 2018-03-01 | 11 | 6 | 0 | 1 |
| 10.2 | 2018-02-08 | 65 | 33 | 0 | 2 |
| 10.1 | 2017-11-09 | 37 | 18 | 0 | 3 |
| 10.0 | 2017-10-05 | 189 | 2 | 27 | 0 |
Initial release changes
Original entries from 10.0, including feature changes and compatibility notes. Categories aid browsing; they are not upstream classifications.
189 of 189 original entries.
Hash indexes must be rebuilt after pg_upgrade-ing from any previous major PostgreSQL version Compatibility Migration
Hash indexes must be rebuilt after pg_upgrade-ing from any previous major PostgreSQL version (Mithun Cy, Robert Haas, Amit Kapila)
Major hash index improvements necessitated this requirement. pg_upgrade will create a script to assist with this.
Original release occurrence ·
10.0/migration/001Rename write-ahead log directory pg_xlog to pg_wal, and rename transaction status directory pg_clog to pg_xact Compatibility Migration
Rename write-ahead log directory
pg_xlogtopg_wal, and rename transaction status directorypg_clogtopg_xact(Michael Paquier)Users have occasionally thought that these directories contained only inessential log files, and proceeded to remove write-ahead log files or transaction status files manually, causing irrecoverable data loss. These name changes are intended to discourage such errors in future.
Original release occurrence ·
10.0/migration/002Rename SQL functions, tools, and options that reference “xlog” to “wal” Compatibility Migration
Rename SQL functions, tools, and options that reference “xlog” to “wal” (Robert Haas)
For example,
pg_switch_xlog()becomespg_switch_wal(), pg_receivexlog becomes pg_receivewal, and--xlogdirbecomes--waldir. This is for consistency with the change of thepg_xlogdirectory name; in general, the “xlog” terminology is no longer used in any user-facing places.Original release occurrence ·
10.0/migration/003Rename WAL-related functions and views to use lsn instead of location Compatibility Migration
Rename WAL-related functions and views to use
lsninstead oflocation(David Rowley)There was previously an inconsistent mixture of the two terminologies.
Original release occurrence ·
10.0/migration/004Change the implementation of set-returning functions appearing in a query's SELECT list Compatibility Migration
Change the implementation of set-returning functions appearing in a query's
SELECTlist (Andres Freund)Set-returning functions are now evaluated before evaluation of scalar expressions in the
SELECTlist, much as though they had been placed in aLATERAL FROM-clause item. This allows saner semantics for cases where multiple set-returning functions are present. If they return different numbers of rows, the shorter results are extended to match the longest result by adding nulls. Previously the results were cycled until they all terminated at the same time, producing a number of rows equal to the least common multiple of the functions' periods. In addition, set-returning functions are now disallowed withinCASEandCOALESCEconstructs. For more information see Section 37.4.8.Original release occurrence ·
10.0/migration/005Use standard row constructor syntax in UPDATE ... SET (column_list) = row_constructor Compatibility Migration
Use standard row constructor syntax in
UPDATE ... SET ((Tom Lane)column_list) =row_constructorThe
row_constructorcan now begin with the keywordROW; previously that had to be omitted. If just one column name appears in thecolumn_list, then therow_constructornow must use theROWkeyword, since otherwise it is not a valid row constructor but just a parenthesized expression. Also, an occurrence ofwithin thetable_name.*row_constructoris now expanded into multiple columns, as occurs in other uses ofrow_constructors.Original release occurrence ·
10.0/migration/006When ALTER TABLE ... ADD PRIMARY KEY marks columns NOT NULL, that change now propagates to inheritance child tables as well Compatibility Migration
When
ALTER TABLE ... ADD PRIMARY KEYmarks columnsNOT NULL, that change now propagates to inheritance child tables as well (Michael Paquier)Original release occurrence ·
10.0/migration/007Prevent statement-level triggers from firing more than once per statement Compatibility Migration
Prevent statement-level triggers from firing more than once per statement (Tom Lane)
Cases involving writable CTEs updating the same table updated by the containing statement, or by another writable CTE, fired
BEFORE STATEMENTorAFTER STATEMENTtriggers more than once. Also, if there were statement-level triggers on a table affected by a foreign key enforcement action (such asON DELETE CASCADE), they could fire more than once per outer SQL statement. This is contrary to the SQL standard, so change it.Original release occurrence ·
10.0/migration/008Move sequences' metadata fields into a new pg_sequence system catalog Compatibility Migration
Move sequences' metadata fields into a new
pg_sequencesystem catalog (Peter Eisentraut)A sequence relation now stores only the fields that can be modified by
nextval(), that islast_value,log_cnt, andis_called. Other sequence properties, such as the starting value and increment, are kept in a corresponding row of thepg_sequencecatalog.ALTER SEQUENCEupdates are now fully transactional, implying that the sequence is locked until commit. Thenextval()andsetval()functions remain nontransactional.The main incompatibility introduced by this change is that selecting from a sequence relation now returns only the three fields named above. To obtain the sequence's other properties, applications must look into
pg_sequence. The new system viewpg_sequencescan also be used for this purpose; it provides column names that are more compatible with existing code.Also, sequences created for
SERIALcolumns now generate positive 32-bit wide values, whereas previous versions generated 64-bit wide values. This has no visible effect if the values are only stored in a column.The output of psql's
\dcommand for a sequence has been redesigned, too.Original release occurrence ·
10.0/migration/009Make pg_basebackup stream the WAL needed to restore the backup by default Compatibility Migration
Make pg_basebackup stream the WAL needed to restore the backup by default (Magnus Hagander)
This changes pg_basebackup's
-X/--wal-methoddefault tostream. An option valuenonehas been added to reproduce the old behavior. The pg_basebackup option-xhas been removed (instead, use-X fetch).Original release occurrence ·
10.0/migration/010Change how logical replication uses pg_hba.conf Compatibility Migration
Change how logical replication uses
pg_hba.conf(Peter Eisentraut)In previous releases, a logical replication connection required the
replicationkeyword in the database column. As of this release, logical replication matches a normal entry with a database name or keywords such asall. Physical replication continues to use thereplicationkeyword. Since built-in logical replication is new in this release, this change only affects users of third-party logical replication plugins.Original release occurrence ·
10.0/migration/011Make all pg_ctl actions wait for completion by default Compatibility Migration
Make all pg_ctl actions wait for completion by default (Peter Eisentraut)
Previously some pg_ctl actions didn't wait for completion, and required the use of
-wto do so.Original release occurrence ·
10.0/migration/012Change the default value of the log_directory server parameter from pg_log to log Compatibility Migration
Change the default value of the log_directory server parameter from
pg_logtolog(Andreas Karlsson)Original release occurrence ·
10.0/migration/013Add configuration option ssl_dh_params_file to specify file name for custom OpenSSL DH parameters Compatibility Migration
Add configuration option ssl_dh_params_file to specify file name for custom OpenSSL DH parameters (Heikki Linnakangas)
This replaces the hardcoded, undocumented file name
dh1024.pem. Note thatdh1024.pemis no longer examined by default; you must set this option if you want to use custom DH parameters.Original release occurrence ·
10.0/migration/014Increase the size of the default DH parameters used for OpenSSL ephemeral DH ciphers to 2048 bits Compatibility Migration
Increase the size of the default DH parameters used for OpenSSL ephemeral DH ciphers to 2048 bits (Heikki Linnakangas)
The size of the compiled-in DH parameters has been increased from 1024 to 2048 bits, making DH key exchange more resistant to brute-force attacks. However, some old SSL implementations, notably some revisions of Java Runtime Environment version 6, will not accept DH parameters longer than 1024 bits, and hence will not be able to connect over SSL. If it's necessary to support such old clients, you can use custom 1024-bit DH parameters instead of the compiled-in defaults. See ssl_dh_params_file.
Original release occurrence ·
10.0/migration/015Remove the ability to store unencrypted passwords on the server Compatibility Migration
Remove the ability to store unencrypted passwords on the server (Heikki Linnakangas)
The password_encryption server parameter no longer supports
offorplain. TheUNENCRYPTEDoption is no longer supported inCREATE/ALTER USER ... PASSWORD. Similarly, the--unencryptedoption has been removed from createuser. Unencrypted passwords migrated from older versions will be stored encrypted in this release. The default setting forpassword_encryptionis stillmd5.Original release occurrence ·
10.0/migration/016Add min_parallel_table_scan_size and min_parallel_index_scan_size server parameters to control parallel queries Compatibility Migration
Add min_parallel_table_scan_size and min_parallel_index_scan_size server parameters to control parallel queries (Amit Kapila, Robert Haas)
These replace
min_parallel_relation_size, which was found to be too generic.Original release occurrence ·
10.0/migration/017Don't downcase unquoted text within shared_preload_libraries and related server parameters Compatibility Migration
Don't downcase unquoted text within shared_preload_libraries and related server parameters (QL Zhuo)
These settings are really lists of file names, but they were previously treated as lists of SQL identifiers, which have different parsing rules.
Original release occurrence ·
10.0/migration/018Remove sql_inheritance server parameter Compatibility Migration
Remove
sql_inheritanceserver parameter (Robert Haas)Changing this setting from the default value caused queries referencing parent tables to not include child tables. The SQL standard requires them to be included, however, and this has been the default since PostgreSQL 7.1.
Original release occurrence ·
10.0/migration/019Allow multi-dimensional arrays to be passed into PL/Python functions, and returned as nested Python lists Compatibility Migration
Allow multi-dimensional arrays to be passed into PL/Python functions, and returned as nested Python lists (Alexey Grishchenko, Dave Cramer, Heikki Linnakangas)
This feature requires a backwards-incompatible change to the handling of arrays of composite types in PL/Python. Previously, you could return an array of composite values by writing, e.g.,
[[col1, col2], [col1, col2]]; but now that is interpreted as a two-dimensional array. Composite types in arrays must now be written as Python tuples, not lists, to resolve the ambiguity; that is, write[(col1, col2), (col1, col2)]instead.Original release occurrence ·
10.0/migration/020Remove PL/Tcl's “module” auto-loading facility Compatibility Migration
Remove PL/Tcl's “module” auto-loading facility (Tom Lane)
This functionality has been replaced by new server parameters pltcl.start_proc and pltclu.start_proc, which are easier to use and more similar to features available in other PLs.
Original release occurrence ·
10.0/migration/021Remove pg_dump/pg_dumpall support for dumping from pre-8.0 servers Compatibility Migration
Remove pg_dump/pg_dumpall support for dumping from pre-8.0 servers (Tom Lane)
Users needing to dump from pre-8.0 servers will need to use dump programs from PostgreSQL 9.6 or earlier. The resulting output should still load successfully into newer servers.
Original release occurrence ·
10.0/migration/022Remove support for floating-point timestamps and intervals Compatibility Migration
Remove support for floating-point timestamps and intervals (Tom Lane)
This removes configure's
--disable-integer-datetimesoption. Floating-point timestamps have few advantages and have not been the default since PostgreSQL 8.3.Original release occurrence ·
10.0/migration/023Remove server support for client/server protocol version 1.0 Compatibility Migration
Remove server support for client/server protocol version 1.0 (Tom Lane)
This protocol hasn't had client support since PostgreSQL 6.3.
Original release occurrence ·
10.0/migration/024Remove contrib/tsearch2 module Compatibility Migration
Remove
contrib/tsearch2module (Robert Haas)This module provided compatibility with the version of full text search that shipped in pre-8.3 PostgreSQL releases.
Original release occurrence ·
10.0/migration/025Remove createlang and droplang command-line applications Compatibility Migration
Remove createlang and droplang command-line applications (Peter Eisentraut)
These had been deprecated since PostgreSQL 9.1. Instead, use
CREATE EXTENSIONandDROP EXTENSIONdirectly.Original release occurrence ·
10.0/migration/026Remove support for version-0 function calling conventions Compatibility Migration
Remove support for version-0 function calling conventions (Andres Freund)
Extensions providing C-coded functions must now conform to version 1 calling conventions. Version 0 has been deprecated since 2001.
Original release occurrence ·
10.0/migration/027Support parallel B-tree index scans Features
Support parallel B-tree index scans (Rahila Syed, Amit Kapila, Robert Haas, Rafia Sabih)
This change allows B-tree index pages to be searched by separate parallel workers.
Original release occurrence ·
10.0/changes/001Support parallel bitmap heap scans Features
Support parallel bitmap heap scans (Dilip Kumar)
This allows a single index scan to dispatch parallel workers to process different areas of the heap.
Original release occurrence ·
10.0/changes/002Allow merge joins to be performed in parallel Features
Allow merge joins to be performed in parallel (Dilip Kumar)
Original release occurrence ·
10.0/changes/003Allow non-correlated subqueries to be run in parallel Features
Allow non-correlated subqueries to be run in parallel (Amit Kapila)
Original release occurrence ·
10.0/changes/004Improve ability of parallel workers to return pre-sorted data Features
Improve ability of parallel workers to return pre-sorted data (Rushabh Lathia)
Original release occurrence ·
10.0/changes/005Increase parallel query usage in procedural language functions Features
Increase parallel query usage in procedural language functions (Robert Haas, Rafia Sabih)
Original release occurrence ·
10.0/changes/006Add max_parallel_workers server parameter to limit the number of worker processes that can be used for query parallelism Features
Add max_parallel_workers server parameter to limit the number of worker processes that can be used for query parallelism (Julien Rouhaud)
This parameter can be set lower than max_worker_processes to reserve worker processes for purposes other than parallel queries.
Original release occurrence ·
10.0/changes/007Enable parallelism by default by changing the default setting of max_parallel_workers_per_gather to 2. Features
Enable parallelism by default by changing the default setting of max_parallel_workers_per_gather to
2.Original release occurrence ·
10.0/changes/008Add write-ahead logging support to hash indexes Features
Add write-ahead logging support to hash indexes (Amit Kapila)
This makes hash indexes crash-safe and replicatable. The former warning message about their use is removed.
Original release occurrence ·
10.0/changes/009Improve hash index performance Performance
Improve hash index performance (Amit Kapila, Mithun Cy, Ashutosh Sharma)
Original release occurrence ·
10.0/changes/010Add SP-GiST index support for INET and CIDR data types Features
Add SP-GiST index support for
INETandCIDRdata types (Emre Hasegeli)Original release occurrence ·
10.0/changes/011Add option to allow BRIN index summarization to happen more aggressively Features
Add option to allow BRIN index summarization to happen more aggressively (Álvaro Herrera)
A new
CREATE INDEXoption enables auto-summarization of the previous BRIN page range when a new page range is created.Original release occurrence ·
10.0/changes/012Add functions to remove and re-add BRIN summarization for BRIN index ranges Features
Add functions to remove and re-add BRIN summarization for BRIN index ranges (Álvaro Herrera)
The new SQL function
brin_summarize_range()updates BRIN index summarization for a specified range andbrin_desummarize_range()removes it. This is helpful to update summarization of a range that is now smaller due toUPDATEs andDELETEs.Original release occurrence ·
10.0/changes/013Improve accuracy in determining if a BRIN index scan is beneficial Features
Improve accuracy in determining if a BRIN index scan is beneficial (David Rowley, Emre Hasegeli)
Original release occurrence ·
10.0/changes/014Allow faster GiST inserts and updates by reusing index space more efficiently Performance
Allow faster GiST inserts and updates by reusing index space more efficiently (Andrey Borodin)
Original release occurrence ·
10.0/changes/015Reduce page locking during vacuuming of GIN indexes Features
Reduce page locking during vacuuming of GIN indexes (Andrey Borodin)
Original release occurrence ·
10.0/changes/016Reduce locking required to change table parameters Features
Reduce locking required to change table parameters (Simon Riggs, Fabrízio Mello)
For example, changing a table's effective_io_concurrency setting can now be done with a more lightweight lock.
Original release occurrence ·
10.0/changes/017Allow tuning of predicate lock promotion thresholds Features
Allow tuning of predicate lock promotion thresholds (Dagfinn Ilmari Mannsåker)
Lock promotion can now be controlled through two new server parameters, max_pred_locks_per_relation and max_pred_locks_per_page.
Original release occurrence ·
10.0/changes/018Add multi-column optimizer statistics to compute the correlation ratio and number of distinct values Features
Add multi-column optimizer statistics to compute the correlation ratio and number of distinct values (Tomas Vondra, David Rowley, Álvaro Herrera)
New commands are
CREATE STATISTICS,ALTER STATISTICS, andDROP STATISTICS. This feature is helpful in estimating query memory usage and when combining the statistics from individual columns.Original release occurrence ·
10.0/changes/019Improve performance of queries affected by row-level security restrictions Performance
Improve performance of queries affected by row-level security restrictions (Tom Lane)
The optimizer now has more knowledge about where it can place RLS filter conditions, allowing better plans to be generated while still enforcing the RLS conditions safely.
Original release occurrence ·
10.0/changes/020Speed up aggregate functions that calculate a running sum using numeric-type arithmetic, including some variants of SUM(), AVG(), and STDDEV() Performance
Speed up aggregate functions that calculate a running sum using
numeric-type arithmetic, including some variants ofSUM(),AVG(), andSTDDEV()(Heikki Linnakangas)Original release occurrence ·
10.0/changes/021Improve performance of character encoding conversions by using radix trees Performance
Improve performance of character encoding conversions by using radix trees (Kyotaro Horiguchi, Heikki Linnakangas)
Original release occurrence ·
10.0/changes/022Reduce expression evaluation overhead during query execution, as well as plan node calling overhead Performance
Reduce expression evaluation overhead during query execution, as well as plan node calling overhead (Andres Freund)
This is particularly helpful for queries that process many rows.
Original release occurrence ·
10.0/changes/023Allow hashed aggregation to be used with grouping sets Performance
Allow hashed aggregation to be used with grouping sets (Andrew Gierth)
Original release occurrence ·
10.0/changes/024Use uniqueness guarantees to optimize certain join types Performance
Use uniqueness guarantees to optimize certain join types (David Rowley)
Original release occurrence ·
10.0/changes/025Improve sort performance of the macaddr data type Performance
Improve sort performance of the
macaddrdata type (Brandur Leach)Original release occurrence ·
10.0/changes/026Reduce statistics tracking overhead in sessions that reference many thousands of relations Performance
Reduce statistics tracking overhead in sessions that reference many thousands of relations (Aleksander Alekseev)
Original release occurrence ·
10.0/changes/027Allow explicit control over EXPLAIN's display of planning and execution time Features
Allow explicit control over
EXPLAIN's display of planning and execution time (Ashutosh Bapat)By default planning and execution time are displayed by
EXPLAIN ANALYZEand are not displayed in other cases. The newEXPLAINoptionSUMMARYallows explicit control of this.Original release occurrence ·
10.0/changes/028Add default monitoring roles Features
Add default monitoring roles (Dave Page)
New roles
pg_monitor,pg_read_all_settings,pg_read_all_stats, andpg_stat_scan_tablesallow simplified permission configuration.Original release occurrence ·
10.0/changes/029Properly update the statistics collector during REFRESH MATERIALIZED VIEW Features
Properly update the statistics collector during
REFRESH MATERIALIZED VIEW(Jim Mlodgenski)Original release occurrence ·
10.0/changes/030Change the default value of log_line_prefix to include current timestamp (with milliseconds) and the process ID in each line of postmaster log output Features
Change the default value of log_line_prefix to include current timestamp (with milliseconds) and the process ID in each line of postmaster log output (Christoph Berg)
The previous default was an empty prefix.
Original release occurrence ·
10.0/changes/031Add functions to return the log and WAL directory contents Features
Add functions to return the log and WAL directory contents (Dave Page)
The new functions are
pg_ls_logdir()andpg_ls_waldir()and can be executed by non-superusers with the proper permissions.Original release occurrence ·
10.0/changes/032Add function pg_current_logfile() to read logging collector's current stderr and csvlog output file names Features
Add function
pg_current_logfile()to read logging collector's current stderr and csvlog output file names (Gilles Darold)Original release occurrence ·
10.0/changes/033Report the address and port number of each listening socket in the server log during postmaster startup Features
Report the address and port number of each listening socket in the server log during postmaster startup (Tom Lane)
Also, when logging failure to bind a listening socket, include the specific address we attempted to bind to.
Original release occurrence ·
10.0/changes/034Reduce log chatter about the starting and stopping of launcher subprocesses Features
Reduce log chatter about the starting and stopping of launcher subprocesses (Tom Lane)
These are now
DEBUG1-level messages.Original release occurrence ·
10.0/changes/035Reduce message verbosity of lower-numbered debug levels controlled by log_min_messages Features
Reduce message verbosity of lower-numbered debug levels controlled by log_min_messages (Robert Haas)
This also changes the verbosity of client_min_messages debug levels.
Original release occurrence ·
10.0/changes/036Add pg_stat_activity reporting of low-level wait states Features
Add
pg_stat_activityreporting of low-level wait states (Michael Paquier, Robert Haas, Rushabh Lathia)This change enables reporting of numerous low-level wait conditions, including latch waits, file reads/writes/fsyncs, client reads/writes, and synchronous replication.
Original release occurrence ·
10.0/changes/037Show auxiliary processes, background workers, and walsender processes in pg_stat_activity Features
Show auxiliary processes, background workers, and walsender processes in
pg_stat_activity(Kuntal Ghosh, Michael Paquier)This simplifies monitoring. A new column
backend_typeidentifies the process type.Original release occurrence ·
10.0/changes/038Allow pg_stat_activity to show the SQL query being executed by parallel workers Features
Allow
pg_stat_activityto show the SQL query being executed by parallel workers (Rafia Sabih)Original release occurrence ·
10.0/changes/039Rename pg_stat_activity.wait_event_type values LWLockTranche and LWLockNamed to LWLock Features
Rename
pg_stat_activity.wait_event_typevaluesLWLockTrancheandLWLockNamedtoLWLock(Robert Haas)This makes the output more consistent.
Original release occurrence ·
10.0/changes/040Add SCRAM-SHA-256 support for password negotiation and storage Features
Add SCRAM-SHA-256 support for password negotiation and storage (Michael Paquier, Heikki Linnakangas)
This provides better security than the existing
md5negotiation and storage method.Original release occurrence ·
10.0/changes/041Change the password_encryption server parameter from boolean to enum Features
Change the password_encryption server parameter from
booleantoenum(Michael Paquier)This was necessary to support additional password hashing options.
Original release occurrence ·
10.0/changes/042Add view pg_hba_file_rules to display the contents of pg_hba.conf Features
Add view
pg_hba_file_rulesto display the contents ofpg_hba.conf(Haribabu Kommi)This shows the file contents, not the currently active settings.
Original release occurrence ·
10.0/changes/043Support multiple RADIUS servers Features
Support multiple RADIUS servers (Magnus Hagander)
All the RADIUS related parameters are now plural and support a comma-separated list of servers.
Original release occurrence ·
10.0/changes/044Allow SSL configuration to be updated during configuration reload Features
Allow SSL configuration to be updated during configuration reload (Andreas Karlsson, Tom Lane)
This allows SSL to be reconfigured without a server restart, by using
pg_ctl reload,SELECT pg_reload_conf(), or sending aSIGHUPsignal. However, reloading the SSL configuration does not work if the server's SSL key requires a passphrase, as there is no way to re-prompt for the passphrase. The original configuration will apply for the life of the postmaster in that case.Original release occurrence ·
10.0/changes/045Make the maximum value of bgwriter_lru_maxpages effectively unlimited Features
Make the maximum value of bgwriter_lru_maxpages effectively unlimited (Jim Nasby)
Original release occurrence ·
10.0/changes/046After creating or unlinking files, perform an fsync on their parent directory Features
After creating or unlinking files, perform an fsync on their parent directory (Michael Paquier)
This reduces the risk of data loss after a power failure.
Original release occurrence ·
10.0/changes/047Prevent unnecessary checkpoints and WAL archiving on otherwise-idle systems Features
Prevent unnecessary checkpoints and WAL archiving on otherwise-idle systems (Michael Paquier)
Original release occurrence ·
10.0/changes/048Add wal_consistency_checking server parameter to add details to WAL that can be sanity-checked on the standby Features
Add wal_consistency_checking server parameter to add details to WAL that can be sanity-checked on the standby (Kuntal Ghosh, Robert Haas)
Any sanity-check failure generates a fatal error on the standby.
Original release occurrence ·
10.0/changes/049Increase the maximum configurable WAL segment size to one gigabyte Features
Increase the maximum configurable WAL segment size to one gigabyte (Beena Emerson)
A larger WAL segment size allows for fewer archive_command invocations and fewer WAL files to manage.
Original release occurrence ·
10.0/changes/050Add the ability to logically replicate tables to standby servers Features
Add the ability to logically replicate tables to standby servers (Petr Jelinek)
Logical replication allows more flexibility than physical replication does, including replication between different major versions of PostgreSQL and selective replication.
Original release occurrence ·
10.0/changes/051Allow waiting for commit acknowledgment from standby servers irrespective of the order they appear in synchronous_standby_names Features
Allow waiting for commit acknowledgment from standby servers irrespective of the order they appear in synchronous_standby_names (Masahiko Sawada)
Previously the server always waited for the active standbys that appeared first in
synchronous_standby_names. The newsynchronous_standby_nameskeywordANYallows waiting for any number of standbys irrespective of their ordering. This is known as quorum commit.Original release occurrence ·
10.0/changes/052Reduce configuration changes necessary to perform streaming backup and replication Features
Reduce configuration changes necessary to perform streaming backup and replication (Magnus Hagander, Dang Minh Huong)
Specifically, the defaults were changed for wal_level, max_wal_senders, max_replication_slots, and hot_standby to make them suitable for these usages out-of-the-box.
Original release occurrence ·
10.0/changes/053Enable replication from localhost connections by default in pg_hba.conf Features
Enable replication from localhost connections by default in
pg_hba.conf(Michael Paquier)Previously
pg_hba.conf's replication connection lines were commented out by default. This is particularly useful for pg_basebackup.Original release occurrence ·
10.0/changes/054Add columns to pg_stat_replication to report replication delay times Features
Add columns to
pg_stat_replicationto report replication delay times (Thomas Munro)The new columns are
write_lag,flush_lag, andreplay_lag.Original release occurrence ·
10.0/changes/055Allow specification of the recovery stopping point by Log Sequence Number (LSN) in recovery.conf Features
Allow specification of the recovery stopping point by Log Sequence Number (LSN) in
recovery.conf(Michael Paquier)Previously the stopping point could only be selected by timestamp or XID.
Original release occurrence ·
10.0/changes/056Allow users to disable pg_stop_backup()'s waiting for all WAL to be archived Features
Allow users to disable
pg_stop_backup()'s waiting for all WAL to be archived (David Steele)An optional second argument to
pg_stop_backup()controls that behavior.Original release occurrence ·
10.0/changes/057Allow creation of temporary replication slots Features
Allow creation of temporary replication slots (Petr Jelinek)
Temporary slots are automatically removed on session exit or error.
Original release occurrence ·
10.0/changes/058Improve performance of hot standby replay with better tracking of Access Exclusive locks Performance
Improve performance of hot standby replay with better tracking of Access Exclusive locks (Simon Riggs, David Rowley)
Original release occurrence ·
10.0/changes/059Speed up two-phase commit recovery performance Performance
Speed up two-phase commit recovery performance (Stas Kelvich, Nikhil Sontakke, Michael Paquier)
Original release occurrence ·
10.0/changes/060Add XMLTABLE function that converts XML-formatted data into a row set Features
Add
XMLTABLEfunction that convertsXML-formatted data into a row set (Pavel Stehule, Álvaro Herrera)Original release occurrence ·
10.0/changes/061Fix regular expressions' character class handling for large character codes, particularly Unicode characters above U+7FF Bug fixes
Fix regular expressions' character class handling for large character codes, particularly Unicode characters above
U+7FF(Tom Lane)Previously, such characters were never recognized as belonging to locale-dependent character classes such as
[[:alpha:]].Original release occurrence ·
10.0/changes/062Add table partitioning syntax that automatically creates partition constraints and handles routing of tuple insertions and updates Features
Add table partitioning syntax that automatically creates partition constraints and handles routing of tuple insertions and updates (Amit Langote)
The syntax supports range and list partitioning.
Original release occurrence ·
10.0/changes/063Add AFTER trigger transition tables to record changed rows Features
Add
AFTERtrigger transition tables to record changed rows (Kevin Grittner, Thomas Munro)Transition tables are accessible from triggers written in server-side languages.
Original release occurrence ·
10.0/changes/064Allow restrictive row-level security policies Features
Allow restrictive row-level security policies (Stephen Frost)
Previously all security policies were permissive, meaning that any matching policy allowed access. A restrictive policy must match for access to be granted. These policy types can be combined.
Original release occurrence ·
10.0/changes/065When creating a foreign-key constraint, check for REFERENCES permission on only the referenced table Features
When creating a foreign-key constraint, check for
REFERENCESpermission on only the referenced table (Tom Lane)Previously
REFERENCESpermission on the referencing table was also required. This appears to have stemmed from a misreading of the SQL standard. Since creating a foreign key (or any other type of) constraint requires ownership privilege on the constrained table, additionally requiringREFERENCESpermission seems rather pointless.Original release occurrence ·
10.0/changes/066Allow default permissions on schemas Features
Allow default permissions on schemas (Matheus Oliveira)
This is done using the
ALTER DEFAULT PRIVILEGEScommand.Original release occurrence ·
10.0/changes/067Add CREATE SEQUENCE AS command to create a sequence matching an integer data type Features
Add
CREATE SEQUENCE AScommand to create a sequence matching an integer data type (Peter Eisentraut)This simplifies the creation of sequences matching the range of base columns.
Original release occurrence ·
10.0/changes/068Allow COPY view FROM source on views with INSTEAD INSERT triggers Features
Allow
COPYon views withviewFROMsourceINSTEAD INSERTtriggers (Haribabu Kommi)The triggers are fed the data rows read by
COPY.Original release occurrence ·
10.0/changes/069Allow the specification of a function name without arguments in DDL commands, if it is unique Features
Allow the specification of a function name without arguments in DDL commands, if it is unique (Peter Eisentraut)
For example, allow
DROP FUNCTIONon a function name without arguments if there is only one function with that name. This behavior is required by the SQL standard.Original release occurrence ·
10.0/changes/070Allow multiple functions, operators, and aggregates to be dropped with a single DROP command Features
Allow multiple functions, operators, and aggregates to be dropped with a single
DROPcommand (Peter Eisentraut)Original release occurrence ·
10.0/changes/071Support IF NOT EXISTS in CREATE SERVER, CREATE USER MAPPING, and CREATE COLLATION Features
Support
IF NOT EXISTSinCREATE SERVER,CREATE USER MAPPING, andCREATE COLLATION(Anastasia Lubennikova, Peter Eisentraut)Original release occurrence ·
10.0/changes/072Make VACUUM VERBOSE report the number of skipped frozen pages and oldest xmin Features
Make
VACUUM VERBOSEreport the number of skipped frozen pages and oldest xmin (Masahiko Sawada, Simon Riggs)This information is also included in log_autovacuum_min_duration output.
Original release occurrence ·
10.0/changes/073Improve speed of VACUUM's removal of trailing empty heap pages Features
Improve speed of
VACUUM's removal of trailing empty heap pages (Claudio Freire, Álvaro Herrera)Original release occurrence ·
10.0/changes/074Add full text search support for JSON and JSONB Features
Add full text search support for
JSONandJSONB(Dmitry Dolgov)The functions
ts_headline()andto_tsvector()can now be used on these data types.Original release occurrence ·
10.0/changes/075Add support for EUI-64 MAC addresses, as a new data type macaddr8 Features
Add support for EUI-64 MAC addresses, as a new data type
macaddr8(Haribabu Kommi)This complements the existing support for EUI-48 MAC addresses (type
macaddr).Original release occurrence ·
10.0/changes/076Add identity columns for assigning a numeric value to columns on insert Features
Add identity columns for assigning a numeric value to columns on insert (Peter Eisentraut)
These are similar to
SERIALcolumns, but are SQL standard compliant.Original release occurrence ·
10.0/changes/077Allow ENUM values to be renamed Features
Allow
ENUMvalues to be renamed (Dagfinn Ilmari Mannsåker)This uses the syntax
ALTER TYPE ... RENAME VALUE.Original release occurrence ·
10.0/changes/078Properly treat array pseudotypes (anyarray) as arrays in to_json() and to_jsonb() Features
Properly treat array pseudotypes (
anyarray) as arrays into_json()andto_jsonb()(Andrew Dunstan)Previously columns declared as
anyarray(particularly those in thepg_statsview) were converted toJSONstrings rather than arrays.Original release occurrence ·
10.0/changes/079Add operators for multiplication and division of money values with int8 values Features
Add operators for multiplication and division of
moneyvalues withint8values (Peter Eisentraut)Previously such cases would result in converting the
int8values tofloat8and then using themoney-and-float8operators. The new behavior avoids possible precision loss. But note that division ofmoneybyint8now truncates the quotient, like other integer-division cases, while the previous behavior would have rounded.Original release occurrence ·
10.0/changes/080Check for overflow in the money type's input function Features
Check for overflow in the
moneytype's input function (Peter Eisentraut)Original release occurrence ·
10.0/changes/081Add simplified regexp_match() function Features
Add simplified
regexp_match()function (Emre Hasegeli)This is similar to
regexp_matches(), but it only returns results from the first match so it does not need to return a set, making it easier to use for simple cases.Original release occurrence ·
10.0/changes/082Add a version of jsonb's delete operator that takes an array of keys to delete Features
Add a version of
jsonb's delete operator that takes an array of keys to delete (Magnus Hagander)Original release occurrence ·
10.0/changes/083Make json_populate_record() and related functions process JSON arrays and objects recursively Features
Make
json_populate_record()and related functions process JSON arrays and objects recursively (Nikita Glukhov)With this change, array-type fields in the destination SQL type are properly converted from JSON arrays, and composite-type fields are properly converted from JSON objects. Previously, such cases would fail because the text representation of the JSON value would be fed to
array_in()orrecord_in(), and its syntax would not match what those input functions expect.Original release occurrence ·
10.0/changes/084Add function txid_current_if_assigned() to return the current transaction ID or NULL if no transaction ID has been assigned Features
Add function
txid_current_if_assigned()to return the current transaction ID orNULLif no transaction ID has been assigned (Craig Ringer)This is different from
txid_current(), which always returns a transaction ID, assigning one if necessary. Unlike that function, this function can be run on standby servers.Original release occurrence ·
10.0/changes/085Add function txid_status() to check if a transaction was committed Features
Add function
txid_status()to check if a transaction was committed (Craig Ringer)This is useful for checking after an abrupt disconnection whether your previous transaction committed and you just didn't receive the acknowledgment.
Original release occurrence ·
10.0/changes/086Allow make_date() to interpret negative years as BC years Features
Allow
make_date()to interpret negative years as BC years (Álvaro Herrera)Original release occurrence ·
10.0/changes/087Make to_timestamp() and to_date() reject out-of-range input fields Features
Make
to_timestamp()andto_date()reject out-of-range input fields (Artur Zakirov)For example, previously
to_date('2009-06-40','YYYY-MM-DD')was accepted and returned2009-07-10. It will now generate an error.Original release occurrence ·
10.0/changes/088Allow PL/Python's cursor() and execute() functions to be called as methods of their plan-object arguments Features
Allow PL/Python's
cursor()andexecute()functions to be called as methods of their plan-object arguments (Peter Eisentraut)This allows a more object-oriented programming style.
Original release occurrence ·
10.0/changes/089Allow PL/pgSQL's GET DIAGNOSTICS statement to retrieve values into array elements Features
Allow PL/pgSQL's
GET DIAGNOSTICSstatement to retrieve values into array elements (Tom Lane)Previously, a syntactic restriction prevented the target variable from being an array element.
Original release occurrence ·
10.0/changes/090Allow PL/Tcl functions to return composite types and sets Features
Allow PL/Tcl functions to return composite types and sets (Karl Lehenbauer)
Original release occurrence ·
10.0/changes/091Add a subtransaction command to PL/Tcl Features
Add a subtransaction command to PL/Tcl (Victor Wagner)
This allows PL/Tcl queries to fail without aborting the entire function.
Original release occurrence ·
10.0/changes/092Add server parameters pltcl.start_proc and pltclu.start_proc, to allow initialization functions to be called on PL/Tcl startup Features
Add server parameters pltcl.start_proc and pltclu.start_proc, to allow initialization functions to be called on PL/Tcl startup (Tom Lane)
Original release occurrence ·
10.0/changes/093Allow specification of multiple host names or addresses in libpq connection strings and URIs Features
Allow specification of multiple host names or addresses in libpq connection strings and URIs (Robert Haas, Heikki Linnakangas)
libpq will connect to the first responsive server in the list.
Original release occurrence ·
10.0/changes/094Allow libpq connection strings and URIs to request a read/write host, that is a master server rather than a standby server Features
Allow libpq connection strings and URIs to request a read/write host, that is a master server rather than a standby server (Victor Wagner, Mithun Cy)
This is useful when multiple host names are specified. It is controlled by libpq connection parameter
target_session_attrs.Original release occurrence ·
10.0/changes/095Allow the password file name to be specified as a libpq connection parameter Features
Allow the password file name to be specified as a libpq connection parameter (Julian Markwort)
Previously this could only be specified via an environment variable.
Original release occurrence ·
10.0/changes/096Add function PQencryptPasswordConn() to allow creation of more types of encrypted passwords on the client side Features
Add function
PQencryptPasswordConn()to allow creation of more types of encrypted passwords on the client side (Michael Paquier, Heikki Linnakangas)Previously only
MD5-encrypted passwords could be created usingPQencryptPassword(). This new function can also createSCRAM-SHA-256-encrypted passwords.Original release occurrence ·
10.0/changes/097Change ecpg preprocessor version from 4.12 to 10 Features
Change ecpg preprocessor version from 4.12 to 10 (Tom Lane)
Henceforth the ecpg version will match the PostgreSQL distribution version number.
Original release occurrence ·
10.0/changes/098Add conditional branch support to psql Features
Add conditional branch support to psql (Corey Huinker)
This feature adds psql meta-commands
\if,\elif,\else, and\endif. This is primarily helpful for scripting.Original release occurrence ·
10.0/changes/099Add psql \gx meta-command to execute (\g) a query in expanded mode (\x) Features
Add psql
\gxmeta-command to execute (\g) a query in expanded mode (\x) (Christoph Berg)Original release occurrence ·
10.0/changes/100Expand psql variable references in backtick-executed strings Features
Expand psql variable references in backtick-executed strings (Tom Lane)
This is particularly useful in the new psql conditional branch commands.
Original release occurrence ·
10.0/changes/101Prevent psql's special variables from being set to invalid values Features
Prevent psql's special variables from being set to invalid values (Daniel Vérité, Tom Lane)
Previously, setting one of psql's special variables to an invalid value silently resulted in the default behavior.
\seton a special variable now fails if the proposed new value is invalid. As a special exception,\setwith an empty or omitted new value, on a boolean-valued special variable, still has the effect of setting the variable toon; but now it actually acquires that value rather than an empty string.\unseton a special variable now explicitly sets the variable to its default value, which is also the value it acquires at startup. In sum, a control variable now always has a displayable value that reflects what psql is actually doing.Original release occurrence ·
10.0/changes/102Add variables showing server version and psql version Features
Add variables showing server version and psql version (Fabien Coelho)
Original release occurrence ·
10.0/changes/103Improve psql's \d (display relation) and \dD (display domain) commands to show collation, nullable, and default properties in separate columns Features
Improve psql's
\d(display relation) and\dD(display domain) commands to show collation, nullable, and default properties in separate columns (Peter Eisentraut)Previously they were shown in a single “Modifiers” column.
Original release occurrence ·
10.0/changes/104Make the various \d commands handle no-matching-object cases more consistently Features
Make the various
\dcommands handle no-matching-object cases more consistently (Daniel Gustafsson)They now all print the message about that to stderr, not stdout, and the message wording is more consistent.
Original release occurrence ·
10.0/changes/105Improve psql's tab completion Features
Improve psql's tab completion (Jeff Janes, Ian Barwick, Andreas Karlsson, Sehrope Sarkuni, Thomas Munro, Kevin Grittner, Dagfinn Ilmari Mannsåker)
Original release occurrence ·
10.0/changes/106Add pgbench option --log-prefix to control the log file prefix Features
Add pgbench option
--log-prefixto control the log file prefix (Masahiko Sawada)Original release occurrence ·
10.0/changes/107Allow pgbench's meta-commands to span multiple lines Features
Allow pgbench's meta-commands to span multiple lines (Fabien Coelho)
A meta-command can now be continued onto the next line by writing backslash-return.
Original release occurrence ·
10.0/changes/108Remove restriction on placement of -M option relative to other command line options Features
Remove restriction on placement of
-Moption relative to other command line options (Tom Lane)Original release occurrence ·
10.0/changes/109Add pg_receivewal option -Z/--compress to specify compression Features
Add pg_receivewal option
-Z/--compressto specify compression (Michael Paquier)Original release occurrence ·
10.0/changes/110Add pg_recvlogical option --endpos to specify the ending position Features
Add pg_recvlogical option
--endposto specify the ending position (Craig Ringer)This complements the existing
--startposoption.Original release occurrence ·
10.0/changes/111Rename initdb options --noclean and --nosync to be spelled --no-clean and --no-sync Features
Rename initdb options
--nocleanand--nosyncto be spelled--no-cleanand--no-sync(Vik Fearing, Peter Eisentraut)The old spellings are still supported.
Original release occurrence ·
10.0/changes/112Allow pg_restore to exclude schemas Features
Allow pg_restore to exclude schemas (Michael Banck)
This adds a new
-N/--exclude-schemaoption.Original release occurrence ·
10.0/changes/113Add --no-blobs option to pg_dump Features
Add
--no-blobsoption to pg_dump (Guillaume Lelarge)This suppresses dumping of large objects.
Original release occurrence ·
10.0/changes/114Add pg_dumpall option --no-role-passwords to omit role passwords Features
Add pg_dumpall option
--no-role-passwordsto omit role passwords (Robins Tharakan, Simon Riggs)This allows use of pg_dumpall by non-superusers; without this option, it fails due to inability to read passwords.
Original release occurrence ·
10.0/changes/115Support using synchronized snapshots when dumping from a standby server Features
Support using synchronized snapshots when dumping from a standby server (Petr Jelinek)
Original release occurrence ·
10.0/changes/116Issue fsync() on the output files generated by pg_dump and pg_dumpall Features
Issue
fsync()on the output files generated by pg_dump and pg_dumpall (Michael Paquier)This provides more security that the output is safely stored on disk before the program exits. This can be disabled with the new
--no-syncoption.Original release occurrence ·
10.0/changes/117Allow pg_basebackup to stream write-ahead log in tar mode Features
Allow pg_basebackup to stream write-ahead log in tar mode (Magnus Hagander)
The WAL will be stored in a separate tar file from the base backup.
Original release occurrence ·
10.0/changes/118Make pg_basebackup use temporary replication slots Features
Make pg_basebackup use temporary replication slots (Magnus Hagander)
Temporary replication slots will be used by default when pg_basebackup uses WAL streaming with default options.
Original release occurrence ·
10.0/changes/119Be more careful about fsync'ing in all required places in pg_basebackup and pg_receivewal Features
Be more careful about fsync'ing in all required places in pg_basebackup and pg_receivewal (Michael Paquier)
Original release occurrence ·
10.0/changes/120Add pg_basebackup option --no-sync to disable fsync Features
Add pg_basebackup option
--no-syncto disable fsync (Michael Paquier)Original release occurrence ·
10.0/changes/121Improve pg_basebackup's handling of which directories to skip Features
Improve pg_basebackup's handling of which directories to skip (David Steele)
Original release occurrence ·
10.0/changes/122Add wait option for pg_ctl's promote operation Features
Add wait option for pg_ctl's promote operation (Peter Eisentraut)
Original release occurrence ·
10.0/changes/123Add long options for pg_ctl wait (--wait) and no-wait (--no-wait) Features
Add long options for pg_ctl wait (
--wait) and no-wait (--no-wait) (Vik Fearing)Original release occurrence ·
10.0/changes/124Add long option for pg_ctl server options (--options) Features
Add long option for pg_ctl server options (
--options) (Peter Eisentraut)Original release occurrence ·
10.0/changes/125Make pg_ctl start --wait detect server-ready by watching postmaster.pid, not by attempting connections Features
Make
pg_ctl start --waitdetect server-ready by watchingpostmaster.pid, not by attempting connections (Tom Lane)The postmaster has been changed to report its ready-for-connections status in
postmaster.pid, and pg_ctl now examines that file to detect whether startup is complete. This is more efficient and reliable than the old method, and it eliminates postmaster log entries about rejected connection attempts during startup.Original release occurrence ·
10.0/changes/126Reduce pg_ctl's reaction time when waiting for postmaster start/stop Features
Reduce pg_ctl's reaction time when waiting for postmaster start/stop (Tom Lane)
pg_ctl now probes ten times per second when waiting for a postmaster state change, rather than once per second.
Original release occurrence ·
10.0/changes/127Ensure that pg_ctl exits with nonzero status if an operation being waited for does not complete within the timeout Features
Ensure that pg_ctl exits with nonzero status if an operation being waited for does not complete within the timeout (Peter Eisentraut)
The
startandpromoteoperations now return exit status 1, not 0, in such cases. Thestopoperation has always done that.Original release occurrence ·
10.0/changes/128Change to two-part release version numbering Features
Change to two-part release version numbering (Peter Eisentraut, Tom Lane)
Release numbers will now have two parts (e.g.,
10.1) rather than three (e.g.,9.6.3). Major versions will now increase just the first number, and minor releases will increase just the second number. Release branches will be referred to by single numbers (e.g.,10rather than9.6). This change is intended to reduce user confusion about what is a major or minor release of PostgreSQL.Original release occurrence ·
10.0/changes/129Improve behavior of pgindent Features
Improve behavior of pgindent (Piotr Stefaniak, Tom Lane)
We have switched to a new version of pg_bsd_indent based on recent improvements made by the FreeBSD project. This fixes numerous small bugs that led to odd C code formatting decisions. Most notably, lines within parentheses (such as in a multi-line function call) are now uniformly indented to match the opening paren, even if that would result in code extending past the right margin.
Original release occurrence ·
10.0/changes/130Allow the ICU library to optionally be used for collation support Features
Allow the ICU library to optionally be used for collation support (Peter Eisentraut)
The ICU library has versioning that allows detection of collation changes between versions. It is enabled via configure option
--with-icu. The default still uses the operating system's native collation library.Original release occurrence ·
10.0/changes/131Automatically mark all PG_FUNCTION_INFO_V1 functions as DLLEXPORT-ed on Windows Features
Automatically mark all
PG_FUNCTION_INFO_V1functions asDLLEXPORT-ed on Windows (Laurenz Albe)If third-party code is using
externfunction declarations, they should also addDLLEXPORTmarkers to those declarations.Original release occurrence ·
10.0/changes/132Remove SPI functions SPI_push(), SPI_pop(), SPI_push_conditional(), SPI_pop_conditional(), and SPI_restore_connection() as unnecessary Features
Remove SPI functions
SPI_push(),SPI_pop(),SPI_push_conditional(),SPI_pop_conditional(), andSPI_restore_connection()as unnecessary (Tom Lane)Their functionality now happens automatically. There are now no-op macros by these names so that external modules don't need to be updated immediately, but eventually such calls should be removed.
A side effect of this change is that
SPI_palloc()and allied functions now require an active SPI connection; they do not degenerate to simplepalloc()if there is none. That previous behavior was not very useful and posed risks of unexpected memory leaks.Original release occurrence ·
10.0/changes/133Allow shared memory to be dynamically allocated Features
Allow shared memory to be dynamically allocated (Thomas Munro, Robert Haas)
Original release occurrence ·
10.0/changes/134Add slab-like memory allocator for efficient fixed-size allocations Bug fixes
Add slab-like memory allocator for efficient fixed-size allocations (Tomas Vondra)
Original release occurrence ·
10.0/changes/135Use POSIX semaphores rather than SysV semaphores on Linux and FreeBSD Features
Use POSIX semaphores rather than SysV semaphores on Linux and FreeBSD (Tom Lane)
This avoids platform-specific limits on SysV semaphore usage.
Original release occurrence ·
10.0/changes/136Improve support for 64-bit atomics Features
Improve support for 64-bit atomics (Andres Freund)
Original release occurrence ·
10.0/changes/137Enable 64-bit atomic operations on ARM64 Features
Enable 64-bit atomic operations on ARM64 (Roman Shaposhnik)
Original release occurrence ·
10.0/changes/138Switch to using clock_gettime(), if available, for duration measurements Features
Switch to using
clock_gettime(), if available, for duration measurements (Tom Lane)gettimeofday()is still used ifclock_gettime()is not available.Original release occurrence ·
10.0/changes/139Add more robust random number generators to be used for cryptographically secure uses Features
Add more robust random number generators to be used for cryptographically secure uses (Magnus Hagander, Michael Paquier, Heikki Linnakangas)
If no strong random number generator can be found, configure will fail unless the
--disable-strong-randomoption is used. However, with this option, pgcrypto functions requiring a strong random number generator will be disabled.Original release occurrence ·
10.0/changes/140Allow WaitLatchOrSocket() to wait for socket connection on Windows Features
Allow
WaitLatchOrSocket()to wait for socket connection on Windows (Andres Freund)Original release occurrence ·
10.0/changes/141tupconvert.c functions no longer convert tuples just to embed a different composite-type OID in them Features
tupconvert.cfunctions no longer convert tuples just to embed a different composite-type OID in them (Ashutosh Bapat, Tom Lane)The majority of callers don't care about the composite-type OID; but if the result tuple is to be used as a composite Datum, steps should be taken to make sure the correct OID is inserted in it.
Original release occurrence ·
10.0/changes/142Remove SCO and Unixware ports Features
Remove SCO and Unixware ports (Tom Lane)
Original release occurrence ·
10.0/changes/143Overhaul documentation build process Features
Overhaul documentation build process (Alexander Lakhin)
Original release occurrence ·
10.0/changes/144Use XSLT to build the PostgreSQL documentation Features
Use XSLT to build the PostgreSQL documentation (Peter Eisentraut)
Previously Jade, DSSSL, and JadeTex were used.
Original release occurrence ·
10.0/changes/145Build HTML documentation using XSLT stylesheets by default Features
Build HTML documentation using XSLT stylesheets by default (Peter Eisentraut)
Original release occurrence ·
10.0/changes/146Allow file_fdw to read from program output as well as files Features
Allow file_fdw to read from program output as well as files (Corey Huinker, Adam Gomaa)
Original release occurrence ·
10.0/changes/147In postgres_fdw, push aggregate functions to the remote server, when possible Features
In postgres_fdw, push aggregate functions to the remote server, when possible (Jeevan Chalke, Ashutosh Bapat)
This reduces the amount of data that must be passed from the remote server, and offloads aggregate computation from the requesting server.
Original release occurrence ·
10.0/changes/148In postgres_fdw, push joins to the remote server in more cases Features
In postgres_fdw, push joins to the remote server in more cases (David Rowley, Ashutosh Bapat, Etsuro Fujita)
Original release occurrence ·
10.0/changes/149Properly support OID columns in postgres_fdw tables Features
Properly support
OIDcolumns in postgres_fdw tables (Etsuro Fujita)Previously
OIDcolumns always returned zeros.Original release occurrence ·
10.0/changes/150Allow btree_gist and btree_gin to index enum types Features
Allow btree_gist and btree_gin to index enum types (Andrew Dunstan)
This allows enums to be used in exclusion constraints.
Original release occurrence ·
10.0/changes/151Add indexing support to btree_gist for the UUID data type Features
Add indexing support to btree_gist for the
UUIDdata type (Paul Jungwirth)Original release occurrence ·
10.0/changes/152Add amcheck which can check the validity of B-tree indexes Features
Add amcheck which can check the validity of B-tree indexes (Peter Geoghegan)
Original release occurrence ·
10.0/changes/153Show ignored constants as $N rather than ? in pg_stat_statements Features
Show ignored constants as
$Nrather than?in pg_stat_statements (Lukas Fittl)Original release occurrence ·
10.0/changes/154Improve cube's handling of zero-dimensional cubes Features
Improve cube's handling of zero-dimensional cubes (Tom Lane)
This also improves handling of
infiniteandNaNvalues.Original release occurrence ·
10.0/changes/155Allow pg_buffercache to run with fewer locks Features
Allow pg_buffercache to run with fewer locks (Ivan Kartyshov)
This makes it less disruptive when run on production systems.
Original release occurrence ·
10.0/changes/156Add pgstattuple function pgstathashindex() to view hash index statistics Features
Add pgstattuple function
pgstathashindex()to view hash index statistics (Ashutosh Sharma)Original release occurrence ·
10.0/changes/157Use GRANT permissions to control pgstattuple function usage Features
Use
GRANTpermissions to control pgstattuple function usage (Stephen Frost)This allows DBAs to allow non-superusers to run these functions.
Original release occurrence ·
10.0/changes/158Reduce locking when pgstattuple examines hash indexes Features
Reduce locking when pgstattuple examines hash indexes (Amit Kapila)
Original release occurrence ·
10.0/changes/159Add pageinspect function page_checksum() to show a page's checksum Features
Add pageinspect function
page_checksum()to show a page's checksum (Tomas Vondra)Original release occurrence ·
10.0/changes/160Add pageinspect function bt_page_items() to print page items from a page image Features
Add pageinspect function
bt_page_items()to print page items from a page image (Tomas Vondra)Original release occurrence ·
10.0/changes/161Add hash index support to pageinspect Features
Add hash index support to pageinspect (Jesper Pedersen, Ashutosh Sharma)
Original release occurrence ·
10.0/changes/162
Security evidence
35 records from the official security matrix and release-note mentions. A fixed version is shown only when the security snapshot explicitly names this branch. A mention alone does not establish applicability or a new fix.
CVE-2022-2625 · Extension scripts replace objects not belonging to the extension CVSS 7.1
Some extensions use CREATE OR REPLACE or CREATE IF NOT EXISTS commands. Some don't adhere to the documented rule to target only objects known to be extension members already. An attack requires permission to create non-temporary objects in at least one schema, ability to lure or wait for an administrator to create or update an affected extension in that schema, and ability to lure or wait for a victim to use the object targeted in CREATE OR REPLACE or CREATE IF NOT EXISTS . Given all three prerequisites, the attacker can run arbitrary code as the victim role, which may be a superuser. Known-affected extensions include both PostgreSQL-bundled and non-bundled extensions. PostgreSQL is blocking this attack in the core server, so there's no need to modify individual extensions. The PostgreSQL project thanks Sven Klemm for reporting this problem.
Fixed in this branch: 10.22. Component: core server.
Official affected-branch entry: 10.
AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2022-1552 · Autovacuum, REINDEX, and others omit "security restricted operation" sandbox CVSS 8.8
Autovacuum, REINDEX , CREATE INDEX , REFRESH MATERIALIZED VIEW , CLUSTER , and pg_amcheck made incomplete efforts to operate safely when a privileged user is maintaining another user's objects. Those commands activated relevant protections too late or not at all. An attacker having permission to create non-temp objects in at least one schema could execute arbitrary SQL functions under a superuser identity. While promptly updating PostgreSQL is the best remediation for most users, a user unable to do that can work around the vulnerability by disabling autovacuum, not manually running the above commands, and not restoring from output of the pg_dump command. Performance may degrade quickly under this workaround. VACUUM is safe, and all commands are fine when a trusted user owns the target object. The PostgreSQL project thanks Alexander Lakhin for reporting this problem.
Fixed in this branch: 10.21. Component: core server.
Official affected-branch entry: 10.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2021-3449 · CVE-2021-3449
No fixed version for this branch is recorded.
Release-note mentions:
CVE-2021-32028 · Memory disclosure in INSERT ... ON CONFLICT ... DO UPDATE CVSS 6.5
Using an INSERT ... ON CONFLICT ... DO UPDATE command on a purpose-crafted table, an attacker can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can create prerequisite objects and complete this attack at will. A user lacking the CREATE and TEMPORARY privileges on all databases and the CREATE privilege on all schemas cannot use this attack at will. The PostgreSQL project thanks Andres Freund for reporting this problem.
Fixed in this branch: 10.17. Component: core server.
Official affected-branch entry: 10.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Release-note mentions:
CVE-2021-32027 · Buffer overrun from integer overflow in array subscripting calculations CVSS 6.5
While modifying certain SQL array values, missing bounds checks let authenticated database users write arbitrary bytes to a wide area of server memory. The PostgreSQL project thanks Tom Lane for reporting this problem.
Fixed in this branch: 10.17. Component: core server.
Official affected-branch entry: 10.
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Release-note mentions:
CVE-2021-23222 · libpq processes unencrypted bytes from man-in-the-middle CVSS 3.7
A man-in-the-middle attacker can inject false responses to the client's first few queries, despite the use of SSL certificate verification and encryption. If more preconditions hold, the attacker can exfiltrate the client's password or other confidential data that might be transmitted early in a session. The attacker must have a way to trick the client's intended server into making the confidential data accessible to the attacker. A known implementation having that property is a PostgreSQL configuration vulnerable to CVE-2021-23214 . As with any exploitation of CVE-2021-23214 , the server must be using trust authentication with a clientcert requirement or using cert authentication. To disclose a password, the client must be in possession of a password, which is atypical when using an authentication configuration vulnerable to CVE-2021-23214 . The attacker must have some other way to access the server to retrieve the exfiltrated data (a valid, unprivileged login account would be sufficient). The PostgreSQL project thanks Jacob Champion for reporting this problem.
Fixed in this branch: 10.19. Component: client.
Official affected-branch entry: 10.
AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2021-23214 · Server processes unencrypted bytes from man-in-the-middle CVSS 8.1
When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption. This is similar to CVE-2011-0411 (different product). The PostgreSQL project thanks Jacob Champion for reporting this problem.
Fixed in this branch: 10.19. Component: core server.
Official affected-branch entry: 10.
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2020-25696 · psql's \gset allows overwriting specially treated variables CVSS 7.5
The \gset meta-command, which sets psql variables based on query results, does not distinguish variables that control psql behavior. If an interactive psql session uses \gset when querying a compromised server, the attacker can execute arbitrary code as the operating system account running psql . Using \gset with a prefix not found among specially treated variables, e.g. any lowercase string, precludes the attack in an unpatched psql . The PostgreSQL project thanks Nick Cleaton for reporting this problem.
Fixed in this branch: 10.15. Component: client.
Official affected-branch entry: 10.
AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2020-25695 · Multiple features escape "security restricted operation" sandbox CVSS 8.8
An attacker having permission to create non-temporary objects in at least one schema can execute arbitrary SQL functions under the identity of a superuser. While promptly updating PostgreSQL is the best remediation for most users, a user unable to do that can work around the vulnerability by disabling autovacuum and not manually running ANALYZE , CLUSTER , REINDEX , CREATE INDEX , VACUUM FULL , REFRESH MATERIALIZED VIEW , or a restore from output of the pg_dump command. Performance may degrade quickly under this workaround. VACUUM without the FULL option is safe, and all commands are fine when a trusted user owns the target object. The PostgreSQL project thanks Etienne Stalmans for reporting this problem.
Fixed in this branch: 10.15. Component: core server.
Official affected-branch entry: 10.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2020-25694 · Reconnection can downgrade connection security settings CVSS 8.1
Many PostgreSQL-provided client applications have options that create additional database connections. Some of those applications reuse only the basic connection parameters (e.g. host , user , port ), dropping others. If this drops a security-relevant parameter (e.g. channel_binding , sslmode , requirepeer , gssencmode ), the attacker has an opportunity to complete a MITM attack or observe cleartext transmission. Affected applications are clusterdb , pg_dump , pg_restore , psql , reindexdb , and vacuumdb . The vulnerability arises only if one invokes an affected client application with a connection string containing a security-relevant parameter. This also fixes how the \connect command of psql reuses connection parameters, i.e. all non-overridden parameters from a previous connection string now re-used. The PostgreSQL project thanks Peter Eisentraut for reporting this problem.
Fixed in this branch: 10.15. Component: client.
Official affected-branch entry: 10.
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2020-1720 · ALTER ... DEPENDS ON EXTENSION is missing authorization checks. CVSS 3.1
The ALTER ... DEPENDS ON EXTENSION sub-commands do not perform authorization checks, which can allow an unprivileged user to drop any function, procedure, materialized view, index, or trigger under certain conditions. This attack is possible if an administrator has installed an extension and an unprivileged user can CREATE , or an extension owner either executes DROP EXTENSION predictably or can be convinced to execute DROP EXTENSION . The PostgreSQL project thanks Tom Lane for reporting this problem.
Fixed in this branch: 10.12. Component: core server.
Official affected-branch entry: 10.
AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Release-note mentions:
CVE-2020-14350 · Uncontrolled search path element in CREATE EXTENSION CVSS 7.1
When a superuser runs certain CREATE EXTENSION statements, users may be able to execute arbitrary SQL functions under the identity of that superuser. The attacker must have permission to create objects in the new extension's schema or a schema of a prerequisite extension. Not all extensions are vulnerable. In addition to correcting the extensions provided with PostgreSQL, the PostgreSQL Global Development Group is issuing guidance for third-party extension authors to secure their own work. The PostgreSQL project thanks Andres Freund for reporting this problem.
Fixed in this branch: 10.14. Component: core server.
Official affected-branch entry: 10.
AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2020-14349 · Uncontrolled search path element in logical replication CVSS 7.5
The PostgreSQL search_path setting determines schemas searched for tables, functions, operators, etc. The CVE-2018-1058 fix caused most PostgreSQL-provided client applications to sanitize search_path , but logical replication continued to leave search_path unchanged. Users of a replication publisher or subscriber database can create objects in the public schema and harness them to execute arbitrary SQL functions under the identity running replication, often a superuser. Installations having adopted a documented secure schema usage pattern are not vulnerable. The PostgreSQL project thanks Noah Misch for reporting this problem.
Fixed in this branch: 10.14. Component: core server.
Official affected-branch entry: 10.
AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2020-10733 · Windows installer runs executables from uncontrolled directories CVSS 6.7
The Windows installer for PostgreSQL invokes system-provided executables that do not have fully-qualified paths. Executables in the directory where the installer loads or the current working directory take precedence over the intended executables. An attacker having permission to add files into one of those directories can use this to execute arbitrary code with the installer's administrative rights. The PostgreSQL project thanks Hou JingYi (@hjy79425575) for reporting this problem.
Fixed in this branch: 10.13. Component: packaging.
Official affected-branch entry: 10.
AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
CVE-2019-3466 · pg_ctlcluster script in postgresql-common does not drop privileges when creating socket/statistics temporary directories CVSS 8.4
A PostgreSQL superuser could escalate to root using a deficiency in the pg_ctlcluster command. pg_ctlcluster is a utility provided by the "postgresql-common" package that is installed with PostgreSQL on Debian and Ubuntu platforms.
Fixed in this branch: 10.11. Component: packaging.
Official affected-branch entry: 10.
AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
CVE-2019-10211 · Windows installer bundled OpenSSL executes code from unprotected directory CVSS 7.8
When the database server or libpq client library initializes SSL, libeay32.dll attempts to read configuration from a hard-coded directory. Typically, the directory does not exist, but any local user could create it and inject configuration. This configuration can direct OpenSSL to load and execute arbitrary code as the user running a PostgreSQL server or client. Most PostgreSQL client tools and libraries use libpq , and one can encounter this vulnerability by using any of them. This vulnerability is much like CVE-2019-5443 , but it originated independently. One can work around the vulnerability by setting environment variable OPENSSL_CONF to "NUL:/openssl.cnf" or any other name that cannot exist as a file. The PostgreSQL project thanks Daniel Gustafsson of the curl security team for reporting this problem.
Fixed in this branch: 10.10. Component: packaging.
Official affected-branch entry: 10.
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE-2019-10210 · Windows installer writes superuser password to unprotected temporary file CVSS 6.7
The EnterpriseDB Windows installer writes a password to a temporary file in its installation directory, creates initial databases, and deletes the file. During those seconds while the file exists, a local attacker can read the PostgreSQL superuser password from the file. The PostgreSQL project thanks Noah Misch for reporting this problem.
Fixed in this branch: 10.10. Component: packaging.
Official affected-branch entry: 10.
AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
CVE-2019-10208 · TYPE in pg_temp executes arbitrary SQL during SECURITY DEFINER execution CVSS 7.5
Given a suitable SECURITY DEFINER function, an attacker can execute arbitrary SQL under the identity of the function owner. An attack requires EXECUTE permission on the function, which must itself contain a function call having inexact argument type match. For example, length('foo'::varchar) and length('foo') are inexact, while length('foo'::text) is exact. As part of exploiting this vulnerability, the attacker uses CREATE DOMAIN to create a type in a pg_temp schema. The attack pattern and fix are similar to that for CVE-2007-2138 . Writing SECURITY DEFINER functions continues to require following the considerations noted in the documentation: https://www.postgresql.org/docs/current/sql-createfunction.html#SQL-CREATEFUNCTION-SECURITY The PostgreSQL project thanks Tom Lane for reporting this problem.
Fixed in this branch: 10.10. Component: core server.
Official affected-branch entry: 10.
AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2019-10164 · Stack-based buffer overflow via setting a password CVSS 7.5
An authenticated user could create a stack-based buffer overflow by changing their own password to a purpose-crafted value. In addition to the ability to crash the PostgreSQL server, this could be further exploited to execute arbitrary code as the PostgreSQL operating system account. Additionally, a rogue server could send a specifically crafted message during the SCRAM authentication process and cause a libpq-enabled client to either crash or execute arbitrary code as the client's operating system account. This issue is fixed by upgrading and restarting your PostgreSQL server as well as your libpq installations. The PostgreSQL Project thanks Alexander Lakhin for reporting this problem.
Fixed in this branch: 10.9. Component: core server.
Official affected-branch entry: 10.
AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2019-10130 · Selectivity estimators bypass row security policies CVSS 3.1
PostgreSQL maintains statistics for tables by sampling data available in columns; this data is consulted during the query planning process. Prior to this release, a user able to execute SQL queries with permissions to read a given column could craft a leaky operator that could read whatever data had been sampled from that column. If this happened to include values from rows that the user is forbidden to see by a row security policy, the user could effectively bypass the policy. This is fixed by only allowing a non-leakproof operator to use this data if there are no relevant row security policies for the table. The PostgreSQL project thanks Dean Rasheed for reporting this problem.
Fixed in this branch: 10.8. Component: core server.
Official affected-branch entry: 10.
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2019-10128 · EnterpriseDB Windows installer does not clear permissive ACL entries CVSS 7.0
Due to both the EnterpriseDB and BigSQL Windows installers not locking down the permissions of the PostgreSQL binary installation directory and the data directory, an unprivileged Windows user account and an unprivileged PostgreSQL account could cause the PostgreSQL service account to execute arbitrary code. This vulnerability is present in all supported versions of PostgreSQL for these installers, and possibly exists in older versions. Both sets of installers have fixed the permissions for these directories for both new and existing installations. If you have installed PostgreSQL on Windows using other methods, we advise that you check that your PostgreSQL binary directories are writable only to trusted users and that your data directories are only accessible to trusted users. The PostgreSQL project thanks Conner Jones for reporting this problem.
Fixed in this branch: 10.8. Component: packaging.
Official affected-branch entry: 10.
AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE-2019-10127 · BigSQL Windows installer does not clear permissive ACL entries. CVSS 7.0
Due to both the EnterpriseDB and BigSQL Windows installers not locking down the permissions of the PostgreSQL binary installation directory and the data directory, an unprivileged Windows user account and an unprivileged PostgreSQL account could cause the PostgreSQL service account to execute arbitrary code. This vulnerability is present in all supported versions of PostgreSQL for these installers, and possibly exists in older versions. Both sets of installers have fixed the permissions for these directories for both new and existing installations. If you have installed PostgreSQL on Windows using other methods, we advise that you check that your PostgreSQL binary directories are writable only to trusted users and that your data directories are only accessible to trusted users. The PostgreSQL project thanks Conner Jones for reporting this problem.
Fixed in this branch: 10.8. Component: packaging.
Official affected-branch entry: 10.
AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE-2018-16850 · SQL injection in pg_upgrade and pg_dump, via CREATE TRIGGER ... REFERENCING. CVSS 8.8
Fixed in this branch: 10.6. Component: core server.
Official affected-branch entry: 10.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2018-1115 · Too-permissive access control list on function pg_logfile_rotate() CVSS 3.1
Fixed in this branch: 10.4. Component: contrib module.
Official affected-branch entry: 10.
AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Release-note mentions:
CVE-2018-10925 · Memory disclosure and missing authorization in INSERT ... ON CONFLICT DO UPDATE. CVSS 7.1
Fixed in this branch: 10.5. Component: core server.
Official affected-branch entry: 10.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Release-note mentions:
CVE-2018-10915 · Certain host connection parameters defeat client-side security defenses CVSS 8.5
Fixed in this branch: 10.5. Component: client.
Official affected-branch entry: 10.
AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Release-note mentions:
CVE-2018-1058 · Uncontrolled search path element in pg_dump and other client applications CVSS 8.8
Fixed in this branch: 10.3. Component: client.
Official affected-branch entry: 10.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
- 10.14: Set a secure search_path in logical replication walsenders and apply workers
- 10.14: Make contrib modules' installation scripts more secure
- 10.3: Document how to configure installations and applications to guard against search-path-dependent trojan-horse attacks from other users
- 10.3: Avoid use of insecure search_path settings in pg_dump and other client programs
CVE-2018-1053 · pg_upgrade creates file of sensitive metadata under prevailing umask CVSS 6.7
Fixed in this branch: 10.2. Component: client.
Official affected-branch entry: 10.
AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2018-1052 · Memory disclosure in table partitioning CVSS 6.5
Fixed in this branch: 10.2. Component: core server.
Official affected-branch entry: 10.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Release-note mentions:
CVE-2017-7484 · selectivity estimators bypass SELECT privilege checks CVSS 4.3
No fixed version for this branch is recorded. Component: core server.
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2017-15099 · INSERT ... ON CONFLICT DO UPDATE fails to enforce SELECT privileges CVSS 3.1
Fixed in this branch: 10.1. Component: core server.
Official affected-branch entry: 10.
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2017-15098 · Memory disclosure in JSON functions CVSS 4.3
Fixed in this branch: 10.1. Component: core server.
Official affected-branch entry: 10.
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2017-12172 · Start scripts permit database administrator to modify root-owned files CVSS 8.4
Fixed in this branch: 10.1. Component: contrib module.
Official affected-branch entry: 10.
AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
Release-note mentions:
CVE-2007-2138 · A vulnerability involving insecure search_path settings allows unprivileged users to gain the SQL privileges of the owner of any SECURITY DEFINER function they are allowed to call. Securing such a function requires both a software update and changes to the function definition.
No fixed version for this branch is recorded.
Release-note mentions:
CVE-2006-2313 · An attacker able to submit crafted strings to an application that will embed those strings in SQL commands can use invalidly-encoded multibyte characters to bypass standard string-escaping methods, resulting in possible SQL injection.
No fixed version for this branch is recorded.
Release-note mentions:
Export this branch as JSON · Compare any two indexed releases