PostgreSQL 12
Read the English manualEnd of life · Recorded build 12.22 · 2024-11-21
This major branch is no longer supported. These records describe its history; the absence of newer security records does not establish that it is safe to run.
- First stable release
- 2019-10-03
- Support end
- 2024-11-21
- Indexed releases
- 23
- Original release-note entries
- 1181
Manuals & provenance
PostgreSQL 12 English manual · 1133 loaded pages.
Manual loaded 2026-09-27T00:10:47.078613.
Release entries: 2026-09-26. Security evidence: 2026-09-26. PDF links use the verified English manifest and locally available files. Lifecycle: PostgreSQL versioning policy.
Upgrade considerations
Major upgrades need a migration method such as dump/reload or pg_upgrade. Read the intervening major-release notes and the target manual. Minor updates can also require extra steps; review the specific release's migration notes. Official upgrade policy.
Compatibility notes for 12.0 · Changes from the initial release through 12.22
Original migration guidance for 12.0
A dump/restore using pg_dumpall or use of pg_upgrade or logical replication is required for those wishing to migrate data from any previous release. See Section 18.6 for general information on migrating to new major releases.
Version 12 contains a number of changes that may affect compatibility with previous releases. Observe the following incompatibilities:
Release history
Every indexed release keeps its original occurrences. CVE counts below are mentions in its notes, including follow-up corrections; they do not count newly fixed vulnerabilities.
| Release | Date / snapshot cutoff | All changes | Bug fixes | Migration entries | CVE mentions |
|---|---|---|---|---|---|
| 12.22 | 2024-11-21 | 1 | 0 | 0 | 1 |
| 12.21 | 2024-11-14 | 34 | 11 | 0 | 4 |
| 12.20 | 2024-08-08 | 34 | 16 | 0 | 2 |
| 12.19 | 2024-05-09 | 35 | 15 | 0 | 0 |
| 12.18 | 2024-02-08 | 39 | 14 | 0 | 1 |
| 12.17 | 2023-11-09 | 43 | 15 | 0 | 3 |
| 12.16 | 2023-08-10 | 32 | 14 | 0 | 1 |
| 12.15 | 2023-05-11 | 50 | 26 | 0 | 2 |
| 12.14 | 2023-02-09 | 36 | 15 | 0 | 1 |
| 12.13 | 2022-11-10 | 38 | 19 | 0 | 0 |
| 12.12 | 2022-08-11 | 39 | 15 | 0 | 2 |
| 12.11 | 2022-05-12 | 36 | 18 | 0 | 1 |
| 12.10 | 2022-02-10 | 33 | 16 | 0 | 0 |
| 12.9 | 2021-11-11 | 63 | 30 | 0 | 2 |
| 12.8 | 2021-08-12 | 68 | 23 | 0 | 3 |
| 12.7 | 2021-05-13 | 41 | 23 | 0 | 3 |
| 12.6 | 2021-02-11 | 67 | 33 | 0 | 1 |
| 12.5 | 2020-11-12 | 58 | 24 | 0 | 3 |
| 12.4 | 2020-08-13 | 52 | 27 | 0 | 3 |
| 12.3 | 2020-05-14 | 76 | 31 | 0 | 0 |
| 12.2 | 2020-02-13 | 75 | 44 | 0 | 2 |
| 12.1 | 2019-11-14 | 51 | 24 | 0 | 0 |
| 12.0 | 2019-10-03 | 180 | 4 | 23 | 0 |
Initial release changes
Original entries from 12.0, including feature changes and compatibility notes. Categories aid browsing; they are not upstream classifications.
180 of 180 original entries.
Remove the special behavior of oid columns Compatibility Migration
Remove the special behavior of oid columns (Andres Freund, John Naylor) §
Previously, a normally-invisible
oidcolumn could be specified during table creation usingWITH OIDS; that ability has been removed. Columns can still be explicitly declared as typeoid. Operations on tables that have columns created usingWITH OIDSwill need adjustment.The system catalogs that previously had hidden
oidcolumns now have ordinaryoidcolumns. Hence,SELECT *will now output those columns, whereas previously they would be displayed only if selected explicitly.Original release occurrence ·
12.0/migration/001Remove data types abstime, reltime, and tinterval Compatibility Migration
Remove data types
abstime,reltime, andtinterval(Andres Freund) §These are obsoleted by SQL-standard types such as
timestamp.Original release occurrence ·
12.0/migration/002Remove the timetravel extension Compatibility Migration
Remove the
timetravelextension (Andres Freund) §Original release occurrence ·
12.0/migration/003Move recovery.conf settings into postgresql.conf Compatibility Migration
Move
recovery.confsettings intopostgresql.conf(Masao Fujii, Simon Riggs, Abhijit Menon-Sen, Sergei Kornilov) §recovery.confis no longer used, and the server will not start if that file exists. recovery.signal andstandby.signalfiles are now used to switch into non-primary mode. Thetrigger_filesetting has been renamed to promote_trigger_file. Thestandby_modesetting has been removed.Original release occurrence ·
12.0/migration/004Do not allow multiple conflicting recovery_target* specifications Compatibility Migration
Do not allow multiple conflicting
recovery_target* specifications (Peter Eisentraut) §Specifically, only allow one of recovery_target, recovery_target_lsn, recovery_target_name, recovery_target_time, and recovery_target_xid. Previously, multiple different instances of these parameters could be specified, and the last one was honored. Now, only one can be specified, though the same one can be specified multiple times and the last specification is honored.
Original release occurrence ·
12.0/migration/005Cause recovery to advance to the latest timeline by default Compatibility Migration
Cause recovery to advance to the latest timeline by default (Peter Eisentraut) §
Specifically, recovery_target_timeline now defaults to
latest. Previously, it defaulted tocurrent.Original release occurrence ·
12.0/migration/006Refactor code for geometric functions and operators Compatibility Migration
Refactor code for geometric functions and operators (Emre Hasegeli) § § §
This could lead to more accurate, but slightly different, results compared to previous releases. Notably, cases involving NaN, underflow, overflow, and division by zero are handled more consistently than before.
Original release occurrence ·
12.0/migration/007Improve performance by using a new algorithm for output of real and double precision values Compatibility Migration
Improve performance by using a new algorithm for output of
realanddouble precisionvalues (Andrew Gierth) § §Previously, displayed floating-point values were rounded to 6 (for
real) or 15 (fordouble precision) digits by default, adjusted by the value of extra_float_digits. Now, wheneverextra_float_digitsis more than zero (as it now is by default), only the minimum number of digits required to preserve the exact binary value are output. The behavior is the same as before whenextra_float_digitsis set to zero or less.Also, formatting of floating-point exponents is now uniform across platforms: two digits are used unless three are necessary. In previous releases, Windows builds always printed three digits.
Original release occurrence ·
12.0/migration/008random() and setseed() now behave uniformly across platforms Compatibility Migration
random()andsetseed()now behave uniformly across platforms (Tom Lane) § §The sequence of
random()values generated following asetseed()call with a particular seed value is likely to be different now than before. However, it will also be repeatable, which was not previously guaranteed because of interference from other uses of random numbers inside the server. The SQLrandom()function now has its own private per-session state to forestall that.Original release occurrence ·
12.0/migration/009Change SQL-style substring() to have standard-compliant greediness behavior Compatibility Migration
Change SQL-style
substring()to have standard-compliant greediness behavior (Tom Lane) §In cases where the pattern can be matched in more than one way, the initial sub-pattern is now treated as matching the least possible amount of text rather than the greatest; for example, a pattern such as
%#"aa*#"%now selects the first group ofa's from the input, not the last group.Original release occurrence ·
12.0/migration/010Do not pretty-print the result of xpath() or the XMLTABLE construct Compatibility Migration
Do not pretty-print the result of
xpath()or theXMLTABLEconstruct (Tom Lane) §In some cases, these functions would insert extra whitespace (newlines and/or spaces) in nodeset values. This is undesirable since depending on usage, the whitespace might be considered semantically significant.
Original release occurrence ·
12.0/migration/011Rename command-line tool pg_verify_checksums to pg_checksums Compatibility Migration
Rename command-line tool pg_verify_checksums to pg_checksums (Michaël Paquier) §
Original release occurrence ·
12.0/migration/012In pg_restore, require specification of -f - to send the dump contents to standard output Compatibility Migration
In pg_restore, require specification of
-f -to send the dump contents to standard output (Euler Taveira) §Previously, this happened by default if no destination was specified, but that was deemed to be unfriendly.
Original release occurrence ·
12.0/migration/013Disallow non-unique abbreviations in psql's \pset format command Compatibility Migration
Disallow non-unique abbreviations in psql's
\pset formatcommand (Daniel Vérité) § §Previously, for example,
\pset format achosealigned; it will now fail since that could equally well meanasciidoc.Original release occurrence ·
12.0/migration/014In new btree indexes, the maximum index entry length is reduced by eight bytes, to improve handling of duplicate entries Compatibility Migration
In new btree indexes, the maximum index entry length is reduced by eight bytes, to improve handling of duplicate entries (Peter Geoghegan) §
This means that a REINDEX operation on an index pg_upgrade'd from a previous release could potentially fail.
Original release occurrence ·
12.0/migration/015Cause DROP IF EXISTS FUNCTION/PROCEDURE/AGGREGATE/ROUTINE to generate an error if no argument list is supplied and there are multiple matching objects Compatibility Migration
Cause
DROP IF EXISTS FUNCTION/PROCEDURE/AGGREGATE/ROUTINEto generate an error if no argument list is supplied and there are multiple matching objects (David Rowley) §Also improve the error message in such cases.
Original release occurrence ·
12.0/migration/016Split the pg_statistic_ext catalog into two catalogs, and add the pg_stats_ext view of it Compatibility Migration
Split the
pg_statistic_extcatalog into two catalogs, and add thepg_stats_extview of it (Dean Rasheed, Tomas Vondra) § §This change supports hiding potentially-sensitive statistics data from unprivileged users.
Original release occurrence ·
12.0/migration/017Remove obsolete pg_constraint.consrc column Compatibility Migration
Remove obsolete
pg_constraint.consrccolumn (Peter Eisentraut) §This column has been deprecated for a long time, because it did not update in response to other catalog changes (such as column renamings). The recommended way to get a text version of a check constraint's expression from
pg_constraintispg_get_expr(conbin, conrelid).pg_get_constraintdef()is also a useful alternative.Original release occurrence ·
12.0/migration/018Remove obsolete pg_attrdef.adsrc column Compatibility Migration
Remove obsolete
pg_attrdef.adsrccolumn (Peter Eisentraut) §This column has been deprecated for a long time, because it did not update in response to other catalog changes (such as column renamings). The recommended way to get a text version of a default-value expression from
pg_attrdefispg_get_expr(adbin, adrelid).Original release occurrence ·
12.0/migration/019Mark table columns of type name as having “C” collation by default Compatibility Migration
Mark table columns of type name as having “C” collation by default (Tom Lane, Daniel Vérité) § §
The comparison operators for data type
namecan now use any collation, rather than always using “C” collation. To preserve the previous semantics of queries, columns of typenameare now explicitly marked as having “C” collation. A side effect of this is that regular-expression operators onnamecolumns will now use the “C” collation by default, not the database collation, to determine the behavior of locale-dependent regular expression patterns (such as\w). If you want non-C behavior for a regular expression on anamecolumn, attach an explicitCOLLATEclause. (For user-definednamecolumns, another possibility is to specify a different collation at table creation time; but that just moves the non-backwards-compatibility to the comparison operators.)Original release occurrence ·
12.0/migration/020Treat object-name columns in the information_schema views as being of type name, not varchar Compatibility Migration
Treat object-name columns in the
information_schemaviews as being of typename, notvarchar(Tom Lane) § § §Per the SQL standard, object-name columns in the
information_schemaviews are declared as being of domain typesql_identifier. In PostgreSQL, the underlying catalog columns are really of typename. This change makessql_identifierbe a domain overname, rather thanvarcharas before. This eliminates a semantic mismatch in comparison and sorting behavior, which can greatly improve the performance of queries oninformation_schemaviews that restrict an object-name column. Note however that inequality restrictions, for exampleSELECT ... FROM information_schema.tables WHERE table_name < 'foo';
will now use “C”-locale comparison semantics by default, rather than the database's default collation as before. Sorting on these columns will also follow “C” ordering rules. The previous behavior (and inefficiency) can be enforced by adding a
COLLATE "default"clause.Original release occurrence ·
12.0/migration/021Remove the ability to disable dynamic shared memory Compatibility Migration
Remove the ability to disable dynamic shared memory (Kyotaro Horiguchi) §
Specifically, dynamic_shared_memory_type can no longer be set to
none.Original release occurrence ·
12.0/migration/022Parse libpq integer connection parameters more strictly Compatibility Migration
Parse libpq integer connection parameters more strictly (Fabien Coelho) §
In previous releases, using an incorrect integer value for connection parameters
connect_timeout,keepalives,keepalives_count,keepalives_idle,keepalives_intervalandportresulted in libpq either ignoring those values or failing with incorrect error messages.Original release occurrence ·
12.0/migration/023Improve performance of many operations on partitioned tables Performance
Improve performance of many operations on partitioned tables (Amit Langote, David Rowley, Tom Lane, Álvaro Herrera) § § § § §
Allow tables with thousands of child partitions to be processed efficiently by operations that only affect a small number of partitions.
Original release occurrence ·
12.0/changes/001Allow foreign keys to reference partitioned tables Features
Allow foreign keys to reference partitioned tables (Álvaro Herrera) §
Original release occurrence ·
12.0/changes/002Improve speed of COPY into partitioned tables Features
Improve speed of
COPYinto partitioned tables (David Rowley) §Original release occurrence ·
12.0/changes/003Allow partition bounds to be any expression Features
Allow partition bounds to be any expression (Kyotaro Horiguchi, Tom Lane, Amit Langote) §
Such expressions are evaluated at partitioned-table creation time. Previously, only simple constants were allowed as partition bounds.
Original release occurrence ·
12.0/changes/004Allow CREATE TABLE's tablespace specification for a partitioned table to affect the tablespace of its children Features
Allow
CREATE TABLE's tablespace specification for a partitioned table to affect the tablespace of its children (David Rowley, Álvaro Herrera) §Original release occurrence ·
12.0/changes/005Avoid sorting when partitions are already being scanned in the necessary order Features
Avoid sorting when partitions are already being scanned in the necessary order (David Rowley) §
Original release occurrence ·
12.0/changes/006ALTER TABLE ATTACH PARTITION is now performed with reduced locking requirements Features
ALTER TABLE ATTACH PARTITIONis now performed with reduced locking requirements (Robert Haas) §Original release occurrence ·
12.0/changes/007Add partition introspection functions Features
Add partition introspection functions (Michaël Paquier, Álvaro Herrera, Amit Langote) § § §
The new function
pg_partition_root()returns the top-most parent of a partition tree,pg_partition_ancestors()reports all ancestors of a partition, andpg_partition_tree()displays information about partitions.Original release occurrence ·
12.0/changes/008Include partitioned indexes in the system view pg_indexes Features
Include partitioned indexes in the system view
pg_indexes(Suraj Kharage) §Original release occurrence ·
12.0/changes/009Add psql command \dP to list partitioned tables and indexes Features
Add psql command
\dPto list partitioned tables and indexes (Pavel Stehule) §Original release occurrence ·
12.0/changes/010Improve psql \d and \z display of partitioned tables Features
Improve psql
\dand\zdisplay of partitioned tables (Pavel Stehule, Michaël Paquier, Álvaro Herrera) § § §Original release occurrence ·
12.0/changes/011Fix bugs that could cause ALTER TABLE DETACH PARTITION to leave behind incorrect dependency state, allowing subsequent operations to misbehave, for example by not dropping a former partition child index when its table is dropped Bug fixes
Fix bugs that could cause
ALTER TABLE DETACH PARTITIONto leave behind incorrect dependency state, allowing subsequent operations to misbehave, for example by not dropping a former partition child index when its table is dropped (Tom Lane) §Original release occurrence ·
12.0/changes/012Improve performance and space utilization of btree indexes with many duplicates Performance
Improve performance and space utilization of btree indexes with many duplicates (Peter Geoghegan, Heikki Linnakangas) § § §
Previously, duplicate index entries were stored unordered within their duplicate groups. This caused overhead during index inserts, wasted space due to excessive page splits, and it reduced
VACUUM's ability to recycle entire pages. Duplicate index entries are now sorted in heap-storage order.Indexes pg_upgrade'd from previous releases will not have these benefits.
Original release occurrence ·
12.0/changes/013Allow multi-column btree indexes to be smaller Features
Allow multi-column btree indexes to be smaller (Peter Geoghegan, Heikki Linnakangas)
Internal pages and min/max leaf page indicators now only store index keys until the change key, rather than all indexed keys. This also improves the locality of index access.
Indexes pg_upgrade'd from previous releases will not have these benefits.
Original release occurrence ·
12.0/changes/014Improve speed of btree index insertions by reducing locking overhead Features
Improve speed of btree index insertions by reducing locking overhead (Alexander Korotkov) §
Original release occurrence ·
12.0/changes/015Support INCLUDE columns in GiST indexes Features
Original release occurrence ·
12.0/changes/016Add support for nearest-neighbor (KNN) searches of SP-GiST indexes Features
Add support for nearest-neighbor (KNN) searches of SP-GiST indexes (Nikita Glukhov, Alexander Korotkov, Vlad Sterzhanov) §
Original release occurrence ·
12.0/changes/017Reduce the WAL write overhead of GiST, GIN, and SP-GiST index creation Performance
Reduce the WAL write overhead of GiST, GIN, and SP-GiST index creation (Anastasia Lubennikova, Andrey V. Lepikhov) §
Original release occurrence ·
12.0/changes/018Allow index-only scans to be more efficient on indexes with many columns Features
Allow index-only scans to be more efficient on indexes with many columns (Konstantin Knizhnik) §
Original release occurrence ·
12.0/changes/019Improve the performance of vacuum scans of GiST indexes Performance
Improve the performance of vacuum scans of GiST indexes (Andrey Borodin, Konstantin Kuznetsov, Heikki Linnakangas) §
Original release occurrence ·
12.0/changes/020Delete empty leaf pages during GiST VACUUM Features
Delete empty leaf pages during GiST
VACUUM(Andrey Borodin) §Original release occurrence ·
12.0/changes/021Reduce locking requirements for index renaming Features
Reduce locking requirements for index renaming (Peter Eisentraut) §
Original release occurrence ·
12.0/changes/022Allow CREATE STATISTICS to create most-common-value statistics for multiple columns Features
Allow CREATE STATISTICS to create most-common-value statistics for multiple columns (Tomas Vondra) § §
This improves optimization for queries that test several columns, requiring an estimate of the combined effect of several
WHEREclauses. If the columns are correlated and have non-uniform distributions then multi-column statistics will allow much better estimates.Original release occurrence ·
12.0/changes/023Allow common table expressions (CTEs) to be inlined into the outer query Features
Allow common table expressions (CTEs) to be inlined into the outer query (Andreas Karlsson, Andrew Gierth, David Fetter, Tom Lane) § §
Specifically, CTEs are automatically inlined if they have no side-effects, are not recursive, and are referenced only once in the query. Inlining can be prevented by specifying
MATERIALIZED, or forced for multiply-referenced CTEs by specifyingNOT MATERIALIZED. Previously, CTEs were never inlined and were always evaluated before the rest of the query.Original release occurrence ·
12.0/changes/024Allow control over when generic plans are used for prepared statements Features
Allow control over when generic plans are used for prepared statements (Pavel Stehule) §
This is controlled by the plan_cache_mode server parameter.
Original release occurrence ·
12.0/changes/025Improve optimization of partition and UNION ALL queries that have only a single child Features
Improve optimization of partition and
UNION ALLqueries that have only a single child (David Rowley) §Original release occurrence ·
12.0/changes/026Improve processing of domains that have no check constraints Features
Improve processing of domains that have no check constraints (Tom Lane) §
Domains that are being used purely as type aliases no longer cause optimization difficulties.
Original release occurrence ·
12.0/changes/027Pre-evaluate calls of LEAST and GREATEST when their arguments are constants Features
Original release occurrence ·
12.0/changes/028Improve optimizer's ability to verify that partial indexes with IS NOT NULL conditions are usable in queries Features
Improve optimizer's ability to verify that partial indexes with
IS NOT NULLconditions are usable in queries (Tom Lane, James Coleman) § §Usability can now be recognized in more cases where the calling query involves casts or large
clauses.xIN (array)Original release occurrence ·
12.0/changes/029Compute ANALYZE statistics using the collation defined for each column Features
Compute
ANALYZEstatistics using the collation defined for each column (Tom Lane) §Previously, the database's default collation was used for all statistics. This potentially gives better optimizer behavior for columns with non-default collations.
Original release occurrence ·
12.0/changes/030Improve selectivity estimates for inequality comparisons on ctid columns Features
Original release occurrence ·
12.0/changes/031Improve optimization of joins on columns of type tid Features
Improve optimization of joins on columns of type
tid(Tom Lane) § §These changes primarily improve the efficiency of self-joins on
ctidcolumns.Original release occurrence ·
12.0/changes/032Fix the leakproofness designations of some btree comparison operators and support functions Bug fixes
Fix the leakproofness designations of some btree comparison operators and support functions (Tom Lane) § §
This allows some optimizations that previously would not have been applied in the presence of security barrier views or row-level security.
Original release occurrence ·
12.0/changes/033Enable Just-in-Time (JIT) compilation by default, if the server has been built with support for it Performance
Enable Just-in-Time (JIT) compilation by default, if the server has been built with support for it (Andres Freund) §
Note that this support is not built by default, but has to be selected explicitly while configuring the build.
Original release occurrence ·
12.0/changes/034Speed up keyword lookup Performance
Original release occurrence ·
12.0/changes/035Improve search performance for multi-byte characters in position() and related functions Performance
Improve search performance for multi-byte characters in
position()and related functions (Heikki Linnakangas) §Original release occurrence ·
12.0/changes/036Allow toasted values to be minimally decompressed Performance
Allow toasted values to be minimally decompressed (Paul Ramsey) §
This is useful for routines that only need to examine the initial portion of a toasted field.
Original release occurrence ·
12.0/changes/037Allow ALTER TABLE ... SET NOT NULL to avoid unnecessary table scans Performance
Allow
ALTER TABLE ... SET NOT NULLto avoid unnecessary table scans (Sergei Kornilov) §This can be optimized when the table's column constraints can be recognized as disallowing nulls.
Original release occurrence ·
12.0/changes/038Allow ALTER TABLE ... SET DATA TYPE changing between timestamp and timestamptz to avoid a table rewrite when the session time zone is UTC Performance
Allow
ALTER TABLE ... SET DATA TYPEchanging betweentimestampandtimestamptzto avoid a table rewrite when the session time zone is UTC (Noah Misch) §In the UTC time zone, these two data types are binary compatible.
Original release occurrence ·
12.0/changes/039Improve speed in converting strings to int2 or int4 integers Performance
Improve speed in converting strings to
int2orint4integers (Andres Freund) §Original release occurrence ·
12.0/changes/040Allow parallelized queries when in SERIALIZABLE isolation mode Performance
Allow parallelized queries when in
SERIALIZABLEisolation mode (Thomas Munro) §Previously, parallelism was disabled when in this mode.
Original release occurrence ·
12.0/changes/041Use pread() and pwrite() for random I/O Performance
Use
pread()andpwrite()for random I/O (Oskari Saarenmaa, Thomas Munro) § §This reduces the number of system calls required for I/O.
Original release occurrence ·
12.0/changes/042Improve the speed of setting the process title on FreeBSD Performance
Improve the speed of setting the process title on FreeBSD (Thomas Munro) §
Original release occurrence ·
12.0/changes/043Allow logging of statements from only a percentage of transactions Features
Allow logging of statements from only a percentage of transactions (Adrien Nayrat) §
The parameter log_transaction_sample_rate controls this.
Original release occurrence ·
12.0/changes/044Add progress reporting to CREATE INDEX and REINDEX operations Features
Add progress reporting to
CREATE INDEXandREINDEXoperations (Álvaro Herrera, Peter Eisentraut) § §Progress is reported in the
pg_stat_progress_create_indexsystem view.Original release occurrence ·
12.0/changes/045Add progress reporting to CLUSTER and VACUUM FULL Features
Add progress reporting to
CLUSTERandVACUUM FULL(Tatsuro Yamada) §Progress is reported in the
pg_stat_progress_clustersystem view.Original release occurrence ·
12.0/changes/046Add progress reporting to pg_checksums Features
Add progress reporting to pg_checksums (Michael Banck, Bernd Helmle) §
This is enabled with the option
--progress.Original release occurrence ·
12.0/changes/047Add counter of checksum failures to pg_stat_database Features
Add counter of checksum failures to
pg_stat_database(Magnus Hagander) §Original release occurrence ·
12.0/changes/048Add tracking of global objects in system view pg_stat_database Features
Add tracking of global objects in system view
pg_stat_database(Julien Rouhaud) §Global objects are shown with a
pg_stat_database.datidvalue of zero.Original release occurrence ·
12.0/changes/049Add the ability to list the contents of the archive directory Features
Add the ability to list the contents of the archive directory (Christoph Moench-Tegeder) §
The function is
pg_ls_archive_statusdir().Original release occurrence ·
12.0/changes/050Add the ability to list the contents of temporary directories Features
Add the ability to list the contents of temporary directories (Nathan Bossart) §
The function,
pg_ls_tmpdir(), optionally allows specification of a tablespace.Original release occurrence ·
12.0/changes/051Add information about the client certificate to the system view pg_stat_ssl Features
Add information about the client certificate to the system view
pg_stat_ssl(Peter Eisentraut) §The new columns are
client_serialandissuer_dn. Columnclientdnhas been renamed toclient_dnfor clarity.Original release occurrence ·
12.0/changes/052Restrict visibility of rows in pg_stat_ssl for unprivileged users Features
Restrict visibility of rows in
pg_stat_sslfor unprivileged users (Peter Eisentraut) §Original release occurrence ·
12.0/changes/053At server start, emit a log message including the server version number Features
At server start, emit a log message including the server version number (Christoph Berg) §
Original release occurrence ·
12.0/changes/054Prevent logging “incomplete startup packet” if a new connection is immediately closed Features
Prevent logging “incomplete startup packet” if a new connection is immediately closed (Tom Lane) §
This avoids log spam from certain forms of monitoring.
Original release occurrence ·
12.0/changes/055Include the application_name, if set, in log_connections log messages Features
Include the application_name, if set, in log_connections log messages (Don Seiler) §
Original release occurrence ·
12.0/changes/056Make the walreceiver set its application name to the cluster name, if set Features
Make the walreceiver set its application name to the cluster name, if set (Peter Eisentraut) §
Original release occurrence ·
12.0/changes/057Add the timestamp of the last received standby message to pg_stat_replication Features
Add the timestamp of the last received standby message to
pg_stat_replication(Lim Myungkyu) §Original release occurrence ·
12.0/changes/058Add a wait event for fsync of WAL segments Features
Add a wait event for fsync of WAL segments (Konstantin Knizhnik) §
Original release occurrence ·
12.0/changes/059Add GSSAPI encryption support Features
Add GSSAPI encryption support (Robbie Harwood, Stephen Frost) §
This feature allows TCP/IP connections to be encrypted when using GSSAPI authentication, without having to set up a separate encryption facility such as SSL. In support of this, add
hostgssencandhostnogssencrecord types inpg_hba.conffor selecting connections that do or do not use GSSAPI encryption, corresponding to the existinghostsslandhostnosslrecord types. There is also a new gssencmode libpq option, and a pg_stat_gssapi system view.Original release occurrence ·
12.0/changes/060Allow the clientcert pg_hba.conf option to check that the database user name matches the client certificate's common name Features
Allow the
clientcertpg_hba.confoption to check that the database user name matches the client certificate's common name (Julian Markwort, Marius Timmer) §This new check is enabled with
clientcert=verify-full.Original release occurrence ·
12.0/changes/061Allow discovery of an LDAP server using DNS SRV records Features
Allow discovery of an LDAP server using DNS SRV records (Thomas Munro) §
This avoids the requirement of specifying
ldapserver. It is only supported if PostgreSQL is compiled with OpenLDAP.Original release occurrence ·
12.0/changes/062Add ability to enable/disable cluster checksums using pg_checksums Features
Add ability to enable/disable cluster checksums using pg_checksums (Michael Banck, Michaël Paquier) §
The cluster must be shut down for these operations.
Original release occurrence ·
12.0/changes/063Reduce the default value of autovacuum_vacuum_cost_delay to 2ms Features
Reduce the default value of autovacuum_vacuum_cost_delay to 2ms (Tom Lane) §
This allows autovacuum operations to proceed faster by default.
Original release occurrence ·
12.0/changes/064Allow vacuum_cost_delay to specify sub-millisecond delays, by accepting fractional values Features
Allow vacuum_cost_delay to specify sub-millisecond delays, by accepting fractional values (Tom Lane) §
Original release occurrence ·
12.0/changes/065Allow time-based server parameters to use units of microseconds (us) Features
Allow time-based server parameters to use units of microseconds (
us) (Tom Lane) §Original release occurrence ·
12.0/changes/066Allow fractional input for integer server parameters Features
Allow fractional input for integer server parameters (Tom Lane) §
For example,
SET work_mem = '30.1GB'is now allowed, even thoughwork_memis an integer parameter. The value will be rounded to an integer after any required units conversion.Original release occurrence ·
12.0/changes/067Allow units to be defined for floating-point server parameters Features
Allow units to be defined for floating-point server parameters (Tom Lane) §
Original release occurrence ·
12.0/changes/068Add wal_recycle and wal_init_zero server parameters to control WAL file recycling Features
Add wal_recycle and wal_init_zero server parameters to control WAL file recycling (Jerry Jelinek) §
Avoiding file recycling can be beneficial on copy-on-write file systems like ZFS.
Original release occurrence ·
12.0/changes/069Add server parameter tcp_user_timeout to control the server's TCP timeout Features
Add server parameter tcp_user_timeout to control the server's TCP timeout (Ryohei Nagaura) §
Original release occurrence ·
12.0/changes/070Allow control of the minimum and maximum SSL protocol versions Features
Allow control of the minimum and maximum SSL protocol versions (Peter Eisentraut) §
The server parameters are ssl_min_protocol_version and ssl_max_protocol_version.
Original release occurrence ·
12.0/changes/071Add server parameter ssl_library to report the SSL library version used by the server Features
Add server parameter ssl_library to report the SSL library version used by the server (Peter Eisentraut) §
Original release occurrence ·
12.0/changes/072Add server parameter shared_memory_type to control the type of shared memory to use Features
Add server parameter shared_memory_type to control the type of shared memory to use (Andres Freund) §
This allows selection of System V shared memory, if desired.
Original release occurrence ·
12.0/changes/073Allow some recovery parameters to be changed with reload Features
Allow some recovery parameters to be changed with reload (Peter Eisentraut) §
These parameters are archive_cleanup_command, promote_trigger_file, recovery_end_command, and recovery_min_apply_delay.
Original release occurrence ·
12.0/changes/074Allow the streaming replication timeout (wal_sender_timeout) to be set per connection Features
Allow the streaming replication timeout (wal_sender_timeout) to be set per connection (Takayuki Tsunakawa) §
Previously, this could only be set cluster-wide.
Original release occurrence ·
12.0/changes/075Add function pg_promote() to promote standbys to primaries Features
Add function
pg_promote()to promote standbys to primaries (Laurenz Albe, Michaël Paquier) § §Previously, this operation was only possible by using pg_ctl or creating a trigger file.
Original release occurrence ·
12.0/changes/076Allow replication slots to be copied Features
Allow replication slots to be copied (Masahiko Sawada) §
The functions for this are
pg_copy_physical_replication_slot()andpg_copy_logical_replication_slot().Original release occurrence ·
12.0/changes/077Make max_wal_senders not count as part of max_connections Features
Make max_wal_senders not count as part of max_connections (Alexander Kukushkin) §
Original release occurrence ·
12.0/changes/078Add an explicit value of current for recovery_target_timeline Features
Add an explicit value of
currentfor recovery_target_timeline (Peter Eisentraut) §Original release occurrence ·
12.0/changes/079Make recovery fail if a two-phase transaction status file is corrupt Features
Make recovery fail if a two-phase transaction status file is corrupt (Michaël Paquier) §
Previously, a warning was logged and recovery continued, allowing the transaction to be lost.
Original release occurrence ·
12.0/changes/080Add REINDEX CONCURRENTLY option to allow reindexing without locking out writes Features
Add REINDEX
CONCURRENTLYoption to allow reindexing without locking out writes (Michaël Paquier, Andreas Karlsson, Peter Eisentraut) §This is also controlled by the reindexdb application's
--concurrentlyoption.Original release occurrence ·
12.0/changes/081Add support for generated columns Features
Add support for generated columns (Peter Eisentraut) §
The content of generated columns are computed from expressions (including references to other columns in the same table) rather than being specified by
INSERTorUPDATEcommands.Original release occurrence ·
12.0/changes/082Add a WHERE clause to COPY FROM to control which rows are accepted Features
Add a
WHEREclause toCOPY FROMto control which rows are accepted (Surafel Temesgen) §This provides a simple way to filter incoming data.
Original release occurrence ·
12.0/changes/083Allow enumerated values to be added more flexibly Features
Allow enumerated values to be added more flexibly (Andrew Dunstan, Tom Lane, Thomas Munro) §
Previously,
ALTER TYPE ... ADD VALUEcould not be called in a transaction block, unless it was part of the same transaction that created the enumerated type. Now it can be called in a later transaction, so long as the new enumerated value is not referenced until after it is committed.Original release occurrence ·
12.0/changes/084Add commands to end a transaction and start a new one Features
Add commands to end a transaction and start a new one (Peter Eisentraut) §
The commands are
COMMIT AND CHAINandROLLBACK AND CHAIN.Original release occurrence ·
12.0/changes/085Add VACUUM and CREATE TABLE options to prevent VACUUM from truncating trailing empty pages Features
Add VACUUM and
CREATE TABLEoptions to preventVACUUMfrom truncating trailing empty pages (Takayuki Tsunakawa) § §These options are
vacuum_truncateandtoast.vacuum_truncate. Use of these options reducesVACUUM's locking requirements, but prevents returning disk space to the operating system.Original release occurrence ·
12.0/changes/086Allow VACUUM to skip index cleanup Features
Allow
VACUUMto skip index cleanup (Masahiko Sawada) § §This change adds a
VACUUMcommand optionINDEX_CLEANUPas well as a table storage optionvacuum_index_cleanup. Use of this option reduces the ability to reclaim space and can lead to index bloat, but it is helpful when the main goal is to freeze old tuples.Original release occurrence ·
12.0/changes/087Add the ability to skip VACUUM and ANALYZE operations on tables that cannot be locked immediately Features
Add the ability to skip
VACUUMandANALYZEoperations on tables that cannot be locked immediately (Nathan Bossart) §This option is called
SKIP_LOCKED.Original release occurrence ·
12.0/changes/088Allow VACUUM and ANALYZE to take optional Boolean argument specifications Features
Allow
VACUUMandANALYZEto take optional Boolean argument specifications (Masahiko Sawada) §Original release occurrence ·
12.0/changes/089Prevent TRUNCATE, VACUUM and ANALYZE from requesting a lock on tables for which the user lacks permission Features
Prevent TRUNCATE,
VACUUMandANALYZEfrom requesting a lock on tables for which the user lacks permission (Michaël Paquier) § §This prevents unauthorized locking, which could interfere with user queries.
Original release occurrence ·
12.0/changes/090Add EXPLAIN option SETTINGS to output non-default optimizer settings Features
Add EXPLAIN option
SETTINGSto output non-default optimizer settings (Tomas Vondra) §This output can also be obtained when using auto_explain by setting
auto_explain.log_settings.Original release occurrence ·
12.0/changes/091Add OR REPLACE option to CREATE AGGREGATE Features
Add
OR REPLACEoption to CREATE AGGREGATE (Andrew Gierth) §Original release occurrence ·
12.0/changes/092Allow modifications of system catalogs' options using ALTER TABLE Features
Allow modifications of system catalogs' options using ALTER TABLE (Peter Eisentraut) §
Modifications of catalogs'
reloptionsand autovacuum settings are now supported. (Setting allow_system_table_mods is still required.)Original release occurrence ·
12.0/changes/093Use all key columns' names when selecting default constraint names for foreign keys Features
Use all key columns' names when selecting default constraint names for foreign keys (Peter Eisentraut) §
Previously, only the first column name was included in the constraint name, resulting in ambiguity for multi-column foreign keys.
Original release occurrence ·
12.0/changes/094Update assorted knowledge about Unicode to match Unicode 12.1.0 Features
Update assorted knowledge about Unicode to match Unicode 12.1.0 (Peter Eisentraut) § §
This fixes, for example, cases where psql would misformat output involving combining characters.
Original release occurrence ·
12.0/changes/095Update Snowball stemmer dictionaries with support for new languages Features
Update Snowball stemmer dictionaries with support for new languages (Arthur Zakirov) §
This adds word stemming support for Arabic, Indonesian, Irish, Lithuanian, Nepali, and Tamil to full text search.
Original release occurrence ·
12.0/changes/096Allow creation of collations that report string equality for strings that are not bit-wise equal Features
Allow creation of collations that report string equality for strings that are not bit-wise equal (Peter Eisentraut) §
This feature supports “nondeterministic” collations that can define case- and accent-agnostic equality comparisons. Thus, for example, a case-insensitive uniqueness constraint on a text column can be made more easily than before. This is only supported for ICU collations.
Original release occurrence ·
12.0/changes/097Add support for ICU collation attributes on older ICU versions Features
Add support for ICU collation attributes on older ICU versions (Peter Eisentraut) §
This allows customization of the collation rules in a consistent way across all ICU versions.
Original release occurrence ·
12.0/changes/098Allow data type name to more seamlessly be compared to other text types Features
Allow data type name to more seamlessly be compared to other text types (Tom Lane) §
Type
namenow behaves much like a domain over typetextthat has default collation “C”. This allows cross-type comparisons to be processed more efficiently.Original release occurrence ·
12.0/changes/099Add support for the SQL/JSON path language Features
Add support for the SQL/JSON path language (Nikita Glukhov, Teodor Sigaev, Alexander Korotkov, Oleg Bartunov, Liudmila Mantrova) § § §
This allows execution of complex queries on
JSONvalues using an SQL-standard language.Original release occurrence ·
12.0/changes/100Add support for hyperbolic functions Features
Add support for hyperbolic functions (Lætitia Avrot) §
Also add
log10()as an alias forlog(), for standards compliance.Original release occurrence ·
12.0/changes/101Improve the accuracy of statistical aggregates like variance() by using more precise algorithms Features
Improve the accuracy of statistical aggregates like
variance()by using more precise algorithms (Dean Rasheed) §Original release occurrence ·
12.0/changes/102Allow date_trunc() to have an additional argument to control the time zone Features
Allow
date_trunc()to have an additional argument to control the time zone (Vik Fearing, Tom Lane) §This is faster and simpler than using the
AT TIME ZONEclause.Original release occurrence ·
12.0/changes/103Adjust to_timestamp()/to_date() functions to be more forgiving of template mismatches Features
Adjust
to_timestamp()/to_date()functions to be more forgiving of template mismatches (Artur Zakirov, Alexander Korotkov, Liudmila Mantrova) §This new behavior more closely matches the Oracle functions of the same name.
Original release occurrence ·
12.0/changes/104Fix assorted bugs in XML functions Bug fixes
Fix assorted bugs in XML functions (Pavel Stehule, Markus Winand, Chapman Flack) §
Specifically, in
XMLTABLE,xpath(), andxmlexists(), fix some cases where nothing was output for a node, or an unexpected error was thrown, or necessary escaping of XML special characters was omitted.Original release occurrence ·
12.0/changes/105Allow the BY VALUE clause in XMLEXISTS and XMLTABLE Features
Allow the
BY VALUEclause inXMLEXISTSandXMLTABLE(Chapman Flack) §This SQL-standard clause has no effect in PostgreSQL's implementation, but it was unnecessarily being rejected.
Original release occurrence ·
12.0/changes/106Prevent current_schema() and current_schemas() from being run by parallel workers, as they are not parallel-safe Features
Prevent
current_schema()andcurrent_schemas()from being run by parallel workers, as they are not parallel-safe (Michaël Paquier) §Original release occurrence ·
12.0/changes/107Allow RECORD and RECORD[] to be used as column types in a query's column definition list for a table function that is declared to return RECORD Features
Allow
RECORDandRECORD[]to be used as column types in a query's column definition list for a table function that is declared to returnRECORD(Elvis Pranskevichus) §Original release occurrence ·
12.0/changes/108Allow SQL commands and variables with the same names as those commands to be used in the same PL/pgSQL function Features
Allow SQL commands and variables with the same names as those commands to be used in the same PL/pgSQL function (Tom Lane) §
For example, allow a variable called
commentto exist in a function that calls theCOMMENTSQL command. Previously this combination caused a parse error.Original release occurrence ·
12.0/changes/109Add new optional warning and error checks to PL/pgSQL Features
Add new optional warning and error checks to PL/pgSQL (Pavel Stehule) §
The new checks allow for run-time validation of
INTOcolumn counts and single-row results.Original release occurrence ·
12.0/changes/110Add connection parameter tcp_user_timeout to control libpq's TCP timeout Features
Add connection parameter tcp_user_timeout to control libpq's TCP timeout (Ryohei Nagaura) §
Original release occurrence ·
12.0/changes/111Allow libpq (and thus psql) to report only the SQLSTATE value in error messages Features
Allow libpq (and thus psql) to report only the
SQLSTATEvalue in error messages (Didier Gautheron) §Original release occurrence ·
12.0/changes/112Add libpq function PQresultMemorySize() to report the memory used by a query result Features
Add libpq function
PQresultMemorySize()to report the memory used by a query result (Lars Kanis, Tom Lane) §Original release occurrence ·
12.0/changes/113Remove the no-display/debug flag from libpq's options connection parameter Features
Remove the no-display/debug flag from libpq's
optionsconnection parameter (Peter Eisentraut) §This allows this parameter to be set by postgres_fdw.
Original release occurrence ·
12.0/changes/114Allow ecpg to create variables of data type bytea Features
Allow ecpg to create variables of data type
bytea(Ryo Matsumura) §This allows ECPG clients to interact with
byteadata directly, rather than using an encoded form.Original release occurrence ·
12.0/changes/115Add PREPARE AS support to ECPG Features
Add
PREPARE ASsupport to ECPG (Ryo Matsumura) §Original release occurrence ·
12.0/changes/116Allow vacuumdb to select tables for vacuum based on their wraparound horizon Features
Allow vacuumdb to select tables for vacuum based on their wraparound horizon (Nathan Bossart) §
The options are
--min-xid-ageand--min-mxid-age.Original release occurrence ·
12.0/changes/117Allow vacuumdb to disable waiting for locks or skipping all-visible pages Features
Allow vacuumdb to disable waiting for locks or skipping all-visible pages (Nathan Bossart) §
The options are
--skip-lockedand--disable-page-skipping.Original release occurrence ·
12.0/changes/118Add colorization to the output of command-line utilities Features
Add colorization to the output of command-line utilities (Peter Eisentraut) §
This is enabled by setting the environment variable
PG_COLORtoalwaysorauto. The specific colors used can be adjusted by setting the environment variablePG_COLORS, using ANSI escape codes for colors. For example, the default behavior is equivalent toPG_COLORS="error=01;31:warning=01;35:locus=01".Original release occurrence ·
12.0/changes/119Add CSV table output mode in psql Features
Add CSV table output mode in psql (Daniel Vérité) §
This is controlled by
\pset format csvor the command-line--csvoption.Original release occurrence ·
12.0/changes/120Show the manual page URL in psql's \help output for a SQL command Features
Show the manual page URL in psql's
\helpoutput for a SQL command (Peter Eisentraut) §Original release occurrence ·
12.0/changes/121Display the IP address in psql's \conninfo Features
Original release occurrence ·
12.0/changes/122Improve tab completion of CREATE TABLE, CREATE TRIGGER, CREATE EVENT TRIGGER, ANALYZE, EXPLAIN, VACUUM, ALTER TABLE, ALTER INDEX, ALTER DATABASE, and ALTER INDEX ALTER COLUMN Features
Improve tab completion of
CREATE TABLE,CREATE TRIGGER,CREATE EVENT TRIGGER,ANALYZE,EXPLAIN,VACUUM,ALTER TABLE,ALTER INDEX,ALTER DATABASE, andALTER INDEX ALTER COLUMN(Dagfinn Ilmari Mannsåker, Tatsuro Yamada, Michaël Paquier, Tom Lane, Justin Pryzby) § § § § § § § § §Original release occurrence ·
12.0/changes/123Allow values produced by queries to be assigned to pgbench variables Features
Allow values produced by queries to be assigned to pgbench variables (Fabien Coelho, Álvaro Herrera) § §
The command for this is
\gset.Original release occurrence ·
12.0/changes/124Improve precision of pgbench's --rate option Features
Improve precision of pgbench's
--rateoption (Tom Lane) §Original release occurrence ·
12.0/changes/125Improve pgbench's error reporting with clearer messages and return codes Features
Improve pgbench's error reporting with clearer messages and return codes (Peter Eisentraut) §
Original release occurrence ·
12.0/changes/126Allow control of log file rotation via pg_ctl Features
Allow control of log file rotation via pg_ctl (Kyotaro Horiguchi, Alexander Kuzmenkov, Alexander Korotkov) §
Previously, this was only possible via an SQL function or a process signal.
Original release occurrence ·
12.0/changes/127Properly detach the new server process during pg_ctl start Features
Properly detach the new server process during
pg_ctl start(Paul Guo) §This prevents the server from being shut down if the shell script that invoked pg_ctl is interrupted later.
Original release occurrence ·
12.0/changes/128Allow pg_upgrade to use the file system's cloning feature, if there is one Features
Allow pg_upgrade to use the file system's cloning feature, if there is one (Peter Eisentraut) §
The
--cloneoption has the advantages of--link, while preventing the old cluster from being changed after the new cluster has started.Original release occurrence ·
12.0/changes/129Allow specification of the socket directory to use in pg_upgrade Features
Allow specification of the socket directory to use in pg_upgrade (Daniel Gustafsson) §
This is controlled by
--socketdir; the default is the current directory.Original release occurrence ·
12.0/changes/130Allow pg_checksums to disable fsync operations Features
Allow pg_checksums to disable fsync operations (Michaël Paquier) §
This is controlled by the
--no-syncoption.Original release occurrence ·
12.0/changes/131Allow pg_rewind to disable fsync operations Features
Original release occurrence ·
12.0/changes/132Fix pg_test_fsync to report accurate open_datasync durations on Windows Bug fixes
Fix pg_test_fsync to report accurate
open_datasyncdurations on Windows (Laurenz Albe) § §Original release occurrence ·
12.0/changes/133When pg_dump emits data with INSERT commands rather than COPY, allow more than one data row to be included in each INSERT Features
When pg_dump emits data with
INSERTcommands rather thanCOPY, allow more than one data row to be included in eachINSERT(Surafel Temesgen, David Rowley) § §The option controlling this is
--rows-per-insert.Original release occurrence ·
12.0/changes/134Allow pg_dump to emit INSERT ... ON CONFLICT DO NOTHING Features
Allow pg_dump to emit
INSERT ... ON CONFLICT DO NOTHING(Surafel Temesgen) §This avoids conflict failures during restore. The option is
--on-conflict-do-nothing.Original release occurrence ·
12.0/changes/135Decouple the order of operations in a parallel pg_dump from the order used by a subsequent parallel pg_restore Features
Decouple the order of operations in a parallel pg_dump from the order used by a subsequent parallel pg_restore (Tom Lane) §
This allows pg_restore to perform more-fully-parallelized parallel restores, especially in cases where the original dump was not done in parallel. Scheduling of a parallel pg_dump is also somewhat improved.
Original release occurrence ·
12.0/changes/136Allow the extra_float_digits setting to be specified for pg_dump and pg_dumpall Features
Allow the extra_float_digits setting to be specified for pg_dump and pg_dumpall (Andrew Dunstan) §
This is primarily useful for making dumps that are exactly comparable across different source server versions. It is not recommended for normal use, as it may result in loss of precision when the dump is restored.
Original release occurrence ·
12.0/changes/137Add --exclude-database option to pg_dumpall Features
Add
--exclude-databaseoption to pg_dumpall (Andrew Dunstan) §Original release occurrence ·
12.0/changes/138Add CREATE ACCESS METHOD command to create new table types Features
Add CREATE ACCESS METHOD command to create new table types (Andres Freund, Haribabu Kommi, Álvaro Herrera, Alexander Korotkov, Dmitry Dolgov) § § § § § § § § §
This enables the development of new table access methods, which can optimize storage for different use cases. The existing
heapaccess method remains the default.Original release occurrence ·
12.0/changes/139Add planner support function interfaces to improve optimizer estimates, inlining, and indexing for functions Features
Add planner support function interfaces to improve optimizer estimates, inlining, and indexing for functions (Tom Lane) § § §
This allows extensions to create planner support functions that can provide function-specific selectivity, cost, and row-count estimates that can depend on the function's arguments. Support functions can also supply simplified representations and index conditions, greatly expanding optimization possibilities.
Original release occurrence ·
12.0/changes/140Simplify renumbering manually-assigned OIDs, and establish a new project policy for management of such OIDs Features
Simplify renumbering manually-assigned OIDs, and establish a new project policy for management of such OIDs (John Naylor, Tom Lane) § §
Patches that manually assign OIDs for new built-in objects (such as new functions) should now randomly choose OIDs in the range 8000—9999. At the end of a development cycle, the OIDs used by committed patches will be renumbered down to lower numbers, currently somewhere in the 4
xxxrange, using the newrenumber_oids.plscript. This approach should greatly reduce the odds of OID collisions between different in-process patches.While there is no specific policy reserving any OIDs for external use, it is recommended that forks and other projects needing private manually-assigned OIDs use numbers in the high 7
xxxrange. This will avoid conflicts with recently-merged patches, and it should be a long time before the core project reaches that range.Original release occurrence ·
12.0/changes/141Build Cygwin binaries using dynamic instead of static libraries Features
Build Cygwin binaries using dynamic instead of static libraries (Marco Atzeri) §
Original release occurrence ·
12.0/changes/142Remove configure switch --disable-strong-random Features
Remove configure switch
--disable-strong-random(Michaël Paquier) §A strong random-number source is now required.
Original release occurrence ·
12.0/changes/143printf-family functions, as well as strerror and strerror_r, now behave uniformly across platforms within Postgres code Features
printf-family functions, as well asstrerrorandstrerror_r, now behave uniformly across platforms within Postgres code (Tom Lane) § § § §Notably,
printfunderstands%meverywhere; on Windows,strerrorcopes with Winsock error codes (it used to do so in backend but not frontend code); andstrerror_ralways follows the GNU return convention.Original release occurrence ·
12.0/changes/144Require a C99-compliant compiler, and MSVC 2013 or later on Windows Features
Require a C99-compliant compiler, and MSVC 2013 or later on Windows (Andres Freund) §
Original release occurrence ·
12.0/changes/145Use pandoc, not lynx, for generating plain-text documentation output files Features
Use pandoc, not lynx, for generating plain-text documentation output files (Peter Eisentraut) § §
This affects only the
INSTALLfile generated duringmake distand the seldom-used plain-textpostgres.txtoutput file. Pandoc produces better output than lynx and avoids some locale/encoding issues. Pandoc version 1.13 or later is required.Original release occurrence ·
12.0/changes/146Support use of images in the PostgreSQL documentation Features
Support use of images in the PostgreSQL documentation (Jürgen Purtz) §
Original release occurrence ·
12.0/changes/147Allow ORDER BY sorts and LIMIT clauses to be pushed to postgres_fdw foreign servers in more cases Features
Allow
ORDER BYsorts andLIMITclauses to be pushed to postgres_fdw foreign servers in more cases (Etsuro Fujita) § §Original release occurrence ·
12.0/changes/148Improve optimizer cost accounting for postgres_fdw queries Features
Original release occurrence ·
12.0/changes/149Properly honor WITH CHECK OPTION on views that reference postgres_fdw tables Features
Properly honor
WITH CHECK OPTIONon views that reference postgres_fdw tables (Etsuro Fujita) §While
CHECK OPTIONs on postgres_fdw tables are ignored (because the reference is foreign), views on such tables are considered local, so this change enforcesCHECK OPTIONs on them. Previously, onlyINSERTs andUPDATEs withRETURNINGclauses that returnedCHECK OPTIONvalues were validated.Original release occurrence ·
12.0/changes/150Allow pg_stat_statements_reset() to be more granular Features
Allow
pg_stat_statements_reset()to be more granular (Haribabu Kommi, Amit Kapila) §The function now allows reset of statistics for specific databases, users, and queries.
Original release occurrence ·
12.0/changes/151Allow control of the auto_explain log level Features
Allow control of the auto_explain log level (Tom Dunstan, Andrew Dunstan) §
The default is
LOG.Original release occurrence ·
12.0/changes/152Update unaccent rules with new punctuation and symbols Features
Original release occurrence ·
12.0/changes/153Allow unaccent to handle some accents encoded as combining characters Features
Allow unaccent to handle some accents encoded as combining characters (Hugh Ranalli) §
Original release occurrence ·
12.0/changes/154Allow unaccent to remove accents from Greek characters Features
Allow unaccent to remove accents from Greek characters (Tasos Maschalidis) §
Original release occurrence ·
12.0/changes/155Add a parameter to amcheck's bt_index_parent_check() function to check each index tuple from the root of the tree Features
Add a parameter to amcheck's
bt_index_parent_check()function to check each index tuple from the root of the tree (Peter Geoghegan) §Original release occurrence ·
12.0/changes/156Improve oid2name and vacuumlo option handling to match other commands Features
Original release occurrence ·
12.0/changes/157
Security evidence
34 records from the official security matrix and release-note mentions. A fixed version is shown only when the security snapshot explicitly names this branch. A mention alone does not establish applicability or a new fix.
CVE-2024-7348 · PostgreSQL relation replacement during pg_dump executes arbitrary SQL CVSS 8.8
Time-of-check Time-of-use (TOCTOU) race condition in pg_dump in PostgreSQL allows an object creator to execute arbitrary SQL functions as the user running pg_dump, which is often a superuser. The attack involves replacing another relation type with a view or foreign table. The attack requires waiting for pg_dump to start, but winning the race condition is trivial if the attacker retains an open transaction. Versions before PostgreSQL 16.4, 15.8, 14.13, 13.16, and 12.20 are affected. The PostgreSQL project thanks Noah Misch for reporting this problem.
Fixed in this branch: 12.20. Component: core server.
Official affected-branch entry: 12.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2024-10979 · PostgreSQL PL/Perl environment variable changes execute arbitrary code CVSS 8.8
Incorrect control of environment variables in PostgreSQL PL/Perl allows an unprivileged database user to change sensitive process environment variables (e.g. PATH ). That often suffices to enable arbitrary code execution, even if the attacker lacks a database server operating system user. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected. The PostgreSQL project thanks Coby Abrams for reporting this problem.
Fixed in this branch: 12.21. Component: core server.
Official affected-branch entry: 12.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2024-10978 · PostgreSQL SET ROLE, SET SESSION AUTHORIZATION reset to wrong user ID CVSS 4.2
Incorrect privilege assignment in PostgreSQL allows a less-privileged application user to view or change different rows from those intended. An attack requires the application to use SET ROLE , SET SESSION AUTHORIZATION , or an equivalent feature. The problem arises when an application query uses parameters from the attacker or conveys query results to the attacker. If that query reacts to current_setting('role') or the current user ID, it may modify or return data as though the session had not used SET ROLE or SET SESSION AUTHORIZATION . The attacker does not control which incorrect user ID applies. Query text from less-privileged sources is not a concern here, because SET ROLE and SET SESSION AUTHORIZATION are not sandboxes for unvetted queries. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected. The PostgreSQL project thanks Tom Lane for reporting this problem.
Fixed in this branch: 12.21. Component: core server.
Official affected-branch entry: 12.
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Release-note mentions:
CVE-2024-10977 · PostgreSQL libpq retains an error message from man-in-the-middle CVSS 3.1
Client use of server error message in PostgreSQL allows a server not trusted under current SSL or GSS settings to furnish arbitrary non-NUL bytes to the libpq application. For example, a man-in-the-middle attacker could send a long error message that a human or screen-scraper user of psql mistakes for valid query results. This is probably not a concern for clients where the user interface unambiguously indicates the boundary between one error message and other text. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected. The PostgreSQL project thanks Jacob Champion for reporting this problem.
Fixed in this branch: 12.21. Component: client.
Official affected-branch entry: 12.
AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
Release-note mentions:
CVE-2024-10976 · PostgreSQL row security below e.g. subqueries disregards user ID changes CVSS 4.2
Incomplete tracking in PostgreSQL of tables with row security allows a reused query to view or change different rows from those intended. CVE-2023-2455 and CVE-2016-2193 fixed most interaction between row security and user ID changes. They missed cases where a subquery, WITH query, security invoker view, or SQL-language function references a table with a row-level security policy. This has the same consequences as the two earlier CVEs. That is to say, it leads to potentially incorrect policies being applied in cases where role-specific policies are used and a given query is planned under one role and then executed under other roles. This scenario can happen under security definer functions or when a common user and query is planned initially and then re-used across multiple SET ROLEs. Applying an incorrect policy may permit a user to complete otherwise-forbidden reads and modifications. This affects only databases that have used CREATE POLICY to define a row security policy. An attacker must tailor an attack to a particular application's pattern of query plan reuse, user ID changes, and role-specific row security policies. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected.
Fixed in this branch: 12.21. Component: core server.
Official affected-branch entry: 12.
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Release-note mentions:
CVE-2024-0985 · PostgreSQL non-owner REFRESH MATERIALIZED VIEW CONCURRENTLY executes arbitrary SQL CVSS 8.0
UPDATE (June 19, 2024) : Added v16 as impacted. Updated description to clarify the attack vector. Late privilege drop in REFRESH MATERIALIZED VIEW CONCURRENTLY in PostgreSQL allows an object creator to execute arbitrary SQL functions as the command issuer. The command intends to run SQL functions as the owner of the materialized view, enabling safe refresh of untrusted materialized views. The victim is a superuser or member of one of the attacker's roles. The attack requires luring the victim into running REFRESH MATERIALIZED VIEW CONCURRENTLY on the attacker's materialized view.
Fixed in this branch: 12.18. Component: core server.
Official affected-branch entry: 12.
AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2023-5870 · Role "pg_signal_backend" can signal certain superuser processes CVSS 2.2
Documentation says the pg_signal_backend role cannot signal "a backend owned by a superuser". On the contrary, it can signal background workers, including the logical replication launcher. It can signal autovacuum workers and the autovacuum launcher. Signaling autovacuum workers and those two launchers provides no meaningful exploit, so exploiting this vulnerability requires a non-core extension with a less-resilient background worker. For example, a non-core background worker that does not auto-restart would experience a denial of service with respect to that particular background worker. The PostgreSQL project thanks Hemanth Sandrana and Mahendrakar Srinivasarao for reporting this problem.
Fixed in this branch: 12.17. Component: core server.
Official affected-branch entry: 12.
AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L
Release-note mentions:
CVE-2023-5869 · Buffer overrun from integer overflow in array modification CVSS 8.8
While modifying certain SQL array values, missing overflow checks let authenticated database users write arbitrary bytes to a memory area that facilitates arbitrary code execution. Missing overflow checks also let authenticated database users read a wide area of server memory. The CVE-2021-32027 fix covered some attacks of this description, but it missed others. The PostgreSQL project thanks Pedro Gallegos for reporting this problem.
Fixed in this branch: 12.17. Component: core server.
Official affected-branch entry: 12.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2023-5868 · Memory disclosure in aggregate function calls CVSS 4.3
Certain aggregate function calls receiving "unknown"-type arguments could disclose bytes of server memory from the end of the "unknown"-type value to the next zero byte. One typically gets an "unknown"-type value via a string literal having no type designation. We have not confirmed or ruled out viability of attacks that arrange for presence of notable, confidential information in disclosed bytes. The PostgreSQL project thanks Jingzhou Fu for reporting this problem.
Fixed in this branch: 12.17. Component: core server.
Official affected-branch entry: 12.
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2023-39417 · Extension script @substitutions@ within quoting allow SQL injection CVSS 7.5
An extension script is vulnerable if it uses @extowner@ , @extschema@ , or @extschema:...@ inside a quoting construct (dollar quoting, '' , or "" ). No bundled extension is vulnerable. Vulnerable uses do appear in a documentation example and in non-bundled extensions. Hence, the attack prerequisite is an administrator having installed files of a vulnerable, trusted, non-bundled extension. Subject to that prerequisite, this enables an attacker having database-level CREATE privilege to execute arbitrary code as the bootstrap superuser. PostgreSQL will block this attack in the core server, so there's no need to modify individual extensions. The PostgreSQL project thanks Micah Gates, Valerie Woolard, Tim Carey-Smith, and Christoph Berg for reporting this problem.
Fixed in this branch: 12.16. Component: core server.
Official affected-branch entry: 12.
AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2023-2455 · Row security policies disregard user ID changes after inlining CVSS 4.2
While CVE-2016-2193 fixed most interaction between row security and user ID changes, it missed a scenario involving function inlining. This leads to potentially incorrect policies being applied in cases where role-specific policies are used and a given query is planned under one role and then executed under other roles. This scenario can happen under security definer functions or when a common user and query is planned initially and then re-used across multiple SET ROLE s. Applying an incorrect policy may permit a user to complete otherwise-forbidden reads and modifications. This affects only databases that have used CREATE POLICY to define a row security policy. The PostgreSQL project thanks Wolfgang Walther for reporting this problem.
Fixed in this branch: 12.15. Component: core server.
Official affected-branch entry: 12.
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Release-note mentions:
CVE-2023-2454 · CREATE SCHEMA ... schema_element defeats protective search_path changes CVSS 7.2
This enabled an attacker having database-level CREATE privilege to execute arbitrary code as the bootstrap superuser. Database owners have that right by default, and explicit grants may extend it to other users. The PostgreSQL project thanks Alexander Lakhin for reporting this problem.
Fixed in this branch: 12.15. Component: core server.
Official affected-branch entry: 12.
AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2022-41862 · Client memory disclosure when connecting, with Kerberos, to modified server CVSS 3.7
A modified, unauthenticated server can send an unterminated string during the establishment of Kerberos transport encryption. When a libpq client application has a Kerberos credential cache and doesn't explicitly disable option gssencmode , a server can cause libpq to over-read and report an error message containing uninitialized bytes from and following its receive buffer. If libpq's caller somehow makes that message accessible to the attacker, this achieves a disclosure of the over-read bytes. We have not confirmed or ruled out viability of attacks that arrange for a crash or for presence of notable, confidential information in disclosed bytes. The PostgreSQL project thanks Jacob Champion for reporting this problem.
Fixed in this branch: 12.14. Component: client.
Official affected-branch entry: 12.
AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2022-2625 · Extension scripts replace objects not belonging to the extension CVSS 7.1
Some extensions use CREATE OR REPLACE or CREATE IF NOT EXISTS commands. Some don't adhere to the documented rule to target only objects known to be extension members already. An attack requires permission to create non-temporary objects in at least one schema, ability to lure or wait for an administrator to create or update an affected extension in that schema, and ability to lure or wait for a victim to use the object targeted in CREATE OR REPLACE or CREATE IF NOT EXISTS . Given all three prerequisites, the attacker can run arbitrary code as the victim role, which may be a superuser. Known-affected extensions include both PostgreSQL-bundled and non-bundled extensions. PostgreSQL is blocking this attack in the core server, so there's no need to modify individual extensions. The PostgreSQL project thanks Sven Klemm for reporting this problem.
Fixed in this branch: 12.12. Component: core server.
Official affected-branch entry: 12.
AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2022-1552 · Autovacuum, REINDEX, and others omit "security restricted operation" sandbox CVSS 8.8
Autovacuum, REINDEX , CREATE INDEX , REFRESH MATERIALIZED VIEW , CLUSTER , and pg_amcheck made incomplete efforts to operate safely when a privileged user is maintaining another user's objects. Those commands activated relevant protections too late or not at all. An attacker having permission to create non-temp objects in at least one schema could execute arbitrary SQL functions under a superuser identity. While promptly updating PostgreSQL is the best remediation for most users, a user unable to do that can work around the vulnerability by disabling autovacuum, not manually running the above commands, and not restoring from output of the pg_dump command. Performance may degrade quickly under this workaround. VACUUM is safe, and all commands are fine when a trusted user owns the target object. The PostgreSQL project thanks Alexander Lakhin for reporting this problem.
Fixed in this branch: 12.11. Component: core server.
Official affected-branch entry: 12.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2021-3677 · Memory disclosure in certain queries CVSS 6.5
A purpose-crafted query can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can complete this attack at will. The attack does not require the ability to create objects. If server settings include max_worker_processes=0 , the known versions of this attack are infeasible. However, undiscovered variants of the attack may be independent of that setting.
Fixed in this branch: 12.8. Component: core server.
Official affected-branch entry: 12.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Release-note mentions:
CVE-2021-3449 · CVE-2021-3449
No fixed version for this branch is recorded.
Release-note mentions:
CVE-2021-3393 · Partition constraint violation errors leak values of denied columns CVSS 3.1
A user having an UPDATE privilege on a partitioned table but lacking the SELECT privilege on some column may be able to acquire denied-column values from an error message. This is similar to CVE-2014-8161 , but the conditions to exploit are more rare. The PostgreSQL project thanks Heikki Linnakangas for reporting this problem.
Fixed in this branch: 12.6. Component: core server.
Official affected-branch entry: 12.
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2021-32029 · Memory disclosure in partitioned-table UPDATE ... RETURNING CVSS 6.5
Using an UPDATE ... RETURNING on a purpose-crafted partitioned table, an attacker can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can create prerequisite objects and complete this attack at will. A user lacking the CREATE and TEMPORARY privileges on all databases and the CREATE privilege on all schemas typically cannot use this attack at will. The PostgreSQL project thanks Tom Lane for reporting this problem.
Fixed in this branch: 12.7. Component: core server.
Official affected-branch entry: 12.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Release-note mentions:
CVE-2021-32028 · Memory disclosure in INSERT ... ON CONFLICT ... DO UPDATE CVSS 6.5
Using an INSERT ... ON CONFLICT ... DO UPDATE command on a purpose-crafted table, an attacker can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can create prerequisite objects and complete this attack at will. A user lacking the CREATE and TEMPORARY privileges on all databases and the CREATE privilege on all schemas cannot use this attack at will. The PostgreSQL project thanks Andres Freund for reporting this problem.
Fixed in this branch: 12.7. Component: core server.
Official affected-branch entry: 12.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Release-note mentions:
CVE-2021-32027 · Buffer overrun from integer overflow in array subscripting calculations CVSS 6.5
While modifying certain SQL array values, missing bounds checks let authenticated database users write arbitrary bytes to a wide area of server memory. The PostgreSQL project thanks Tom Lane for reporting this problem.
Fixed in this branch: 12.7. Component: core server.
Official affected-branch entry: 12.
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Release-note mentions:
CVE-2021-23222 · libpq processes unencrypted bytes from man-in-the-middle CVSS 3.7
A man-in-the-middle attacker can inject false responses to the client's first few queries, despite the use of SSL certificate verification and encryption. If more preconditions hold, the attacker can exfiltrate the client's password or other confidential data that might be transmitted early in a session. The attacker must have a way to trick the client's intended server into making the confidential data accessible to the attacker. A known implementation having that property is a PostgreSQL configuration vulnerable to CVE-2021-23214 . As with any exploitation of CVE-2021-23214 , the server must be using trust authentication with a clientcert requirement or using cert authentication. To disclose a password, the client must be in possession of a password, which is atypical when using an authentication configuration vulnerable to CVE-2021-23214 . The attacker must have some other way to access the server to retrieve the exfiltrated data (a valid, unprivileged login account would be sufficient). The PostgreSQL project thanks Jacob Champion for reporting this problem.
Fixed in this branch: 12.9. Component: client.
Official affected-branch entry: 12.
AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2021-23214 · Server processes unencrypted bytes from man-in-the-middle CVSS 8.1
When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption. This is similar to CVE-2011-0411 (different product). The PostgreSQL project thanks Jacob Champion for reporting this problem.
Fixed in this branch: 12.9. Component: core server.
Official affected-branch entry: 12.
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2020-25696 · psql's \gset allows overwriting specially treated variables CVSS 7.5
The \gset meta-command, which sets psql variables based on query results, does not distinguish variables that control psql behavior. If an interactive psql session uses \gset when querying a compromised server, the attacker can execute arbitrary code as the operating system account running psql . Using \gset with a prefix not found among specially treated variables, e.g. any lowercase string, precludes the attack in an unpatched psql . The PostgreSQL project thanks Nick Cleaton for reporting this problem.
Fixed in this branch: 12.5. Component: client.
Official affected-branch entry: 12.
AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2020-25695 · Multiple features escape "security restricted operation" sandbox CVSS 8.8
An attacker having permission to create non-temporary objects in at least one schema can execute arbitrary SQL functions under the identity of a superuser. While promptly updating PostgreSQL is the best remediation for most users, a user unable to do that can work around the vulnerability by disabling autovacuum and not manually running ANALYZE , CLUSTER , REINDEX , CREATE INDEX , VACUUM FULL , REFRESH MATERIALIZED VIEW , or a restore from output of the pg_dump command. Performance may degrade quickly under this workaround. VACUUM without the FULL option is safe, and all commands are fine when a trusted user owns the target object. The PostgreSQL project thanks Etienne Stalmans for reporting this problem.
Fixed in this branch: 12.5. Component: core server.
Official affected-branch entry: 12.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2020-25694 · Reconnection can downgrade connection security settings CVSS 8.1
Many PostgreSQL-provided client applications have options that create additional database connections. Some of those applications reuse only the basic connection parameters (e.g. host , user , port ), dropping others. If this drops a security-relevant parameter (e.g. channel_binding , sslmode , requirepeer , gssencmode ), the attacker has an opportunity to complete a MITM attack or observe cleartext transmission. Affected applications are clusterdb , pg_dump , pg_restore , psql , reindexdb , and vacuumdb . The vulnerability arises only if one invokes an affected client application with a connection string containing a security-relevant parameter. This also fixes how the \connect command of psql reuses connection parameters, i.e. all non-overridden parameters from a previous connection string now re-used. The PostgreSQL project thanks Peter Eisentraut for reporting this problem.
Fixed in this branch: 12.5. Component: client.
Official affected-branch entry: 12.
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2020-1720 · ALTER ... DEPENDS ON EXTENSION is missing authorization checks. CVSS 3.1
The ALTER ... DEPENDS ON EXTENSION sub-commands do not perform authorization checks, which can allow an unprivileged user to drop any function, procedure, materialized view, index, or trigger under certain conditions. This attack is possible if an administrator has installed an extension and an unprivileged user can CREATE , or an extension owner either executes DROP EXTENSION predictably or can be convinced to execute DROP EXTENSION . The PostgreSQL project thanks Tom Lane for reporting this problem.
Fixed in this branch: 12.2. Component: core server.
Official affected-branch entry: 12.
AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Release-note mentions:
CVE-2020-14350 · Uncontrolled search path element in CREATE EXTENSION CVSS 7.1
When a superuser runs certain CREATE EXTENSION statements, users may be able to execute arbitrary SQL functions under the identity of that superuser. The attacker must have permission to create objects in the new extension's schema or a schema of a prerequisite extension. Not all extensions are vulnerable. In addition to correcting the extensions provided with PostgreSQL, the PostgreSQL Global Development Group is issuing guidance for third-party extension authors to secure their own work. The PostgreSQL project thanks Andres Freund for reporting this problem.
Fixed in this branch: 12.4. Component: core server.
Official affected-branch entry: 12.
AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2020-14349 · Uncontrolled search path element in logical replication CVSS 7.5
The PostgreSQL search_path setting determines schemas searched for tables, functions, operators, etc. The CVE-2018-1058 fix caused most PostgreSQL-provided client applications to sanitize search_path , but logical replication continued to leave search_path unchanged. Users of a replication publisher or subscriber database can create objects in the public schema and harness them to execute arbitrary SQL functions under the identity running replication, often a superuser. Installations having adopted a documented secure schema usage pattern are not vulnerable. The PostgreSQL project thanks Noah Misch for reporting this problem.
Fixed in this branch: 12.4. Component: core server.
Official affected-branch entry: 12.
AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2020-10733 · Windows installer runs executables from uncontrolled directories CVSS 6.7
The Windows installer for PostgreSQL invokes system-provided executables that do not have fully-qualified paths. Executables in the directory where the installer loads or the current working directory take precedence over the intended executables. An attacker having permission to add files into one of those directories can use this to execute arbitrary code with the installer's administrative rights. The PostgreSQL project thanks Hou JingYi (@hjy79425575) for reporting this problem.
Fixed in this branch: 12.3. Component: packaging.
Official affected-branch entry: 12.
AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
CVE-2019-3466 · pg_ctlcluster script in postgresql-common does not drop privileges when creating socket/statistics temporary directories CVSS 8.4
A PostgreSQL superuser could escalate to root using a deficiency in the pg_ctlcluster command. pg_ctlcluster is a utility provided by the "postgresql-common" package that is installed with PostgreSQL on Debian and Ubuntu platforms.
Fixed in this branch: 12.1. Component: packaging.
Official affected-branch entry: 12.
AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
CVE-2018-1058 · Uncontrolled search path element in pg_dump and other client applications CVSS 8.8
No fixed version for this branch is recorded. Component: client.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2017-7484 · selectivity estimators bypass SELECT privilege checks CVSS 4.3
No fixed version for this branch is recorded. Component: core server.
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2006-2313 · An attacker able to submit crafted strings to an application that will embed those strings in SQL commands can use invalidly-encoded multibyte characters to bypass standard string-escaping methods, resulting in possible SQL injection.
No fixed version for this branch is recorded.
Release-note mentions:
Export this branch as JSON · Compare any two indexed releases