↑↓ select ↵ open ⌫ change scope Open full search

PG.CENTER connects PostgreSQL documentation, reference, and ecosystem knowledge. Maintained by Pigsty.

Wiki / Versions

PostgreSQL 10

Read the English manual

End of life · Recorded build 10.23 · 2022-11-10

This major branch is no longer supported. These records describe its history; the absence of newer security records does not establish that it is safe to run.

First stable release
2017-10-05
Support end
2022-11-10
Indexed releases
24
Original release-note entries
1140

Manuals & provenance

PostgreSQL 10 English manual · 1085 loaded pages.

Manual loaded 2026-09-27T00:10:47.078613.

Release entries: 2026-09-26. Security evidence: 2026-09-26. PDF links use the verified English manifest and locally available files. Lifecycle: PostgreSQL versioning policy.

Upgrade considerations

Major upgrades need a migration method such as dump/reload or pg_upgrade. Read the intervening major-release notes and the target manual. Minor updates can also require extra steps; review the specific release's migration notes. Official upgrade policy.

Compatibility notes for 10.0 · Changes from the initial release through 10.23

Original migration guidance for 10.0

A dump/restore using pg_dumpall or use of pg_upgrade or logical replication is required for those wishing to migrate data from any previous release. See Section 18.6 for general information on migrating to new major releases.

Version 10 contains a number of changes that may affect compatibility with previous releases. Observe the following incompatibilities:

Release history

Every indexed release keeps its original occurrences. CVE counts below are mentions in its notes, including follow-up corrections; they do not count newly fixed vulnerabilities.

ReleaseDate / snapshot cutoffAll changesBug fixesMigration entriesCVE mentions
10.23 2022-11-10 291300
10.22 2022-08-11 341102
10.21 2022-05-12 291401
10.20 2022-02-10 281300
10.19 2021-11-11 502102
10.18 2021-08-12 521702
10.17 2021-05-13 301502
10.16 2021-02-11 401800
10.15 2020-11-12 401403
10.14 2020-08-13 351703
10.13 2020-05-14 451900
10.12 2020-02-13 462401
10.11 2019-11-14 592600
10.10 2019-08-08 311302
10.9 2019-06-20 221301
10.8 2019-05-09 432702
10.7 2019-02-14 542600
10.6 2018-11-08 713401
10.5 2018-08-09 472202
10.4 2018-05-10 533001
10.3 2018-03-01 11601
10.2 2018-02-08 653302
10.1 2017-11-09 371803
10.0 2017-10-05 1892270

Initial release changes

Original entries from 10.0, including feature changes and compatibility notes. Categories aid browsing; they are not upstream classifications.

189 of 189 original entries.

  • Hash indexes must be rebuilt after pg_upgrade-ing from any previous major PostgreSQL version Compatibility Migration

    Hash indexes must be rebuilt after pg_upgrade-ing from any previous major PostgreSQL version (Mithun Cy, Robert Haas, Amit Kapila)

    Major hash index improvements necessitated this requirement. pg_upgrade will create a script to assist with this.

    Original release occurrence · 10.0/migration/001

  • Rename write-ahead log directory pg_xlog to pg_wal, and rename transaction status directory pg_clog to pg_xact Compatibility Migration

    Rename write-ahead log directory pg_xlog to pg_wal, and rename transaction status directory pg_clog to pg_xact (Michael Paquier)

    Users have occasionally thought that these directories contained only inessential log files, and proceeded to remove write-ahead log files or transaction status files manually, causing irrecoverable data loss. These name changes are intended to discourage such errors in future.

    Original release occurrence · 10.0/migration/002

  • Rename SQL functions, tools, and options that reference “xlog” to “wal” Compatibility Migration

    Rename SQL functions, tools, and options that reference “xlog” to “wal” (Robert Haas)

    For example, pg_switch_xlog() becomes pg_switch_wal(), pg_receivexlog becomes pg_receivewal, and --xlogdir becomes --waldir. This is for consistency with the change of the pg_xlog directory name; in general, the “xlog” terminology is no longer used in any user-facing places.

    Original release occurrence · 10.0/migration/003

  • Rename WAL-related functions and views to use lsn instead of location Compatibility Migration

    Rename WAL-related functions and views to use lsn instead of location (David Rowley)

    There was previously an inconsistent mixture of the two terminologies.

    Original release occurrence · 10.0/migration/004

  • Change the implementation of set-returning functions appearing in a query's SELECT list Compatibility Migration

    Change the implementation of set-returning functions appearing in a query's SELECT list (Andres Freund)

    Set-returning functions are now evaluated before evaluation of scalar expressions in the SELECT list, much as though they had been placed in a LATERAL FROM-clause item. This allows saner semantics for cases where multiple set-returning functions are present. If they return different numbers of rows, the shorter results are extended to match the longest result by adding nulls. Previously the results were cycled until they all terminated at the same time, producing a number of rows equal to the least common multiple of the functions' periods. In addition, set-returning functions are now disallowed within CASE and COALESCE constructs. For more information see Section 37.4.8.

    Original release occurrence · 10.0/migration/005

  • Use standard row constructor syntax in UPDATE ... SET (column_list) = row_constructor Compatibility Migration

    Use standard row constructor syntax in UPDATE ... SET (column_list) = row_constructor (Tom Lane)

    The row_constructor can now begin with the keyword ROW; previously that had to be omitted. If just one column name appears in the column_list, then the row_constructor now must use the ROW keyword, since otherwise it is not a valid row constructor but just a parenthesized expression. Also, an occurrence of table_name.* within the row_constructor is now expanded into multiple columns, as occurs in other uses of row_constructors.

    Original release occurrence · 10.0/migration/006

  • When ALTER TABLE ... ADD PRIMARY KEY marks columns NOT NULL, that change now propagates to inheritance child tables as well Compatibility Migration

    When ALTER TABLE ... ADD PRIMARY KEY marks columns NOT NULL, that change now propagates to inheritance child tables as well (Michael Paquier)

    Original release occurrence · 10.0/migration/007

  • Prevent statement-level triggers from firing more than once per statement Compatibility Migration

    Prevent statement-level triggers from firing more than once per statement (Tom Lane)

    Cases involving writable CTEs updating the same table updated by the containing statement, or by another writable CTE, fired BEFORE STATEMENT or AFTER STATEMENT triggers more than once. Also, if there were statement-level triggers on a table affected by a foreign key enforcement action (such as ON DELETE CASCADE), they could fire more than once per outer SQL statement. This is contrary to the SQL standard, so change it.

    Original release occurrence · 10.0/migration/008

  • Move sequences' metadata fields into a new pg_sequence system catalog Compatibility Migration

    Move sequences' metadata fields into a new pg_sequence system catalog (Peter Eisentraut)

    A sequence relation now stores only the fields that can be modified by nextval(), that is last_value, log_cnt, and is_called. Other sequence properties, such as the starting value and increment, are kept in a corresponding row of the pg_sequence catalog. ALTER SEQUENCE updates are now fully transactional, implying that the sequence is locked until commit. The nextval() and setval() functions remain nontransactional.

    The main incompatibility introduced by this change is that selecting from a sequence relation now returns only the three fields named above. To obtain the sequence's other properties, applications must look into pg_sequence. The new system view pg_sequences can also be used for this purpose; it provides column names that are more compatible with existing code.

    Also, sequences created for SERIAL columns now generate positive 32-bit wide values, whereas previous versions generated 64-bit wide values. This has no visible effect if the values are only stored in a column.

    The output of psql's \d command for a sequence has been redesigned, too.

    Original release occurrence · 10.0/migration/009

  • Make pg_basebackup stream the WAL needed to restore the backup by default Compatibility Migration

    Make pg_basebackup stream the WAL needed to restore the backup by default (Magnus Hagander)

    This changes pg_basebackup's -X/--wal-method default to stream. An option value none has been added to reproduce the old behavior. The pg_basebackup option -x has been removed (instead, use -X fetch).

    Original release occurrence · 10.0/migration/010

  • Change how logical replication uses pg_hba.conf Compatibility Migration

    Change how logical replication uses pg_hba.conf (Peter Eisentraut)

    In previous releases, a logical replication connection required the replication keyword in the database column. As of this release, logical replication matches a normal entry with a database name or keywords such as all. Physical replication continues to use the replication keyword. Since built-in logical replication is new in this release, this change only affects users of third-party logical replication plugins.

    Original release occurrence · 10.0/migration/011

  • Make all pg_ctl actions wait for completion by default Compatibility Migration

    Make all pg_ctl actions wait for completion by default (Peter Eisentraut)

    Previously some pg_ctl actions didn't wait for completion, and required the use of -w to do so.

    Original release occurrence · 10.0/migration/012

  • Change the default value of the log_directory server parameter from pg_log to log Compatibility Migration

    Change the default value of the log_directory server parameter from pg_log to log (Andreas Karlsson)

    Original release occurrence · 10.0/migration/013

  • Add configuration option ssl_dh_params_file to specify file name for custom OpenSSL DH parameters Compatibility Migration

    Add configuration option ssl_dh_params_file to specify file name for custom OpenSSL DH parameters (Heikki Linnakangas)

    This replaces the hardcoded, undocumented file name dh1024.pem. Note that dh1024.pem is no longer examined by default; you must set this option if you want to use custom DH parameters.

    Original release occurrence · 10.0/migration/014

  • Increase the size of the default DH parameters used for OpenSSL ephemeral DH ciphers to 2048 bits Compatibility Migration

    Increase the size of the default DH parameters used for OpenSSL ephemeral DH ciphers to 2048 bits (Heikki Linnakangas)

    The size of the compiled-in DH parameters has been increased from 1024 to 2048 bits, making DH key exchange more resistant to brute-force attacks. However, some old SSL implementations, notably some revisions of Java Runtime Environment version 6, will not accept DH parameters longer than 1024 bits, and hence will not be able to connect over SSL. If it's necessary to support such old clients, you can use custom 1024-bit DH parameters instead of the compiled-in defaults. See ssl_dh_params_file.

    Original release occurrence · 10.0/migration/015

  • Remove the ability to store unencrypted passwords on the server Compatibility Migration

    Remove the ability to store unencrypted passwords on the server (Heikki Linnakangas)

    The password_encryption server parameter no longer supports off or plain. The UNENCRYPTED option is no longer supported in CREATE/ALTER USER ... PASSWORD. Similarly, the --unencrypted option has been removed from createuser. Unencrypted passwords migrated from older versions will be stored encrypted in this release. The default setting for password_encryption is still md5.

    Original release occurrence · 10.0/migration/016

  • Add min_parallel_table_scan_size and min_parallel_index_scan_size server parameters to control parallel queries Compatibility Migration

    Add min_parallel_table_scan_size and min_parallel_index_scan_size server parameters to control parallel queries (Amit Kapila, Robert Haas)

    These replace min_parallel_relation_size, which was found to be too generic.

    Original release occurrence · 10.0/migration/017

  • Don't downcase unquoted text within shared_preload_libraries and related server parameters Compatibility Migration

    Don't downcase unquoted text within shared_preload_libraries and related server parameters (QL Zhuo)

    These settings are really lists of file names, but they were previously treated as lists of SQL identifiers, which have different parsing rules.

    Original release occurrence · 10.0/migration/018

  • Remove sql_inheritance server parameter Compatibility Migration

    Remove sql_inheritance server parameter (Robert Haas)

    Changing this setting from the default value caused queries referencing parent tables to not include child tables. The SQL standard requires them to be included, however, and this has been the default since PostgreSQL 7.1.

    Original release occurrence · 10.0/migration/019

  • Allow multi-dimensional arrays to be passed into PL/Python functions, and returned as nested Python lists Compatibility Migration

    Allow multi-dimensional arrays to be passed into PL/Python functions, and returned as nested Python lists (Alexey Grishchenko, Dave Cramer, Heikki Linnakangas)

    This feature requires a backwards-incompatible change to the handling of arrays of composite types in PL/Python. Previously, you could return an array of composite values by writing, e.g., [[col1, col2], [col1, col2]]; but now that is interpreted as a two-dimensional array. Composite types in arrays must now be written as Python tuples, not lists, to resolve the ambiguity; that is, write [(col1, col2), (col1, col2)] instead.

    Original release occurrence · 10.0/migration/020

  • Remove PL/Tcl's “module” auto-loading facility Compatibility Migration

    Remove PL/Tcl's “module” auto-loading facility (Tom Lane)

    This functionality has been replaced by new server parameters pltcl.start_proc and pltclu.start_proc, which are easier to use and more similar to features available in other PLs.

    Original release occurrence · 10.0/migration/021

  • Remove pg_dump/pg_dumpall support for dumping from pre-8.0 servers Compatibility Migration

    Remove pg_dump/pg_dumpall support for dumping from pre-8.0 servers (Tom Lane)

    Users needing to dump from pre-8.0 servers will need to use dump programs from PostgreSQL 9.6 or earlier. The resulting output should still load successfully into newer servers.

    Original release occurrence · 10.0/migration/022

  • Remove support for floating-point timestamps and intervals Compatibility Migration

    Remove support for floating-point timestamps and intervals (Tom Lane)

    This removes configure's --disable-integer-datetimes option. Floating-point timestamps have few advantages and have not been the default since PostgreSQL 8.3.

    Original release occurrence · 10.0/migration/023

  • Remove server support for client/server protocol version 1.0 Compatibility Migration

    Remove server support for client/server protocol version 1.0 (Tom Lane)

    This protocol hasn't had client support since PostgreSQL 6.3.

    Original release occurrence · 10.0/migration/024

  • Remove contrib/tsearch2 module Compatibility Migration

    Remove contrib/tsearch2 module (Robert Haas)

    This module provided compatibility with the version of full text search that shipped in pre-8.3 PostgreSQL releases.

    Original release occurrence · 10.0/migration/025

  • Remove createlang and droplang command-line applications Compatibility Migration

    Remove createlang and droplang command-line applications (Peter Eisentraut)

    These had been deprecated since PostgreSQL 9.1. Instead, use CREATE EXTENSION and DROP EXTENSION directly.

    Original release occurrence · 10.0/migration/026

  • Remove support for version-0 function calling conventions Compatibility Migration

    Remove support for version-0 function calling conventions (Andres Freund)

    Extensions providing C-coded functions must now conform to version 1 calling conventions. Version 0 has been deprecated since 2001.

    Original release occurrence · 10.0/migration/027

  • Support parallel B-tree index scans Features

    Support parallel B-tree index scans (Rahila Syed, Amit Kapila, Robert Haas, Rafia Sabih)

    This change allows B-tree index pages to be searched by separate parallel workers.

    Original release occurrence · 10.0/changes/001

  • Support parallel bitmap heap scans Features

    Support parallel bitmap heap scans (Dilip Kumar)

    This allows a single index scan to dispatch parallel workers to process different areas of the heap.

    Original release occurrence · 10.0/changes/002

  • Allow merge joins to be performed in parallel Features

    Allow merge joins to be performed in parallel (Dilip Kumar)

    Original release occurrence · 10.0/changes/003

  • Allow non-correlated subqueries to be run in parallel Features

    Allow non-correlated subqueries to be run in parallel (Amit Kapila)

    Original release occurrence · 10.0/changes/004

  • Improve ability of parallel workers to return pre-sorted data Features

    Improve ability of parallel workers to return pre-sorted data (Rushabh Lathia)

    Original release occurrence · 10.0/changes/005

  • Increase parallel query usage in procedural language functions Features

    Increase parallel query usage in procedural language functions (Robert Haas, Rafia Sabih)

    Original release occurrence · 10.0/changes/006

  • Add max_parallel_workers server parameter to limit the number of worker processes that can be used for query parallelism Features

    Add max_parallel_workers server parameter to limit the number of worker processes that can be used for query parallelism (Julien Rouhaud)

    This parameter can be set lower than max_worker_processes to reserve worker processes for purposes other than parallel queries.

    Original release occurrence · 10.0/changes/007

  • Enable parallelism by default by changing the default setting of max_parallel_workers_per_gather to 2. Features

    Enable parallelism by default by changing the default setting of max_parallel_workers_per_gather to 2.

    Original release occurrence · 10.0/changes/008

  • Add write-ahead logging support to hash indexes Features

    Add write-ahead logging support to hash indexes (Amit Kapila)

    This makes hash indexes crash-safe and replicatable. The former warning message about their use is removed.

    Original release occurrence · 10.0/changes/009

  • Improve hash index performance Performance

    Improve hash index performance (Amit Kapila, Mithun Cy, Ashutosh Sharma)

    Original release occurrence · 10.0/changes/010

  • Add SP-GiST index support for INET and CIDR data types Features

    Add SP-GiST index support for INET and CIDR data types (Emre Hasegeli)

    Original release occurrence · 10.0/changes/011

  • Add option to allow BRIN index summarization to happen more aggressively Features

    Add option to allow BRIN index summarization to happen more aggressively (Álvaro Herrera)

    A new CREATE INDEX option enables auto-summarization of the previous BRIN page range when a new page range is created.

    Original release occurrence · 10.0/changes/012

  • Add functions to remove and re-add BRIN summarization for BRIN index ranges Features

    Add functions to remove and re-add BRIN summarization for BRIN index ranges (Álvaro Herrera)

    The new SQL function brin_summarize_range() updates BRIN index summarization for a specified range and brin_desummarize_range() removes it. This is helpful to update summarization of a range that is now smaller due to UPDATEs and DELETEs.

    Original release occurrence · 10.0/changes/013

  • Improve accuracy in determining if a BRIN index scan is beneficial Features

    Improve accuracy in determining if a BRIN index scan is beneficial (David Rowley, Emre Hasegeli)

    Original release occurrence · 10.0/changes/014

  • Allow faster GiST inserts and updates by reusing index space more efficiently Performance

    Allow faster GiST inserts and updates by reusing index space more efficiently (Andrey Borodin)

    Original release occurrence · 10.0/changes/015

  • Reduce page locking during vacuuming of GIN indexes Features

    Reduce page locking during vacuuming of GIN indexes (Andrey Borodin)

    Original release occurrence · 10.0/changes/016

  • Reduce locking required to change table parameters Features

    Reduce locking required to change table parameters (Simon Riggs, Fabrízio Mello)

    For example, changing a table's effective_io_concurrency setting can now be done with a more lightweight lock.

    Original release occurrence · 10.0/changes/017

  • Allow tuning of predicate lock promotion thresholds Features

    Allow tuning of predicate lock promotion thresholds (Dagfinn Ilmari Mannsåker)

    Lock promotion can now be controlled through two new server parameters, max_pred_locks_per_relation and max_pred_locks_per_page.

    Original release occurrence · 10.0/changes/018

  • Add multi-column optimizer statistics to compute the correlation ratio and number of distinct values Features

    Add multi-column optimizer statistics to compute the correlation ratio and number of distinct values (Tomas Vondra, David Rowley, Álvaro Herrera)

    New commands are CREATE STATISTICS, ALTER STATISTICS, and DROP STATISTICS. This feature is helpful in estimating query memory usage and when combining the statistics from individual columns.

    Original release occurrence · 10.0/changes/019

  • Improve performance of queries affected by row-level security restrictions Performance

    Improve performance of queries affected by row-level security restrictions (Tom Lane)

    The optimizer now has more knowledge about where it can place RLS filter conditions, allowing better plans to be generated while still enforcing the RLS conditions safely.

    Original release occurrence · 10.0/changes/020

  • Speed up aggregate functions that calculate a running sum using numeric-type arithmetic, including some variants of SUM(), AVG(), and STDDEV() Performance

    Speed up aggregate functions that calculate a running sum using numeric-type arithmetic, including some variants of SUM(), AVG(), and STDDEV() (Heikki Linnakangas)

    Original release occurrence · 10.0/changes/021

  • Improve performance of character encoding conversions by using radix trees Performance

    Improve performance of character encoding conversions by using radix trees (Kyotaro Horiguchi, Heikki Linnakangas)

    Original release occurrence · 10.0/changes/022

  • Reduce expression evaluation overhead during query execution, as well as plan node calling overhead Performance

    Reduce expression evaluation overhead during query execution, as well as plan node calling overhead (Andres Freund)

    This is particularly helpful for queries that process many rows.

    Original release occurrence · 10.0/changes/023

  • Allow hashed aggregation to be used with grouping sets Performance

    Allow hashed aggregation to be used with grouping sets (Andrew Gierth)

    Original release occurrence · 10.0/changes/024

  • Use uniqueness guarantees to optimize certain join types Performance

    Use uniqueness guarantees to optimize certain join types (David Rowley)

    Original release occurrence · 10.0/changes/025

  • Improve sort performance of the macaddr data type Performance

    Improve sort performance of the macaddr data type (Brandur Leach)

    Original release occurrence · 10.0/changes/026

  • Reduce statistics tracking overhead in sessions that reference many thousands of relations Performance

    Reduce statistics tracking overhead in sessions that reference many thousands of relations (Aleksander Alekseev)

    Original release occurrence · 10.0/changes/027

  • Allow explicit control over EXPLAIN's display of planning and execution time Features

    Allow explicit control over EXPLAIN's display of planning and execution time (Ashutosh Bapat)

    By default planning and execution time are displayed by EXPLAIN ANALYZE and are not displayed in other cases. The new EXPLAIN option SUMMARY allows explicit control of this.

    Original release occurrence · 10.0/changes/028

  • Add default monitoring roles Features

    Add default monitoring roles (Dave Page)

    New roles pg_monitor, pg_read_all_settings, pg_read_all_stats, and pg_stat_scan_tables allow simplified permission configuration.

    Original release occurrence · 10.0/changes/029

  • Properly update the statistics collector during REFRESH MATERIALIZED VIEW Features

    Properly update the statistics collector during REFRESH MATERIALIZED VIEW (Jim Mlodgenski)

    Original release occurrence · 10.0/changes/030

  • Change the default value of log_line_prefix to include current timestamp (with milliseconds) and the process ID in each line of postmaster log output Features

    Change the default value of log_line_prefix to include current timestamp (with milliseconds) and the process ID in each line of postmaster log output (Christoph Berg)

    The previous default was an empty prefix.

    Original release occurrence · 10.0/changes/031

  • Add functions to return the log and WAL directory contents Features

    Add functions to return the log and WAL directory contents (Dave Page)

    The new functions are pg_ls_logdir() and pg_ls_waldir() and can be executed by non-superusers with the proper permissions.

    Original release occurrence · 10.0/changes/032

  • Add function pg_current_logfile() to read logging collector's current stderr and csvlog output file names Features

    Add function pg_current_logfile() to read logging collector's current stderr and csvlog output file names (Gilles Darold)

    Original release occurrence · 10.0/changes/033

  • Report the address and port number of each listening socket in the server log during postmaster startup Features

    Report the address and port number of each listening socket in the server log during postmaster startup (Tom Lane)

    Also, when logging failure to bind a listening socket, include the specific address we attempted to bind to.

    Original release occurrence · 10.0/changes/034

  • Reduce log chatter about the starting and stopping of launcher subprocesses Features

    Reduce log chatter about the starting and stopping of launcher subprocesses (Tom Lane)

    These are now DEBUG1-level messages.

    Original release occurrence · 10.0/changes/035

  • Reduce message verbosity of lower-numbered debug levels controlled by log_min_messages Features

    Reduce message verbosity of lower-numbered debug levels controlled by log_min_messages (Robert Haas)

    This also changes the verbosity of client_min_messages debug levels.

    Original release occurrence · 10.0/changes/036

  • Add pg_stat_activity reporting of low-level wait states Features

    Add pg_stat_activity reporting of low-level wait states (Michael Paquier, Robert Haas, Rushabh Lathia)

    This change enables reporting of numerous low-level wait conditions, including latch waits, file reads/writes/fsyncs, client reads/writes, and synchronous replication.

    Original release occurrence · 10.0/changes/037

  • Show auxiliary processes, background workers, and walsender processes in pg_stat_activity Features

    Show auxiliary processes, background workers, and walsender processes in pg_stat_activity (Kuntal Ghosh, Michael Paquier)

    This simplifies monitoring. A new column backend_type identifies the process type.

    Original release occurrence · 10.0/changes/038

  • Allow pg_stat_activity to show the SQL query being executed by parallel workers Features

    Allow pg_stat_activity to show the SQL query being executed by parallel workers (Rafia Sabih)

    Original release occurrence · 10.0/changes/039

  • Rename pg_stat_activity.wait_event_type values LWLockTranche and LWLockNamed to LWLock Features

    Rename pg_stat_activity.wait_event_type values LWLockTranche and LWLockNamed to LWLock (Robert Haas)

    This makes the output more consistent.

    Original release occurrence · 10.0/changes/040

  • Add SCRAM-SHA-256 support for password negotiation and storage Features

    Add SCRAM-SHA-256 support for password negotiation and storage (Michael Paquier, Heikki Linnakangas)

    This provides better security than the existing md5 negotiation and storage method.

    Original release occurrence · 10.0/changes/041

  • Change the password_encryption server parameter from boolean to enum Features

    Change the password_encryption server parameter from boolean to enum (Michael Paquier)

    This was necessary to support additional password hashing options.

    Original release occurrence · 10.0/changes/042

  • Add view pg_hba_file_rules to display the contents of pg_hba.conf Features

    Add view pg_hba_file_rules to display the contents of pg_hba.conf (Haribabu Kommi)

    This shows the file contents, not the currently active settings.

    Original release occurrence · 10.0/changes/043

  • Support multiple RADIUS servers Features

    Support multiple RADIUS servers (Magnus Hagander)

    All the RADIUS related parameters are now plural and support a comma-separated list of servers.

    Original release occurrence · 10.0/changes/044

  • Allow SSL configuration to be updated during configuration reload Features

    Allow SSL configuration to be updated during configuration reload (Andreas Karlsson, Tom Lane)

    This allows SSL to be reconfigured without a server restart, by using pg_ctl reload, SELECT pg_reload_conf(), or sending a SIGHUP signal. However, reloading the SSL configuration does not work if the server's SSL key requires a passphrase, as there is no way to re-prompt for the passphrase. The original configuration will apply for the life of the postmaster in that case.

    Original release occurrence · 10.0/changes/045

  • Make the maximum value of bgwriter_lru_maxpages effectively unlimited Features

    Make the maximum value of bgwriter_lru_maxpages effectively unlimited (Jim Nasby)

    Original release occurrence · 10.0/changes/046

  • After creating or unlinking files, perform an fsync on their parent directory Features

    After creating or unlinking files, perform an fsync on their parent directory (Michael Paquier)

    This reduces the risk of data loss after a power failure.

    Original release occurrence · 10.0/changes/047

  • Prevent unnecessary checkpoints and WAL archiving on otherwise-idle systems Features

    Prevent unnecessary checkpoints and WAL archiving on otherwise-idle systems (Michael Paquier)

    Original release occurrence · 10.0/changes/048

  • Add wal_consistency_checking server parameter to add details to WAL that can be sanity-checked on the standby Features

    Add wal_consistency_checking server parameter to add details to WAL that can be sanity-checked on the standby (Kuntal Ghosh, Robert Haas)

    Any sanity-check failure generates a fatal error on the standby.

    Original release occurrence · 10.0/changes/049

  • Increase the maximum configurable WAL segment size to one gigabyte Features

    Increase the maximum configurable WAL segment size to one gigabyte (Beena Emerson)

    A larger WAL segment size allows for fewer archive_command invocations and fewer WAL files to manage.

    Original release occurrence · 10.0/changes/050

  • Add the ability to logically replicate tables to standby servers Features

    Add the ability to logically replicate tables to standby servers (Petr Jelinek)

    Logical replication allows more flexibility than physical replication does, including replication between different major versions of PostgreSQL and selective replication.

    Original release occurrence · 10.0/changes/051

  • Allow waiting for commit acknowledgment from standby servers irrespective of the order they appear in synchronous_standby_names Features

    Allow waiting for commit acknowledgment from standby servers irrespective of the order they appear in synchronous_standby_names (Masahiko Sawada)

    Previously the server always waited for the active standbys that appeared first in synchronous_standby_names. The new synchronous_standby_names keyword ANY allows waiting for any number of standbys irrespective of their ordering. This is known as quorum commit.

    Original release occurrence · 10.0/changes/052

  • Reduce configuration changes necessary to perform streaming backup and replication Features

    Reduce configuration changes necessary to perform streaming backup and replication (Magnus Hagander, Dang Minh Huong)

    Specifically, the defaults were changed for wal_level, max_wal_senders, max_replication_slots, and hot_standby to make them suitable for these usages out-of-the-box.

    Original release occurrence · 10.0/changes/053

  • Enable replication from localhost connections by default in pg_hba.conf Features

    Enable replication from localhost connections by default in pg_hba.conf (Michael Paquier)

    Previously pg_hba.conf's replication connection lines were commented out by default. This is particularly useful for pg_basebackup.

    Original release occurrence · 10.0/changes/054

  • Add columns to pg_stat_replication to report replication delay times Features

    Add columns to pg_stat_replication to report replication delay times (Thomas Munro)

    The new columns are write_lag, flush_lag, and replay_lag.

    Original release occurrence · 10.0/changes/055

  • Allow specification of the recovery stopping point by Log Sequence Number (LSN) in recovery.conf Features

    Allow specification of the recovery stopping point by Log Sequence Number (LSN) in recovery.conf (Michael Paquier)

    Previously the stopping point could only be selected by timestamp or XID.

    Original release occurrence · 10.0/changes/056

  • Allow users to disable pg_stop_backup()'s waiting for all WAL to be archived Features

    Allow users to disable pg_stop_backup()'s waiting for all WAL to be archived (David Steele)

    An optional second argument to pg_stop_backup() controls that behavior.

    Original release occurrence · 10.0/changes/057

  • Allow creation of temporary replication slots Features

    Allow creation of temporary replication slots (Petr Jelinek)

    Temporary slots are automatically removed on session exit or error.

    Original release occurrence · 10.0/changes/058

  • Improve performance of hot standby replay with better tracking of Access Exclusive locks Performance

    Improve performance of hot standby replay with better tracking of Access Exclusive locks (Simon Riggs, David Rowley)

    Original release occurrence · 10.0/changes/059

  • Speed up two-phase commit recovery performance Performance

    Speed up two-phase commit recovery performance (Stas Kelvich, Nikhil Sontakke, Michael Paquier)

    Original release occurrence · 10.0/changes/060

  • Add XMLTABLE function that converts XML-formatted data into a row set Features

    Add XMLTABLE function that converts XML-formatted data into a row set (Pavel Stehule, Álvaro Herrera)

    Original release occurrence · 10.0/changes/061

  • Fix regular expressions' character class handling for large character codes, particularly Unicode characters above U+7FF Bug fixes

    Fix regular expressions' character class handling for large character codes, particularly Unicode characters above U+7FF (Tom Lane)

    Previously, such characters were never recognized as belonging to locale-dependent character classes such as [[:alpha:]].

    Original release occurrence · 10.0/changes/062

  • Add table partitioning syntax that automatically creates partition constraints and handles routing of tuple insertions and updates Features

    Add table partitioning syntax that automatically creates partition constraints and handles routing of tuple insertions and updates (Amit Langote)

    The syntax supports range and list partitioning.

    Original release occurrence · 10.0/changes/063

  • Add AFTER trigger transition tables to record changed rows Features

    Add AFTER trigger transition tables to record changed rows (Kevin Grittner, Thomas Munro)

    Transition tables are accessible from triggers written in server-side languages.

    Original release occurrence · 10.0/changes/064

  • Allow restrictive row-level security policies Features

    Allow restrictive row-level security policies (Stephen Frost)

    Previously all security policies were permissive, meaning that any matching policy allowed access. A restrictive policy must match for access to be granted. These policy types can be combined.

    Original release occurrence · 10.0/changes/065

  • When creating a foreign-key constraint, check for REFERENCES permission on only the referenced table Features

    When creating a foreign-key constraint, check for REFERENCES permission on only the referenced table (Tom Lane)

    Previously REFERENCES permission on the referencing table was also required. This appears to have stemmed from a misreading of the SQL standard. Since creating a foreign key (or any other type of) constraint requires ownership privilege on the constrained table, additionally requiring REFERENCES permission seems rather pointless.

    Original release occurrence · 10.0/changes/066

  • Allow default permissions on schemas Features

    Allow default permissions on schemas (Matheus Oliveira)

    This is done using the ALTER DEFAULT PRIVILEGES command.

    Original release occurrence · 10.0/changes/067

  • Add CREATE SEQUENCE AS command to create a sequence matching an integer data type Features

    Add CREATE SEQUENCE AS command to create a sequence matching an integer data type (Peter Eisentraut)

    This simplifies the creation of sequences matching the range of base columns.

    Original release occurrence · 10.0/changes/068

  • Allow COPY view FROM source on views with INSTEAD INSERT triggers Features

    Allow COPY view FROM source on views with INSTEAD INSERT triggers (Haribabu Kommi)

    The triggers are fed the data rows read by COPY.

    Original release occurrence · 10.0/changes/069

  • Allow the specification of a function name without arguments in DDL commands, if it is unique Features

    Allow the specification of a function name without arguments in DDL commands, if it is unique (Peter Eisentraut)

    For example, allow DROP FUNCTION on a function name without arguments if there is only one function with that name. This behavior is required by the SQL standard.

    Original release occurrence · 10.0/changes/070

  • Allow multiple functions, operators, and aggregates to be dropped with a single DROP command Features

    Allow multiple functions, operators, and aggregates to be dropped with a single DROP command (Peter Eisentraut)

    Original release occurrence · 10.0/changes/071

  • Support IF NOT EXISTS in CREATE SERVER, CREATE USER MAPPING, and CREATE COLLATION Features

    Support IF NOT EXISTS in CREATE SERVER, CREATE USER MAPPING, and CREATE COLLATION (Anastasia Lubennikova, Peter Eisentraut)

    Original release occurrence · 10.0/changes/072

  • Make VACUUM VERBOSE report the number of skipped frozen pages and oldest xmin Features

    Make VACUUM VERBOSE report the number of skipped frozen pages and oldest xmin (Masahiko Sawada, Simon Riggs)

    This information is also included in log_autovacuum_min_duration output.

    Original release occurrence · 10.0/changes/073

  • Improve speed of VACUUM's removal of trailing empty heap pages Features

    Improve speed of VACUUM's removal of trailing empty heap pages (Claudio Freire, Álvaro Herrera)

    Original release occurrence · 10.0/changes/074

  • Add full text search support for JSON and JSONB Features

    Add full text search support for JSON and JSONB (Dmitry Dolgov)

    The functions ts_headline() and to_tsvector() can now be used on these data types.

    Original release occurrence · 10.0/changes/075

  • Add support for EUI-64 MAC addresses, as a new data type macaddr8 Features

    Add support for EUI-64 MAC addresses, as a new data type macaddr8 (Haribabu Kommi)

    This complements the existing support for EUI-48 MAC addresses (type macaddr).

    Original release occurrence · 10.0/changes/076

  • Add identity columns for assigning a numeric value to columns on insert Features

    Add identity columns for assigning a numeric value to columns on insert (Peter Eisentraut)

    These are similar to SERIAL columns, but are SQL standard compliant.

    Original release occurrence · 10.0/changes/077

  • Allow ENUM values to be renamed Features

    Allow ENUM values to be renamed (Dagfinn Ilmari Mannsåker)

    This uses the syntax ALTER TYPE ... RENAME VALUE.

    Original release occurrence · 10.0/changes/078

  • Properly treat array pseudotypes (anyarray) as arrays in to_json() and to_jsonb() Features

    Properly treat array pseudotypes (anyarray) as arrays in to_json() and to_jsonb() (Andrew Dunstan)

    Previously columns declared as anyarray (particularly those in the pg_stats view) were converted to JSON strings rather than arrays.

    Original release occurrence · 10.0/changes/079

  • Add operators for multiplication and division of money values with int8 values Features

    Add operators for multiplication and division of money values with int8 values (Peter Eisentraut)

    Previously such cases would result in converting the int8 values to float8 and then using the money-and-float8 operators. The new behavior avoids possible precision loss. But note that division of money by int8 now truncates the quotient, like other integer-division cases, while the previous behavior would have rounded.

    Original release occurrence · 10.0/changes/080

  • Check for overflow in the money type's input function Features

    Check for overflow in the money type's input function (Peter Eisentraut)

    Original release occurrence · 10.0/changes/081

  • Add simplified regexp_match() function Features

    Add simplified regexp_match() function (Emre Hasegeli)

    This is similar to regexp_matches(), but it only returns results from the first match so it does not need to return a set, making it easier to use for simple cases.

    Original release occurrence · 10.0/changes/082

  • Add a version of jsonb's delete operator that takes an array of keys to delete Features

    Add a version of jsonb's delete operator that takes an array of keys to delete (Magnus Hagander)

    Original release occurrence · 10.0/changes/083

  • Make json_populate_record() and related functions process JSON arrays and objects recursively Features

    Make json_populate_record() and related functions process JSON arrays and objects recursively (Nikita Glukhov)

    With this change, array-type fields in the destination SQL type are properly converted from JSON arrays, and composite-type fields are properly converted from JSON objects. Previously, such cases would fail because the text representation of the JSON value would be fed to array_in() or record_in(), and its syntax would not match what those input functions expect.

    Original release occurrence · 10.0/changes/084

  • Add function txid_current_if_assigned() to return the current transaction ID or NULL if no transaction ID has been assigned Features

    Add function txid_current_if_assigned() to return the current transaction ID or NULL if no transaction ID has been assigned (Craig Ringer)

    This is different from txid_current(), which always returns a transaction ID, assigning one if necessary. Unlike that function, this function can be run on standby servers.

    Original release occurrence · 10.0/changes/085

  • Add function txid_status() to check if a transaction was committed Features

    Add function txid_status() to check if a transaction was committed (Craig Ringer)

    This is useful for checking after an abrupt disconnection whether your previous transaction committed and you just didn't receive the acknowledgment.

    Original release occurrence · 10.0/changes/086

  • Allow make_date() to interpret negative years as BC years Features

    Allow make_date() to interpret negative years as BC years (Álvaro Herrera)

    Original release occurrence · 10.0/changes/087

  • Make to_timestamp() and to_date() reject out-of-range input fields Features

    Make to_timestamp() and to_date() reject out-of-range input fields (Artur Zakirov)

    For example, previously to_date('2009-06-40','YYYY-MM-DD') was accepted and returned 2009-07-10. It will now generate an error.

    Original release occurrence · 10.0/changes/088

  • Allow PL/Python's cursor() and execute() functions to be called as methods of their plan-object arguments Features

    Allow PL/Python's cursor() and execute() functions to be called as methods of their plan-object arguments (Peter Eisentraut)

    This allows a more object-oriented programming style.

    Original release occurrence · 10.0/changes/089

  • Allow PL/pgSQL's GET DIAGNOSTICS statement to retrieve values into array elements Features

    Allow PL/pgSQL's GET DIAGNOSTICS statement to retrieve values into array elements (Tom Lane)

    Previously, a syntactic restriction prevented the target variable from being an array element.

    Original release occurrence · 10.0/changes/090

  • Allow PL/Tcl functions to return composite types and sets Features

    Allow PL/Tcl functions to return composite types and sets (Karl Lehenbauer)

    Original release occurrence · 10.0/changes/091

  • Add a subtransaction command to PL/Tcl Features

    Add a subtransaction command to PL/Tcl (Victor Wagner)

    This allows PL/Tcl queries to fail without aborting the entire function.

    Original release occurrence · 10.0/changes/092

  • Add server parameters pltcl.start_proc and pltclu.start_proc, to allow initialization functions to be called on PL/Tcl startup Features

    Add server parameters pltcl.start_proc and pltclu.start_proc, to allow initialization functions to be called on PL/Tcl startup (Tom Lane)

    Original release occurrence · 10.0/changes/093

  • Allow specification of multiple host names or addresses in libpq connection strings and URIs Features

    Allow specification of multiple host names or addresses in libpq connection strings and URIs (Robert Haas, Heikki Linnakangas)

    libpq will connect to the first responsive server in the list.

    Original release occurrence · 10.0/changes/094

  • Allow libpq connection strings and URIs to request a read/write host, that is a master server rather than a standby server Features

    Allow libpq connection strings and URIs to request a read/write host, that is a master server rather than a standby server (Victor Wagner, Mithun Cy)

    This is useful when multiple host names are specified. It is controlled by libpq connection parameter target_session_attrs.

    Original release occurrence · 10.0/changes/095

  • Allow the password file name to be specified as a libpq connection parameter Features

    Allow the password file name to be specified as a libpq connection parameter (Julian Markwort)

    Previously this could only be specified via an environment variable.

    Original release occurrence · 10.0/changes/096

  • Add function PQencryptPasswordConn() to allow creation of more types of encrypted passwords on the client side Features

    Add function PQencryptPasswordConn() to allow creation of more types of encrypted passwords on the client side (Michael Paquier, Heikki Linnakangas)

    Previously only MD5-encrypted passwords could be created using PQencryptPassword(). This new function can also create SCRAM-SHA-256-encrypted passwords.

    Original release occurrence · 10.0/changes/097

  • Change ecpg preprocessor version from 4.12 to 10 Features

    Change ecpg preprocessor version from 4.12 to 10 (Tom Lane)

    Henceforth the ecpg version will match the PostgreSQL distribution version number.

    Original release occurrence · 10.0/changes/098

  • Add conditional branch support to psql Features

    Add conditional branch support to psql (Corey Huinker)

    This feature adds psql meta-commands \if, \elif, \else, and \endif. This is primarily helpful for scripting.

    Original release occurrence · 10.0/changes/099

  • Add psql \gx meta-command to execute (\g) a query in expanded mode (\x) Features

    Add psql \gx meta-command to execute (\g) a query in expanded mode (\x) (Christoph Berg)

    Original release occurrence · 10.0/changes/100

  • Expand psql variable references in backtick-executed strings Features

    Expand psql variable references in backtick-executed strings (Tom Lane)

    This is particularly useful in the new psql conditional branch commands.

    Original release occurrence · 10.0/changes/101

  • Prevent psql's special variables from being set to invalid values Features

    Prevent psql's special variables from being set to invalid values (Daniel Vérité, Tom Lane)

    Previously, setting one of psql's special variables to an invalid value silently resulted in the default behavior. \set on a special variable now fails if the proposed new value is invalid. As a special exception, \set with an empty or omitted new value, on a boolean-valued special variable, still has the effect of setting the variable to on; but now it actually acquires that value rather than an empty string. \unset on a special variable now explicitly sets the variable to its default value, which is also the value it acquires at startup. In sum, a control variable now always has a displayable value that reflects what psql is actually doing.

    Original release occurrence · 10.0/changes/102

  • Add variables showing server version and psql version Features

    Add variables showing server version and psql version (Fabien Coelho)

    Original release occurrence · 10.0/changes/103

  • Improve psql's \d (display relation) and \dD (display domain) commands to show collation, nullable, and default properties in separate columns Features

    Improve psql's \d (display relation) and \dD (display domain) commands to show collation, nullable, and default properties in separate columns (Peter Eisentraut)

    Previously they were shown in a single “Modifiers” column.

    Original release occurrence · 10.0/changes/104

  • Make the various \d commands handle no-matching-object cases more consistently Features

    Make the various \d commands handle no-matching-object cases more consistently (Daniel Gustafsson)

    They now all print the message about that to stderr, not stdout, and the message wording is more consistent.

    Original release occurrence · 10.0/changes/105

  • Improve psql's tab completion Features

    Improve psql's tab completion (Jeff Janes, Ian Barwick, Andreas Karlsson, Sehrope Sarkuni, Thomas Munro, Kevin Grittner, Dagfinn Ilmari Mannsåker)

    Original release occurrence · 10.0/changes/106

  • Add pgbench option --log-prefix to control the log file prefix Features

    Add pgbench option --log-prefix to control the log file prefix (Masahiko Sawada)

    Original release occurrence · 10.0/changes/107

  • Allow pgbench's meta-commands to span multiple lines Features

    Allow pgbench's meta-commands to span multiple lines (Fabien Coelho)

    A meta-command can now be continued onto the next line by writing backslash-return.

    Original release occurrence · 10.0/changes/108

  • Remove restriction on placement of -M option relative to other command line options Features

    Remove restriction on placement of -M option relative to other command line options (Tom Lane)

    Original release occurrence · 10.0/changes/109

  • Add pg_receivewal option -Z/--compress to specify compression Features

    Add pg_receivewal option -Z/--compress to specify compression (Michael Paquier)

    Original release occurrence · 10.0/changes/110

  • Add pg_recvlogical option --endpos to specify the ending position Features

    Add pg_recvlogical option --endpos to specify the ending position (Craig Ringer)

    This complements the existing --startpos option.

    Original release occurrence · 10.0/changes/111

  • Rename initdb options --noclean and --nosync to be spelled --no-clean and --no-sync Features

    Rename initdb options --noclean and --nosync to be spelled --no-clean and --no-sync (Vik Fearing, Peter Eisentraut)

    The old spellings are still supported.

    Original release occurrence · 10.0/changes/112

  • Allow pg_restore to exclude schemas Features

    Allow pg_restore to exclude schemas (Michael Banck)

    This adds a new -N/--exclude-schema option.

    Original release occurrence · 10.0/changes/113

  • Add --no-blobs option to pg_dump Features

    Add --no-blobs option to pg_dump (Guillaume Lelarge)

    This suppresses dumping of large objects.

    Original release occurrence · 10.0/changes/114

  • Add pg_dumpall option --no-role-passwords to omit role passwords Features

    Add pg_dumpall option --no-role-passwords to omit role passwords (Robins Tharakan, Simon Riggs)

    This allows use of pg_dumpall by non-superusers; without this option, it fails due to inability to read passwords.

    Original release occurrence · 10.0/changes/115

  • Support using synchronized snapshots when dumping from a standby server Features

    Support using synchronized snapshots when dumping from a standby server (Petr Jelinek)

    Original release occurrence · 10.0/changes/116

  • Issue fsync() on the output files generated by pg_dump and pg_dumpall Features

    Issue fsync() on the output files generated by pg_dump and pg_dumpall (Michael Paquier)

    This provides more security that the output is safely stored on disk before the program exits. This can be disabled with the new --no-sync option.

    Original release occurrence · 10.0/changes/117

  • Allow pg_basebackup to stream write-ahead log in tar mode Features

    Allow pg_basebackup to stream write-ahead log in tar mode (Magnus Hagander)

    The WAL will be stored in a separate tar file from the base backup.

    Original release occurrence · 10.0/changes/118

  • Make pg_basebackup use temporary replication slots Features

    Make pg_basebackup use temporary replication slots (Magnus Hagander)

    Temporary replication slots will be used by default when pg_basebackup uses WAL streaming with default options.

    Original release occurrence · 10.0/changes/119

  • Be more careful about fsync'ing in all required places in pg_basebackup and pg_receivewal Features

    Be more careful about fsync'ing in all required places in pg_basebackup and pg_receivewal (Michael Paquier)

    Original release occurrence · 10.0/changes/120

  • Add pg_basebackup option --no-sync to disable fsync Features

    Add pg_basebackup option --no-sync to disable fsync (Michael Paquier)

    Original release occurrence · 10.0/changes/121

  • Improve pg_basebackup's handling of which directories to skip Features

    Improve pg_basebackup's handling of which directories to skip (David Steele)

    Original release occurrence · 10.0/changes/122

  • Add wait option for pg_ctl's promote operation Features

    Add wait option for pg_ctl's promote operation (Peter Eisentraut)

    Original release occurrence · 10.0/changes/123

  • Add long options for pg_ctl wait (--wait) and no-wait (--no-wait) Features

    Add long options for pg_ctl wait (--wait) and no-wait (--no-wait) (Vik Fearing)

    Original release occurrence · 10.0/changes/124

  • Add long option for pg_ctl server options (--options) Features

    Add long option for pg_ctl server options (--options) (Peter Eisentraut)

    Original release occurrence · 10.0/changes/125

  • Make pg_ctl start --wait detect server-ready by watching postmaster.pid, not by attempting connections Features

    Make pg_ctl start --wait detect server-ready by watching postmaster.pid, not by attempting connections (Tom Lane)

    The postmaster has been changed to report its ready-for-connections status in postmaster.pid, and pg_ctl now examines that file to detect whether startup is complete. This is more efficient and reliable than the old method, and it eliminates postmaster log entries about rejected connection attempts during startup.

    Original release occurrence · 10.0/changes/126

  • Reduce pg_ctl's reaction time when waiting for postmaster start/stop Features

    Reduce pg_ctl's reaction time when waiting for postmaster start/stop (Tom Lane)

    pg_ctl now probes ten times per second when waiting for a postmaster state change, rather than once per second.

    Original release occurrence · 10.0/changes/127

  • Ensure that pg_ctl exits with nonzero status if an operation being waited for does not complete within the timeout Features

    Ensure that pg_ctl exits with nonzero status if an operation being waited for does not complete within the timeout (Peter Eisentraut)

    The start and promote operations now return exit status 1, not 0, in such cases. The stop operation has always done that.

    Original release occurrence · 10.0/changes/128

  • Change to two-part release version numbering Features

    Change to two-part release version numbering (Peter Eisentraut, Tom Lane)

    Release numbers will now have two parts (e.g., 10.1) rather than three (e.g., 9.6.3). Major versions will now increase just the first number, and minor releases will increase just the second number. Release branches will be referred to by single numbers (e.g., 10 rather than 9.6). This change is intended to reduce user confusion about what is a major or minor release of PostgreSQL.

    Original release occurrence · 10.0/changes/129

  • Improve behavior of pgindent Features

    Improve behavior of pgindent (Piotr Stefaniak, Tom Lane)

    We have switched to a new version of pg_bsd_indent based on recent improvements made by the FreeBSD project. This fixes numerous small bugs that led to odd C code formatting decisions. Most notably, lines within parentheses (such as in a multi-line function call) are now uniformly indented to match the opening paren, even if that would result in code extending past the right margin.

    Original release occurrence · 10.0/changes/130

  • Allow the ICU library to optionally be used for collation support Features

    Allow the ICU library to optionally be used for collation support (Peter Eisentraut)

    The ICU library has versioning that allows detection of collation changes between versions. It is enabled via configure option --with-icu. The default still uses the operating system's native collation library.

    Original release occurrence · 10.0/changes/131

  • Automatically mark all PG_FUNCTION_INFO_V1 functions as DLLEXPORT-ed on Windows Features

    Automatically mark all PG_FUNCTION_INFO_V1 functions as DLLEXPORT-ed on Windows (Laurenz Albe)

    If third-party code is using extern function declarations, they should also add DLLEXPORT markers to those declarations.

    Original release occurrence · 10.0/changes/132

  • Remove SPI functions SPI_push(), SPI_pop(), SPI_push_conditional(), SPI_pop_conditional(), and SPI_restore_connection() as unnecessary Features

    Remove SPI functions SPI_push(), SPI_pop(), SPI_push_conditional(), SPI_pop_conditional(), and SPI_restore_connection() as unnecessary (Tom Lane)

    Their functionality now happens automatically. There are now no-op macros by these names so that external modules don't need to be updated immediately, but eventually such calls should be removed.

    A side effect of this change is that SPI_palloc() and allied functions now require an active SPI connection; they do not degenerate to simple palloc() if there is none. That previous behavior was not very useful and posed risks of unexpected memory leaks.

    Original release occurrence · 10.0/changes/133

  • Allow shared memory to be dynamically allocated Features

    Allow shared memory to be dynamically allocated (Thomas Munro, Robert Haas)

    Original release occurrence · 10.0/changes/134

  • Add slab-like memory allocator for efficient fixed-size allocations Bug fixes

    Add slab-like memory allocator for efficient fixed-size allocations (Tomas Vondra)

    Original release occurrence · 10.0/changes/135

  • Use POSIX semaphores rather than SysV semaphores on Linux and FreeBSD Features

    Use POSIX semaphores rather than SysV semaphores on Linux and FreeBSD (Tom Lane)

    This avoids platform-specific limits on SysV semaphore usage.

    Original release occurrence · 10.0/changes/136

  • Improve support for 64-bit atomics Features

    Improve support for 64-bit atomics (Andres Freund)

    Original release occurrence · 10.0/changes/137

  • Enable 64-bit atomic operations on ARM64 Features

    Enable 64-bit atomic operations on ARM64 (Roman Shaposhnik)

    Original release occurrence · 10.0/changes/138

  • Switch to using clock_gettime(), if available, for duration measurements Features

    Switch to using clock_gettime(), if available, for duration measurements (Tom Lane)

    gettimeofday() is still used if clock_gettime() is not available.

    Original release occurrence · 10.0/changes/139

  • Add more robust random number generators to be used for cryptographically secure uses Features

    Add more robust random number generators to be used for cryptographically secure uses (Magnus Hagander, Michael Paquier, Heikki Linnakangas)

    If no strong random number generator can be found, configure will fail unless the --disable-strong-random option is used. However, with this option, pgcrypto functions requiring a strong random number generator will be disabled.

    Original release occurrence · 10.0/changes/140

  • Allow WaitLatchOrSocket() to wait for socket connection on Windows Features

    Allow WaitLatchOrSocket() to wait for socket connection on Windows (Andres Freund)

    Original release occurrence · 10.0/changes/141

  • tupconvert.c functions no longer convert tuples just to embed a different composite-type OID in them Features

    tupconvert.c functions no longer convert tuples just to embed a different composite-type OID in them (Ashutosh Bapat, Tom Lane)

    The majority of callers don't care about the composite-type OID; but if the result tuple is to be used as a composite Datum, steps should be taken to make sure the correct OID is inserted in it.

    Original release occurrence · 10.0/changes/142

  • Remove SCO and Unixware ports Features

    Remove SCO and Unixware ports (Tom Lane)

    Original release occurrence · 10.0/changes/143

  • Overhaul documentation build process Features

    Overhaul documentation build process (Alexander Lakhin)

    Original release occurrence · 10.0/changes/144

  • Use XSLT to build the PostgreSQL documentation Features

    Use XSLT to build the PostgreSQL documentation (Peter Eisentraut)

    Previously Jade, DSSSL, and JadeTex were used.

    Original release occurrence · 10.0/changes/145

  • Build HTML documentation using XSLT stylesheets by default Features

    Build HTML documentation using XSLT stylesheets by default (Peter Eisentraut)

    Original release occurrence · 10.0/changes/146

  • Allow file_fdw to read from program output as well as files Features

    Allow file_fdw to read from program output as well as files (Corey Huinker, Adam Gomaa)

    Original release occurrence · 10.0/changes/147

  • In postgres_fdw, push aggregate functions to the remote server, when possible Features

    In postgres_fdw, push aggregate functions to the remote server, when possible (Jeevan Chalke, Ashutosh Bapat)

    This reduces the amount of data that must be passed from the remote server, and offloads aggregate computation from the requesting server.

    Original release occurrence · 10.0/changes/148

  • In postgres_fdw, push joins to the remote server in more cases Features

    In postgres_fdw, push joins to the remote server in more cases (David Rowley, Ashutosh Bapat, Etsuro Fujita)

    Original release occurrence · 10.0/changes/149

  • Properly support OID columns in postgres_fdw tables Features

    Properly support OID columns in postgres_fdw tables (Etsuro Fujita)

    Previously OID columns always returned zeros.

    Original release occurrence · 10.0/changes/150

  • Allow btree_gist and btree_gin to index enum types Features

    Allow btree_gist and btree_gin to index enum types (Andrew Dunstan)

    This allows enums to be used in exclusion constraints.

    Original release occurrence · 10.0/changes/151

  • Add indexing support to btree_gist for the UUID data type Features

    Add indexing support to btree_gist for the UUID data type (Paul Jungwirth)

    Original release occurrence · 10.0/changes/152

  • Add amcheck which can check the validity of B-tree indexes Features

    Add amcheck which can check the validity of B-tree indexes (Peter Geoghegan)

    Original release occurrence · 10.0/changes/153

  • Show ignored constants as $N rather than ? in pg_stat_statements Features

    Show ignored constants as $N rather than ? in pg_stat_statements (Lukas Fittl)

    Original release occurrence · 10.0/changes/154

  • Improve cube's handling of zero-dimensional cubes Features

    Improve cube's handling of zero-dimensional cubes (Tom Lane)

    This also improves handling of infinite and NaN values.

    Original release occurrence · 10.0/changes/155

  • Allow pg_buffercache to run with fewer locks Features

    Allow pg_buffercache to run with fewer locks (Ivan Kartyshov)

    This makes it less disruptive when run on production systems.

    Original release occurrence · 10.0/changes/156

  • Add pgstattuple function pgstathashindex() to view hash index statistics Features

    Add pgstattuple function pgstathashindex() to view hash index statistics (Ashutosh Sharma)

    Original release occurrence · 10.0/changes/157

  • Use GRANT permissions to control pgstattuple function usage Features

    Use GRANT permissions to control pgstattuple function usage (Stephen Frost)

    This allows DBAs to allow non-superusers to run these functions.

    Original release occurrence · 10.0/changes/158

  • Reduce locking when pgstattuple examines hash indexes Features

    Reduce locking when pgstattuple examines hash indexes (Amit Kapila)

    Original release occurrence · 10.0/changes/159

  • Add pageinspect function page_checksum() to show a page's checksum Features

    Add pageinspect function page_checksum() to show a page's checksum (Tomas Vondra)

    Original release occurrence · 10.0/changes/160

  • Add pageinspect function bt_page_items() to print page items from a page image Features

    Add pageinspect function bt_page_items() to print page items from a page image (Tomas Vondra)

    Original release occurrence · 10.0/changes/161

  • Add hash index support to pageinspect Features

    Add hash index support to pageinspect (Jesper Pedersen, Ashutosh Sharma)

    Original release occurrence · 10.0/changes/162

Security evidence

35 records from the official security matrix and release-note mentions. A fixed version is shown only when the security snapshot explicitly names this branch. A mention alone does not establish applicability or a new fix.

CVE-2022-2625 · Extension scripts replace objects not belonging to the extension CVSS 7.1

Some extensions use CREATE OR REPLACE or CREATE IF NOT EXISTS commands. Some don't adhere to the documented rule to target only objects known to be extension members already. An attack requires permission to create non-temporary objects in at least one schema, ability to lure or wait for an administrator to create or update an affected extension in that schema, and ability to lure or wait for a victim to use the object targeted in CREATE OR REPLACE or CREATE IF NOT EXISTS . Given all three prerequisites, the attacker can run arbitrary code as the victim role, which may be a superuser. Known-affected extensions include both PostgreSQL-bundled and non-bundled extensions. PostgreSQL is blocking this attack in the core server, so there's no need to modify individual extensions. The PostgreSQL project thanks Sven Klemm for reporting this problem.

Fixed in this branch: 10.22. Component: core server.

Official affected-branch entry: 10.

AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2022-1552 · Autovacuum, REINDEX, and others omit "security restricted operation" sandbox CVSS 8.8

Autovacuum, REINDEX , CREATE INDEX , REFRESH MATERIALIZED VIEW , CLUSTER , and pg_amcheck made incomplete efforts to operate safely when a privileged user is maintaining another user's objects. Those commands activated relevant protections too late or not at all. An attacker having permission to create non-temp objects in at least one schema could execute arbitrary SQL functions under a superuser identity. While promptly updating PostgreSQL is the best remediation for most users, a user unable to do that can work around the vulnerability by disabling autovacuum, not manually running the above commands, and not restoring from output of the pg_dump command. Performance may degrade quickly under this workaround. VACUUM is safe, and all commands are fine when a trusted user owns the target object. The PostgreSQL project thanks Alexander Lakhin for reporting this problem.

Fixed in this branch: 10.21. Component: core server.

Official affected-branch entry: 10.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2021-3449 · CVE-2021-3449

No fixed version for this branch is recorded.

Release-note mentions:

CVE-2021-32028 · Memory disclosure in INSERT ... ON CONFLICT ... DO UPDATE CVSS 6.5

Using an INSERT ... ON CONFLICT ... DO UPDATE command on a purpose-crafted table, an attacker can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can create prerequisite objects and complete this attack at will. A user lacking the CREATE and TEMPORARY privileges on all databases and the CREATE privilege on all schemas cannot use this attack at will. The PostgreSQL project thanks Andres Freund for reporting this problem.

Fixed in this branch: 10.17. Component: core server.

Official affected-branch entry: 10.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Release-note mentions:

CVE-2021-32027 · Buffer overrun from integer overflow in array subscripting calculations CVSS 6.5

While modifying certain SQL array values, missing bounds checks let authenticated database users write arbitrary bytes to a wide area of server memory. The PostgreSQL project thanks Tom Lane for reporting this problem.

Fixed in this branch: 10.17. Component: core server.

Official affected-branch entry: 10.

AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Release-note mentions:

CVE-2021-23222 · libpq processes unencrypted bytes from man-in-the-middle CVSS 3.7

A man-in-the-middle attacker can inject false responses to the client's first few queries, despite the use of SSL certificate verification and encryption. If more preconditions hold, the attacker can exfiltrate the client's password or other confidential data that might be transmitted early in a session. The attacker must have a way to trick the client's intended server into making the confidential data accessible to the attacker. A known implementation having that property is a PostgreSQL configuration vulnerable to CVE-2021-23214 . As with any exploitation of CVE-2021-23214 , the server must be using trust authentication with a clientcert requirement or using cert authentication. To disclose a password, the client must be in possession of a password, which is atypical when using an authentication configuration vulnerable to CVE-2021-23214 . The attacker must have some other way to access the server to retrieve the exfiltrated data (a valid, unprivileged login account would be sufficient). The PostgreSQL project thanks Jacob Champion for reporting this problem.

Fixed in this branch: 10.19. Component: client.

Official affected-branch entry: 10.

AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2021-23214 · Server processes unencrypted bytes from man-in-the-middle CVSS 8.1

When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption. This is similar to CVE-2011-0411 (different product). The PostgreSQL project thanks Jacob Champion for reporting this problem.

Fixed in this branch: 10.19. Component: core server.

Official affected-branch entry: 10.

AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2020-25696 · psql's \gset allows overwriting specially treated variables CVSS 7.5

The \gset meta-command, which sets psql variables based on query results, does not distinguish variables that control psql behavior. If an interactive psql session uses \gset when querying a compromised server, the attacker can execute arbitrary code as the operating system account running psql . Using \gset with a prefix not found among specially treated variables, e.g. any lowercase string, precludes the attack in an unpatched psql . The PostgreSQL project thanks Nick Cleaton for reporting this problem.

Fixed in this branch: 10.15. Component: client.

Official affected-branch entry: 10.

AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2020-25695 · Multiple features escape "security restricted operation" sandbox CVSS 8.8

An attacker having permission to create non-temporary objects in at least one schema can execute arbitrary SQL functions under the identity of a superuser. While promptly updating PostgreSQL is the best remediation for most users, a user unable to do that can work around the vulnerability by disabling autovacuum and not manually running ANALYZE , CLUSTER , REINDEX , CREATE INDEX , VACUUM FULL , REFRESH MATERIALIZED VIEW , or a restore from output of the pg_dump command. Performance may degrade quickly under this workaround. VACUUM without the FULL option is safe, and all commands are fine when a trusted user owns the target object. The PostgreSQL project thanks Etienne Stalmans for reporting this problem.

Fixed in this branch: 10.15. Component: core server.

Official affected-branch entry: 10.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2020-25694 · Reconnection can downgrade connection security settings CVSS 8.1

Many PostgreSQL-provided client applications have options that create additional database connections. Some of those applications reuse only the basic connection parameters (e.g. host , user , port ), dropping others. If this drops a security-relevant parameter (e.g. channel_binding , sslmode , requirepeer , gssencmode ), the attacker has an opportunity to complete a MITM attack or observe cleartext transmission. Affected applications are clusterdb , pg_dump , pg_restore , psql , reindexdb , and vacuumdb . The vulnerability arises only if one invokes an affected client application with a connection string containing a security-relevant parameter. This also fixes how the \connect command of psql reuses connection parameters, i.e. all non-overridden parameters from a previous connection string now re-used. The PostgreSQL project thanks Peter Eisentraut for reporting this problem.

Fixed in this branch: 10.15. Component: client.

Official affected-branch entry: 10.

AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2020-1720 · ALTER ... DEPENDS ON EXTENSION is missing authorization checks. CVSS 3.1

The ALTER ... DEPENDS ON EXTENSION sub-commands do not perform authorization checks, which can allow an unprivileged user to drop any function, procedure, materialized view, index, or trigger under certain conditions. This attack is possible if an administrator has installed an extension and an unprivileged user can CREATE , or an extension owner either executes DROP EXTENSION predictably or can be convinced to execute DROP EXTENSION . The PostgreSQL project thanks Tom Lane for reporting this problem.

Fixed in this branch: 10.12. Component: core server.

Official affected-branch entry: 10.

AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N

Release-note mentions:

CVE-2020-14350 · Uncontrolled search path element in CREATE EXTENSION CVSS 7.1

When a superuser runs certain CREATE EXTENSION statements, users may be able to execute arbitrary SQL functions under the identity of that superuser. The attacker must have permission to create objects in the new extension's schema or a schema of a prerequisite extension. Not all extensions are vulnerable. In addition to correcting the extensions provided with PostgreSQL, the PostgreSQL Global Development Group is issuing guidance for third-party extension authors to secure their own work. The PostgreSQL project thanks Andres Freund for reporting this problem.

Fixed in this branch: 10.14. Component: core server.

Official affected-branch entry: 10.

AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2020-14349 · Uncontrolled search path element in logical replication CVSS 7.5

The PostgreSQL search_path setting determines schemas searched for tables, functions, operators, etc. The CVE-2018-1058 fix caused most PostgreSQL-provided client applications to sanitize search_path , but logical replication continued to leave search_path unchanged. Users of a replication publisher or subscriber database can create objects in the public schema and harness them to execute arbitrary SQL functions under the identity running replication, often a superuser. Installations having adopted a documented secure schema usage pattern are not vulnerable. The PostgreSQL project thanks Noah Misch for reporting this problem.

Fixed in this branch: 10.14. Component: core server.

Official affected-branch entry: 10.

AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2020-10733 · Windows installer runs executables from uncontrolled directories CVSS 6.7

The Windows installer for PostgreSQL invokes system-provided executables that do not have fully-qualified paths. Executables in the directory where the installer loads or the current working directory take precedence over the intended executables. An attacker having permission to add files into one of those directories can use this to execute arbitrary code with the installer's administrative rights. The PostgreSQL project thanks Hou JingYi (@hjy79425575) for reporting this problem.

Fixed in this branch: 10.13. Component: packaging.

Official affected-branch entry: 10.

AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

CVE-2019-3466 · pg_ctlcluster script in postgresql-common does not drop privileges when creating socket/statistics temporary directories CVSS 8.4

A PostgreSQL superuser could escalate to root using a deficiency in the pg_ctlcluster command. pg_ctlcluster is a utility provided by the "postgresql-common" package that is installed with PostgreSQL on Debian and Ubuntu platforms.

Fixed in this branch: 10.11. Component: packaging.

Official affected-branch entry: 10.

AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H

CVE-2019-10211 · Windows installer bundled OpenSSL executes code from unprotected directory CVSS 7.8

When the database server or libpq client library initializes SSL, libeay32.dll attempts to read configuration from a hard-coded directory. Typically, the directory does not exist, but any local user could create it and inject configuration. This configuration can direct OpenSSL to load and execute arbitrary code as the user running a PostgreSQL server or client. Most PostgreSQL client tools and libraries use libpq , and one can encounter this vulnerability by using any of them. This vulnerability is much like CVE-2019-5443 , but it originated independently. One can work around the vulnerability by setting environment variable OPENSSL_CONF to "NUL:/openssl.cnf" or any other name that cannot exist as a file. The PostgreSQL project thanks Daniel Gustafsson of the curl security team for reporting this problem.

Fixed in this branch: 10.10. Component: packaging.

Official affected-branch entry: 10.

AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVE-2019-10210 · Windows installer writes superuser password to unprotected temporary file CVSS 6.7

The EnterpriseDB Windows installer writes a password to a temporary file in its installation directory, creates initial databases, and deletes the file. During those seconds while the file exists, a local attacker can read the PostgreSQL superuser password from the file. The PostgreSQL project thanks Noah Misch for reporting this problem.

Fixed in this branch: 10.10. Component: packaging.

Official affected-branch entry: 10.

AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

CVE-2019-10208 · TYPE in pg_temp executes arbitrary SQL during SECURITY DEFINER execution CVSS 7.5

Given a suitable SECURITY DEFINER function, an attacker can execute arbitrary SQL under the identity of the function owner. An attack requires EXECUTE permission on the function, which must itself contain a function call having inexact argument type match. For example, length('foo'::varchar) and length('foo') are inexact, while length('foo'::text) is exact. As part of exploiting this vulnerability, the attacker uses CREATE DOMAIN to create a type in a pg_temp schema. The attack pattern and fix are similar to that for CVE-2007-2138 . Writing SECURITY DEFINER functions continues to require following the considerations noted in the documentation: https://www.postgresql.org/docs/current/sql-createfunction.html#SQL-CREATEFUNCTION-SECURITY The PostgreSQL project thanks Tom Lane for reporting this problem.

Fixed in this branch: 10.10. Component: core server.

Official affected-branch entry: 10.

AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2019-10164 · Stack-based buffer overflow via setting a password CVSS 7.5

An authenticated user could create a stack-based buffer overflow by changing their own password to a purpose-crafted value. In addition to the ability to crash the PostgreSQL server, this could be further exploited to execute arbitrary code as the PostgreSQL operating system account. Additionally, a rogue server could send a specifically crafted message during the SCRAM authentication process and cause a libpq-enabled client to either crash or execute arbitrary code as the client's operating system account. This issue is fixed by upgrading and restarting your PostgreSQL server as well as your libpq installations. The PostgreSQL Project thanks Alexander Lakhin for reporting this problem.

Fixed in this branch: 10.9. Component: core server.

Official affected-branch entry: 10.

AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2019-10130 · Selectivity estimators bypass row security policies CVSS 3.1

PostgreSQL maintains statistics for tables by sampling data available in columns; this data is consulted during the query planning process. Prior to this release, a user able to execute SQL queries with permissions to read a given column could craft a leaky operator that could read whatever data had been sampled from that column. If this happened to include values from rows that the user is forbidden to see by a row security policy, the user could effectively bypass the policy. This is fixed by only allowing a non-leakproof operator to use this data if there are no relevant row security policies for the table. The PostgreSQL project thanks Dean Rasheed for reporting this problem.

Fixed in this branch: 10.8. Component: core server.

Official affected-branch entry: 10.

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2019-10128 · EnterpriseDB Windows installer does not clear permissive ACL entries CVSS 7.0

Due to both the EnterpriseDB and BigSQL Windows installers not locking down the permissions of the PostgreSQL binary installation directory and the data directory, an unprivileged Windows user account and an unprivileged PostgreSQL account could cause the PostgreSQL service account to execute arbitrary code. This vulnerability is present in all supported versions of PostgreSQL for these installers, and possibly exists in older versions. Both sets of installers have fixed the permissions for these directories for both new and existing installations. If you have installed PostgreSQL on Windows using other methods, we advise that you check that your PostgreSQL binary directories are writable only to trusted users and that your data directories are only accessible to trusted users. The PostgreSQL project thanks Conner Jones for reporting this problem.

Fixed in this branch: 10.8. Component: packaging.

Official affected-branch entry: 10.

AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

CVE-2019-10127 · BigSQL Windows installer does not clear permissive ACL entries. CVSS 7.0

Due to both the EnterpriseDB and BigSQL Windows installers not locking down the permissions of the PostgreSQL binary installation directory and the data directory, an unprivileged Windows user account and an unprivileged PostgreSQL account could cause the PostgreSQL service account to execute arbitrary code. This vulnerability is present in all supported versions of PostgreSQL for these installers, and possibly exists in older versions. Both sets of installers have fixed the permissions for these directories for both new and existing installations. If you have installed PostgreSQL on Windows using other methods, we advise that you check that your PostgreSQL binary directories are writable only to trusted users and that your data directories are only accessible to trusted users. The PostgreSQL project thanks Conner Jones for reporting this problem.

Fixed in this branch: 10.8. Component: packaging.

Official affected-branch entry: 10.

AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

CVE-2018-16850 · SQL injection in pg_upgrade and pg_dump, via CREATE TRIGGER ... REFERENCING. CVSS 8.8

Fixed in this branch: 10.6. Component: core server.

Official affected-branch entry: 10.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2018-1115 · Too-permissive access control list on function pg_logfile_rotate() CVSS 3.1

Fixed in this branch: 10.4. Component: contrib module.

Official affected-branch entry: 10.

AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N

Release-note mentions:

CVE-2018-10925 · Memory disclosure and missing authorization in INSERT ... ON CONFLICT DO UPDATE. CVSS 7.1

Fixed in this branch: 10.5. Component: core server.

Official affected-branch entry: 10.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

Release-note mentions:

CVE-2018-10915 · Certain host connection parameters defeat client-side security defenses CVSS 8.5

Fixed in this branch: 10.5. Component: client.

Official affected-branch entry: 10.

AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

Release-note mentions:

CVE-2018-1058 · Uncontrolled search path element in pg_dump and other client applications CVSS 8.8
CVE-2018-1053 · pg_upgrade creates file of sensitive metadata under prevailing umask CVSS 6.7

Fixed in this branch: 10.2. Component: client.

Official affected-branch entry: 10.

AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2018-1052 · Memory disclosure in table partitioning CVSS 6.5

Fixed in this branch: 10.2. Component: core server.

Official affected-branch entry: 10.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Release-note mentions:

CVE-2017-7484 · selectivity estimators bypass SELECT privilege checks CVSS 4.3

No fixed version for this branch is recorded. Component: core server.

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2017-15099 · INSERT ... ON CONFLICT DO UPDATE fails to enforce SELECT privileges CVSS 3.1

Fixed in this branch: 10.1. Component: core server.

Official affected-branch entry: 10.

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2017-15098 · Memory disclosure in JSON functions CVSS 4.3

Fixed in this branch: 10.1. Component: core server.

Official affected-branch entry: 10.

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2017-12172 · Start scripts permit database administrator to modify root-owned files CVSS 8.4

Fixed in this branch: 10.1. Component: contrib module.

Official affected-branch entry: 10.

AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H

Release-note mentions:

CVE-2007-2138 · A vulnerability involving insecure search_path settings allows unprivileged users to gain the SQL privileges of the owner of any SECURITY DEFINER function they are allowed to call. Securing such a function requires both a software update and changes to the function definition.

No fixed version for this branch is recorded.

Release-note mentions:

CVE-2006-2313 · An attacker able to submit crafted strings to an application that will embed those strings in SQL commands can use invalidly-encoded multibyte characters to bypass standard string-escaping methods, resulting in possible SQL injection.

Export this branch as JSON · Compare any two indexed releases