↑↓ select ↵ open ⌫ change scope Open full search

PG.CENTER connects PostgreSQL documentation, reference, and ecosystem knowledge. Maintained by Pigsty.

Wiki / Versions

PostgreSQL 12

Read the English manual

End of life · Recorded build 12.22 · 2024-11-21

This major branch is no longer supported. These records describe its history; the absence of newer security records does not establish that it is safe to run.

First stable release
2019-10-03
Support end
2024-11-21
Indexed releases
23
Original release-note entries
1181

Manuals & provenance

PostgreSQL 12 English manual · 1133 loaded pages.

Manual loaded 2026-09-27T00:10:47.078613.

Release entries: 2026-09-26. Security evidence: 2026-09-26. PDF links use the verified English manifest and locally available files. Lifecycle: PostgreSQL versioning policy.

Upgrade considerations

Major upgrades need a migration method such as dump/reload or pg_upgrade. Read the intervening major-release notes and the target manual. Minor updates can also require extra steps; review the specific release's migration notes. Official upgrade policy.

Compatibility notes for 12.0 · Changes from the initial release through 12.22

Original migration guidance for 12.0

A dump/restore using pg_dumpall or use of pg_upgrade or logical replication is required for those wishing to migrate data from any previous release. See Section 18.6 for general information on migrating to new major releases.

Version 12 contains a number of changes that may affect compatibility with previous releases. Observe the following incompatibilities:

Release history

Every indexed release keeps its original occurrences. CVE counts below are mentions in its notes, including follow-up corrections; they do not count newly fixed vulnerabilities.

ReleaseDate / snapshot cutoffAll changesBug fixesMigration entriesCVE mentions
12.22 2024-11-21 1001
12.21 2024-11-14 341104
12.20 2024-08-08 341602
12.19 2024-05-09 351500
12.18 2024-02-08 391401
12.17 2023-11-09 431503
12.16 2023-08-10 321401
12.15 2023-05-11 502602
12.14 2023-02-09 361501
12.13 2022-11-10 381900
12.12 2022-08-11 391502
12.11 2022-05-12 361801
12.10 2022-02-10 331600
12.9 2021-11-11 633002
12.8 2021-08-12 682303
12.7 2021-05-13 412303
12.6 2021-02-11 673301
12.5 2020-11-12 582403
12.4 2020-08-13 522703
12.3 2020-05-14 763100
12.2 2020-02-13 754402
12.1 2019-11-14 512400
12.0 2019-10-03 1804230

Initial release changes

Original entries from 12.0, including feature changes and compatibility notes. Categories aid browsing; they are not upstream classifications.

180 of 180 original entries.

  • Remove the special behavior of oid columns Compatibility Migration

    Remove the special behavior of oid columns (Andres Freund, John Naylor) §

    Previously, a normally-invisible oid column could be specified during table creation using WITH OIDS; that ability has been removed. Columns can still be explicitly declared as type oid. Operations on tables that have columns created using WITH OIDS will need adjustment.

    The system catalogs that previously had hidden oid columns now have ordinary oid columns. Hence, SELECT * will now output those columns, whereas previously they would be displayed only if selected explicitly.

    Original release occurrence · 12.0/migration/001

  • Remove data types abstime, reltime, and tinterval Compatibility Migration

    Remove data types abstime, reltime, and tinterval (Andres Freund) §

    These are obsoleted by SQL-standard types such as timestamp.

    Original release occurrence · 12.0/migration/002

  • Remove the timetravel extension Compatibility Migration

    Remove the timetravel extension (Andres Freund) §

    Original release occurrence · 12.0/migration/003

  • Move recovery.conf settings into postgresql.conf Compatibility Migration

    Move recovery.conf settings into postgresql.conf (Masao Fujii, Simon Riggs, Abhijit Menon-Sen, Sergei Kornilov) §

    recovery.conf is no longer used, and the server will not start if that file exists. recovery.signal and standby.signal files are now used to switch into non-primary mode. The trigger_file setting has been renamed to promote_trigger_file. The standby_mode setting has been removed.

    Original release occurrence · 12.0/migration/004

  • Do not allow multiple conflicting recovery_target* specifications Compatibility Migration

    Do not allow multiple conflicting recovery_target* specifications (Peter Eisentraut) §

    Specifically, only allow one of recovery_target, recovery_target_lsn, recovery_target_name, recovery_target_time, and recovery_target_xid. Previously, multiple different instances of these parameters could be specified, and the last one was honored. Now, only one can be specified, though the same one can be specified multiple times and the last specification is honored.

    Original release occurrence · 12.0/migration/005

  • Cause recovery to advance to the latest timeline by default Compatibility Migration

    Cause recovery to advance to the latest timeline by default (Peter Eisentraut) §

    Specifically, recovery_target_timeline now defaults to latest. Previously, it defaulted to current.

    Original release occurrence · 12.0/migration/006

  • Refactor code for geometric functions and operators Compatibility Migration

    Refactor code for geometric functions and operators (Emre Hasegeli) § § §

    This could lead to more accurate, but slightly different, results compared to previous releases. Notably, cases involving NaN, underflow, overflow, and division by zero are handled more consistently than before.

    Original release occurrence · 12.0/migration/007

  • Improve performance by using a new algorithm for output of real and double precision values Compatibility Migration

    Improve performance by using a new algorithm for output of real and double precision values (Andrew Gierth) § §

    Previously, displayed floating-point values were rounded to 6 (for real) or 15 (for double precision) digits by default, adjusted by the value of extra_float_digits. Now, whenever extra_float_digits is more than zero (as it now is by default), only the minimum number of digits required to preserve the exact binary value are output. The behavior is the same as before when extra_float_digits is set to zero or less.

    Also, formatting of floating-point exponents is now uniform across platforms: two digits are used unless three are necessary. In previous releases, Windows builds always printed three digits.

    Original release occurrence · 12.0/migration/008

  • random() and setseed() now behave uniformly across platforms Compatibility Migration

    random() and setseed() now behave uniformly across platforms (Tom Lane) § §

    The sequence of random() values generated following a setseed() call with a particular seed value is likely to be different now than before. However, it will also be repeatable, which was not previously guaranteed because of interference from other uses of random numbers inside the server. The SQL random() function now has its own private per-session state to forestall that.

    Original release occurrence · 12.0/migration/009

  • Change SQL-style substring() to have standard-compliant greediness behavior Compatibility Migration

    Change SQL-style substring() to have standard-compliant greediness behavior (Tom Lane) §

    In cases where the pattern can be matched in more than one way, the initial sub-pattern is now treated as matching the least possible amount of text rather than the greatest; for example, a pattern such as %#"aa*#"% now selects the first group of a's from the input, not the last group.

    Original release occurrence · 12.0/migration/010

  • Do not pretty-print the result of xpath() or the XMLTABLE construct Compatibility Migration

    Do not pretty-print the result of xpath() or the XMLTABLE construct (Tom Lane) §

    In some cases, these functions would insert extra whitespace (newlines and/or spaces) in nodeset values. This is undesirable since depending on usage, the whitespace might be considered semantically significant.

    Original release occurrence · 12.0/migration/011

  • Rename command-line tool pg_verify_checksums to pg_checksums Compatibility Migration

    Rename command-line tool pg_verify_checksums to pg_checksums (Michaël Paquier) §

    Original release occurrence · 12.0/migration/012

  • In pg_restore, require specification of -f - to send the dump contents to standard output Compatibility Migration

    In pg_restore, require specification of -f - to send the dump contents to standard output (Euler Taveira) §

    Previously, this happened by default if no destination was specified, but that was deemed to be unfriendly.

    Original release occurrence · 12.0/migration/013

  • Disallow non-unique abbreviations in psql's \pset format command Compatibility Migration

    Disallow non-unique abbreviations in psql's \pset format command (Daniel Vérité) § §

    Previously, for example, \pset format a chose aligned; it will now fail since that could equally well mean asciidoc.

    Original release occurrence · 12.0/migration/014

  • In new btree indexes, the maximum index entry length is reduced by eight bytes, to improve handling of duplicate entries Compatibility Migration

    In new btree indexes, the maximum index entry length is reduced by eight bytes, to improve handling of duplicate entries (Peter Geoghegan) §

    This means that a REINDEX operation on an index pg_upgrade'd from a previous release could potentially fail.

    Original release occurrence · 12.0/migration/015

  • Cause DROP IF EXISTS FUNCTION/PROCEDURE/AGGREGATE/ROUTINE to generate an error if no argument list is supplied and there are multiple matching objects Compatibility Migration

    Cause DROP IF EXISTS FUNCTION/PROCEDURE/AGGREGATE/ROUTINE to generate an error if no argument list is supplied and there are multiple matching objects (David Rowley) §

    Also improve the error message in such cases.

    Original release occurrence · 12.0/migration/016

  • Split the pg_statistic_ext catalog into two catalogs, and add the pg_stats_ext view of it Compatibility Migration

    Split the pg_statistic_ext catalog into two catalogs, and add the pg_stats_ext view of it (Dean Rasheed, Tomas Vondra) § §

    This change supports hiding potentially-sensitive statistics data from unprivileged users.

    Original release occurrence · 12.0/migration/017

  • Remove obsolete pg_constraint.consrc column Compatibility Migration

    Remove obsolete pg_constraint.consrc column (Peter Eisentraut) §

    This column has been deprecated for a long time, because it did not update in response to other catalog changes (such as column renamings). The recommended way to get a text version of a check constraint's expression from pg_constraint is pg_get_expr(conbin, conrelid). pg_get_constraintdef() is also a useful alternative.

    Original release occurrence · 12.0/migration/018

  • Remove obsolete pg_attrdef.adsrc column Compatibility Migration

    Remove obsolete pg_attrdef.adsrc column (Peter Eisentraut) §

    This column has been deprecated for a long time, because it did not update in response to other catalog changes (such as column renamings). The recommended way to get a text version of a default-value expression from pg_attrdef is pg_get_expr(adbin, adrelid).

    Original release occurrence · 12.0/migration/019

  • Mark table columns of type name as having “C” collation by default Compatibility Migration

    Mark table columns of type name as having “C” collation by default (Tom Lane, Daniel Vérité) § §

    The comparison operators for data type name can now use any collation, rather than always using “C” collation. To preserve the previous semantics of queries, columns of type name are now explicitly marked as having “C” collation. A side effect of this is that regular-expression operators on name columns will now use the “C” collation by default, not the database collation, to determine the behavior of locale-dependent regular expression patterns (such as \w). If you want non-C behavior for a regular expression on a name column, attach an explicit COLLATE clause. (For user-defined name columns, another possibility is to specify a different collation at table creation time; but that just moves the non-backwards-compatibility to the comparison operators.)

    Original release occurrence · 12.0/migration/020

  • Treat object-name columns in the information_schema views as being of type name, not varchar Compatibility Migration

    Treat object-name columns in the information_schema views as being of type name, not varchar (Tom Lane) § § §

    Per the SQL standard, object-name columns in the information_schema views are declared as being of domain type sql_identifier. In PostgreSQL, the underlying catalog columns are really of type name. This change makes sql_identifier be a domain over name, rather than varchar as before. This eliminates a semantic mismatch in comparison and sorting behavior, which can greatly improve the performance of queries on information_schema views that restrict an object-name column. Note however that inequality restrictions, for example

    SELECT ... FROM information_schema.tables WHERE table_name < 'foo';
    

    will now use “C”-locale comparison semantics by default, rather than the database's default collation as before. Sorting on these columns will also follow “C” ordering rules. The previous behavior (and inefficiency) can be enforced by adding a COLLATE "default" clause.

    Original release occurrence · 12.0/migration/021

  • Remove the ability to disable dynamic shared memory Compatibility Migration

    Remove the ability to disable dynamic shared memory (Kyotaro Horiguchi) §

    Specifically, dynamic_shared_memory_type can no longer be set to none.

    Original release occurrence · 12.0/migration/022

  • Parse libpq integer connection parameters more strictly Compatibility Migration

    Parse libpq integer connection parameters more strictly (Fabien Coelho) §

    In previous releases, using an incorrect integer value for connection parameters connect_timeout, keepalives, keepalives_count, keepalives_idle, keepalives_interval and port resulted in libpq either ignoring those values or failing with incorrect error messages.

    Original release occurrence · 12.0/migration/023

  • Improve performance of many operations on partitioned tables Performance

    Improve performance of many operations on partitioned tables (Amit Langote, David Rowley, Tom Lane, Álvaro Herrera) § § § § §

    Allow tables with thousands of child partitions to be processed efficiently by operations that only affect a small number of partitions.

    Original release occurrence · 12.0/changes/001

  • Allow foreign keys to reference partitioned tables Features

    Allow foreign keys to reference partitioned tables (Álvaro Herrera) §

    Original release occurrence · 12.0/changes/002

  • Improve speed of COPY into partitioned tables Features

    Improve speed of COPY into partitioned tables (David Rowley) §

    Original release occurrence · 12.0/changes/003

  • Allow partition bounds to be any expression Features

    Allow partition bounds to be any expression (Kyotaro Horiguchi, Tom Lane, Amit Langote) §

    Such expressions are evaluated at partitioned-table creation time. Previously, only simple constants were allowed as partition bounds.

    Original release occurrence · 12.0/changes/004

  • Allow CREATE TABLE's tablespace specification for a partitioned table to affect the tablespace of its children Features

    Allow CREATE TABLE's tablespace specification for a partitioned table to affect the tablespace of its children (David Rowley, Álvaro Herrera) §

    Original release occurrence · 12.0/changes/005

  • Avoid sorting when partitions are already being scanned in the necessary order Features

    Avoid sorting when partitions are already being scanned in the necessary order (David Rowley) §

    Original release occurrence · 12.0/changes/006

  • ALTER TABLE ATTACH PARTITION is now performed with reduced locking requirements Features

    ALTER TABLE ATTACH PARTITION is now performed with reduced locking requirements (Robert Haas) §

    Original release occurrence · 12.0/changes/007

  • Add partition introspection functions Features

    Add partition introspection functions (Michaël Paquier, Álvaro Herrera, Amit Langote) § § §

    The new function pg_partition_root() returns the top-most parent of a partition tree, pg_partition_ancestors() reports all ancestors of a partition, and pg_partition_tree() displays information about partitions.

    Original release occurrence · 12.0/changes/008

  • Include partitioned indexes in the system view pg_indexes Features

    Include partitioned indexes in the system view pg_indexes (Suraj Kharage) §

    Original release occurrence · 12.0/changes/009

  • Add psql command \dP to list partitioned tables and indexes Features

    Add psql command \dP to list partitioned tables and indexes (Pavel Stehule) §

    Original release occurrence · 12.0/changes/010

  • Improve psql \d and \z display of partitioned tables Features

    Improve psql \d and \z display of partitioned tables (Pavel Stehule, Michaël Paquier, Álvaro Herrera) § § §

    Original release occurrence · 12.0/changes/011

  • Fix bugs that could cause ALTER TABLE DETACH PARTITION to leave behind incorrect dependency state, allowing subsequent operations to misbehave, for example by not dropping a former partition child index when its table is dropped Bug fixes

    Fix bugs that could cause ALTER TABLE DETACH PARTITION to leave behind incorrect dependency state, allowing subsequent operations to misbehave, for example by not dropping a former partition child index when its table is dropped (Tom Lane) §

    Original release occurrence · 12.0/changes/012

  • Improve performance and space utilization of btree indexes with many duplicates Performance

    Improve performance and space utilization of btree indexes with many duplicates (Peter Geoghegan, Heikki Linnakangas) § § §

    Previously, duplicate index entries were stored unordered within their duplicate groups. This caused overhead during index inserts, wasted space due to excessive page splits, and it reduced VACUUM's ability to recycle entire pages. Duplicate index entries are now sorted in heap-storage order.

    Indexes pg_upgrade'd from previous releases will not have these benefits.

    Original release occurrence · 12.0/changes/013

  • Allow multi-column btree indexes to be smaller Features

    Allow multi-column btree indexes to be smaller (Peter Geoghegan, Heikki Linnakangas)

    Internal pages and min/max leaf page indicators now only store index keys until the change key, rather than all indexed keys. This also improves the locality of index access.

    Indexes pg_upgrade'd from previous releases will not have these benefits.

    Original release occurrence · 12.0/changes/014

  • Improve speed of btree index insertions by reducing locking overhead Features

    Improve speed of btree index insertions by reducing locking overhead (Alexander Korotkov) §

    Original release occurrence · 12.0/changes/015

  • Support INCLUDE columns in GiST indexes Features

    Support INCLUDE columns in GiST indexes (Andrey Borodin) §

    Original release occurrence · 12.0/changes/016

  • Add support for nearest-neighbor (KNN) searches of SP-GiST indexes Features

    Add support for nearest-neighbor (KNN) searches of SP-GiST indexes (Nikita Glukhov, Alexander Korotkov, Vlad Sterzhanov) §

    Original release occurrence · 12.0/changes/017

  • Reduce the WAL write overhead of GiST, GIN, and SP-GiST index creation Performance

    Reduce the WAL write overhead of GiST, GIN, and SP-GiST index creation (Anastasia Lubennikova, Andrey V. Lepikhov) §

    Original release occurrence · 12.0/changes/018

  • Allow index-only scans to be more efficient on indexes with many columns Features

    Allow index-only scans to be more efficient on indexes with many columns (Konstantin Knizhnik) §

    Original release occurrence · 12.0/changes/019

  • Improve the performance of vacuum scans of GiST indexes Performance

    Improve the performance of vacuum scans of GiST indexes (Andrey Borodin, Konstantin Kuznetsov, Heikki Linnakangas) §

    Original release occurrence · 12.0/changes/020

  • Delete empty leaf pages during GiST VACUUM Features

    Delete empty leaf pages during GiST VACUUM (Andrey Borodin) §

    Original release occurrence · 12.0/changes/021

  • Reduce locking requirements for index renaming Features

    Reduce locking requirements for index renaming (Peter Eisentraut) §

    Original release occurrence · 12.0/changes/022

  • Allow CREATE STATISTICS to create most-common-value statistics for multiple columns Features

    Allow CREATE STATISTICS to create most-common-value statistics for multiple columns (Tomas Vondra) § §

    This improves optimization for queries that test several columns, requiring an estimate of the combined effect of several WHERE clauses. If the columns are correlated and have non-uniform distributions then multi-column statistics will allow much better estimates.

    Original release occurrence · 12.0/changes/023

  • Allow common table expressions (CTEs) to be inlined into the outer query Features

    Allow common table expressions (CTEs) to be inlined into the outer query (Andreas Karlsson, Andrew Gierth, David Fetter, Tom Lane) § §

    Specifically, CTEs are automatically inlined if they have no side-effects, are not recursive, and are referenced only once in the query. Inlining can be prevented by specifying MATERIALIZED, or forced for multiply-referenced CTEs by specifying NOT MATERIALIZED. Previously, CTEs were never inlined and were always evaluated before the rest of the query.

    Original release occurrence · 12.0/changes/024

  • Allow control over when generic plans are used for prepared statements Features

    Allow control over when generic plans are used for prepared statements (Pavel Stehule) §

    This is controlled by the plan_cache_mode server parameter.

    Original release occurrence · 12.0/changes/025

  • Improve optimization of partition and UNION ALL queries that have only a single child Features

    Improve optimization of partition and UNION ALL queries that have only a single child (David Rowley) §

    Original release occurrence · 12.0/changes/026

  • Improve processing of domains that have no check constraints Features

    Improve processing of domains that have no check constraints (Tom Lane) §

    Domains that are being used purely as type aliases no longer cause optimization difficulties.

    Original release occurrence · 12.0/changes/027

  • Pre-evaluate calls of LEAST and GREATEST when their arguments are constants Features

    Pre-evaluate calls of LEAST and GREATEST when their arguments are constants (Vik Fearing) §

    Original release occurrence · 12.0/changes/028

  • Improve optimizer's ability to verify that partial indexes with IS NOT NULL conditions are usable in queries Features

    Improve optimizer's ability to verify that partial indexes with IS NOT NULL conditions are usable in queries (Tom Lane, James Coleman) § §

    Usability can now be recognized in more cases where the calling query involves casts or large x IN (array) clauses.

    Original release occurrence · 12.0/changes/029

  • Compute ANALYZE statistics using the collation defined for each column Features

    Compute ANALYZE statistics using the collation defined for each column (Tom Lane) §

    Previously, the database's default collation was used for all statistics. This potentially gives better optimizer behavior for columns with non-default collations.

    Original release occurrence · 12.0/changes/030

  • Improve selectivity estimates for inequality comparisons on ctid columns Features

    Improve selectivity estimates for inequality comparisons on ctid columns (Edmund Horner) §

    Original release occurrence · 12.0/changes/031

  • Improve optimization of joins on columns of type tid Features

    Improve optimization of joins on columns of type tid (Tom Lane) § §

    These changes primarily improve the efficiency of self-joins on ctid columns.

    Original release occurrence · 12.0/changes/032

  • Fix the leakproofness designations of some btree comparison operators and support functions Bug fixes

    Fix the leakproofness designations of some btree comparison operators and support functions (Tom Lane) § §

    This allows some optimizations that previously would not have been applied in the presence of security barrier views or row-level security.

    Original release occurrence · 12.0/changes/033

  • Enable Just-in-Time (JIT) compilation by default, if the server has been built with support for it Performance

    Enable Just-in-Time (JIT) compilation by default, if the server has been built with support for it (Andres Freund) §

    Note that this support is not built by default, but has to be selected explicitly while configuring the build.

    Original release occurrence · 12.0/changes/034

  • Speed up keyword lookup Performance

    Speed up keyword lookup (John Naylor, Joerg Sonnenberger, Tom Lane) § §

    Original release occurrence · 12.0/changes/035

  • Improve search performance for multi-byte characters in position() and related functions Performance

    Improve search performance for multi-byte characters in position() and related functions (Heikki Linnakangas) §

    Original release occurrence · 12.0/changes/036

  • Allow toasted values to be minimally decompressed Performance

    Allow toasted values to be minimally decompressed (Paul Ramsey) §

    This is useful for routines that only need to examine the initial portion of a toasted field.

    Original release occurrence · 12.0/changes/037

  • Allow ALTER TABLE ... SET NOT NULL to avoid unnecessary table scans Performance

    Allow ALTER TABLE ... SET NOT NULL to avoid unnecessary table scans (Sergei Kornilov) §

    This can be optimized when the table's column constraints can be recognized as disallowing nulls.

    Original release occurrence · 12.0/changes/038

  • Allow ALTER TABLE ... SET DATA TYPE changing between timestamp and timestamptz to avoid a table rewrite when the session time zone is UTC Performance

    Allow ALTER TABLE ... SET DATA TYPE changing between timestamp and timestamptz to avoid a table rewrite when the session time zone is UTC (Noah Misch) §

    In the UTC time zone, these two data types are binary compatible.

    Original release occurrence · 12.0/changes/039

  • Improve speed in converting strings to int2 or int4 integers Performance

    Improve speed in converting strings to int2 or int4 integers (Andres Freund) §

    Original release occurrence · 12.0/changes/040

  • Allow parallelized queries when in SERIALIZABLE isolation mode Performance

    Allow parallelized queries when in SERIALIZABLE isolation mode (Thomas Munro) §

    Previously, parallelism was disabled when in this mode.

    Original release occurrence · 12.0/changes/041

  • Use pread() and pwrite() for random I/O Performance

    Use pread() and pwrite() for random I/O (Oskari Saarenmaa, Thomas Munro) § §

    This reduces the number of system calls required for I/O.

    Original release occurrence · 12.0/changes/042

  • Improve the speed of setting the process title on FreeBSD Performance

    Improve the speed of setting the process title on FreeBSD (Thomas Munro) §

    Original release occurrence · 12.0/changes/043

  • Allow logging of statements from only a percentage of transactions Features

    Allow logging of statements from only a percentage of transactions (Adrien Nayrat) §

    The parameter log_transaction_sample_rate controls this.

    Original release occurrence · 12.0/changes/044

  • Add progress reporting to CREATE INDEX and REINDEX operations Features

    Add progress reporting to CREATE INDEX and REINDEX operations (Álvaro Herrera, Peter Eisentraut) § §

    Progress is reported in the pg_stat_progress_create_index system view.

    Original release occurrence · 12.0/changes/045

  • Add progress reporting to CLUSTER and VACUUM FULL Features

    Add progress reporting to CLUSTER and VACUUM FULL (Tatsuro Yamada) §

    Progress is reported in the pg_stat_progress_cluster system view.

    Original release occurrence · 12.0/changes/046

  • Add progress reporting to pg_checksums Features

    Add progress reporting to pg_checksums (Michael Banck, Bernd Helmle) §

    This is enabled with the option --progress.

    Original release occurrence · 12.0/changes/047

  • Add counter of checksum failures to pg_stat_database Features

    Add counter of checksum failures to pg_stat_database (Magnus Hagander) §

    Original release occurrence · 12.0/changes/048

  • Add tracking of global objects in system view pg_stat_database Features

    Add tracking of global objects in system view pg_stat_database (Julien Rouhaud) §

    Global objects are shown with a pg_stat_database.datid value of zero.

    Original release occurrence · 12.0/changes/049

  • Add the ability to list the contents of the archive directory Features

    Add the ability to list the contents of the archive directory (Christoph Moench-Tegeder) §

    The function is pg_ls_archive_statusdir().

    Original release occurrence · 12.0/changes/050

  • Add the ability to list the contents of temporary directories Features

    Add the ability to list the contents of temporary directories (Nathan Bossart) §

    The function, pg_ls_tmpdir(), optionally allows specification of a tablespace.

    Original release occurrence · 12.0/changes/051

  • Add information about the client certificate to the system view pg_stat_ssl Features

    Add information about the client certificate to the system view pg_stat_ssl (Peter Eisentraut) §

    The new columns are client_serial and issuer_dn. Column clientdn has been renamed to client_dn for clarity.

    Original release occurrence · 12.0/changes/052

  • Restrict visibility of rows in pg_stat_ssl for unprivileged users Features

    Restrict visibility of rows in pg_stat_ssl for unprivileged users (Peter Eisentraut) §

    Original release occurrence · 12.0/changes/053

  • At server start, emit a log message including the server version number Features

    At server start, emit a log message including the server version number (Christoph Berg) §

    Original release occurrence · 12.0/changes/054

  • Prevent logging “incomplete startup packet” if a new connection is immediately closed Features

    Prevent logging “incomplete startup packet” if a new connection is immediately closed (Tom Lane) §

    This avoids log spam from certain forms of monitoring.

    Original release occurrence · 12.0/changes/055

  • Include the application_name, if set, in log_connections log messages Features

    Include the application_name, if set, in log_connections log messages (Don Seiler) §

    Original release occurrence · 12.0/changes/056

  • Make the walreceiver set its application name to the cluster name, if set Features

    Make the walreceiver set its application name to the cluster name, if set (Peter Eisentraut) §

    Original release occurrence · 12.0/changes/057

  • Add the timestamp of the last received standby message to pg_stat_replication Features

    Add the timestamp of the last received standby message to pg_stat_replication (Lim Myungkyu) §

    Original release occurrence · 12.0/changes/058

  • Add a wait event for fsync of WAL segments Features

    Add a wait event for fsync of WAL segments (Konstantin Knizhnik) §

    Original release occurrence · 12.0/changes/059

  • Add GSSAPI encryption support Features

    Add GSSAPI encryption support (Robbie Harwood, Stephen Frost) §

    This feature allows TCP/IP connections to be encrypted when using GSSAPI authentication, without having to set up a separate encryption facility such as SSL. In support of this, add hostgssenc and hostnogssenc record types in pg_hba.conf for selecting connections that do or do not use GSSAPI encryption, corresponding to the existing hostssl and hostnossl record types. There is also a new gssencmode libpq option, and a pg_stat_gssapi system view.

    Original release occurrence · 12.0/changes/060

  • Allow the clientcert pg_hba.conf option to check that the database user name matches the client certificate's common name Features

    Allow the clientcert pg_hba.conf option to check that the database user name matches the client certificate's common name (Julian Markwort, Marius Timmer) §

    This new check is enabled with clientcert=verify-full.

    Original release occurrence · 12.0/changes/061

  • Allow discovery of an LDAP server using DNS SRV records Features

    Allow discovery of an LDAP server using DNS SRV records (Thomas Munro) §

    This avoids the requirement of specifying ldapserver. It is only supported if PostgreSQL is compiled with OpenLDAP.

    Original release occurrence · 12.0/changes/062

  • Add ability to enable/disable cluster checksums using pg_checksums Features

    Add ability to enable/disable cluster checksums using pg_checksums (Michael Banck, Michaël Paquier) §

    The cluster must be shut down for these operations.

    Original release occurrence · 12.0/changes/063

  • Reduce the default value of autovacuum_vacuum_cost_delay to 2ms Features

    Reduce the default value of autovacuum_vacuum_cost_delay to 2ms (Tom Lane) §

    This allows autovacuum operations to proceed faster by default.

    Original release occurrence · 12.0/changes/064

  • Allow vacuum_cost_delay to specify sub-millisecond delays, by accepting fractional values Features

    Allow vacuum_cost_delay to specify sub-millisecond delays, by accepting fractional values (Tom Lane) §

    Original release occurrence · 12.0/changes/065

  • Allow time-based server parameters to use units of microseconds (us) Features

    Allow time-based server parameters to use units of microseconds (us) (Tom Lane) §

    Original release occurrence · 12.0/changes/066

  • Allow fractional input for integer server parameters Features

    Allow fractional input for integer server parameters (Tom Lane) §

    For example, SET work_mem = '30.1GB' is now allowed, even though work_mem is an integer parameter. The value will be rounded to an integer after any required units conversion.

    Original release occurrence · 12.0/changes/067

  • Allow units to be defined for floating-point server parameters Features

    Allow units to be defined for floating-point server parameters (Tom Lane) §

    Original release occurrence · 12.0/changes/068

  • Add wal_recycle and wal_init_zero server parameters to control WAL file recycling Features

    Add wal_recycle and wal_init_zero server parameters to control WAL file recycling (Jerry Jelinek) §

    Avoiding file recycling can be beneficial on copy-on-write file systems like ZFS.

    Original release occurrence · 12.0/changes/069

  • Add server parameter tcp_user_timeout to control the server's TCP timeout Features

    Add server parameter tcp_user_timeout to control the server's TCP timeout (Ryohei Nagaura) §

    Original release occurrence · 12.0/changes/070

  • Allow control of the minimum and maximum SSL protocol versions Features

    Allow control of the minimum and maximum SSL protocol versions (Peter Eisentraut) §

    The server parameters are ssl_min_protocol_version and ssl_max_protocol_version.

    Original release occurrence · 12.0/changes/071

  • Add server parameter ssl_library to report the SSL library version used by the server Features

    Add server parameter ssl_library to report the SSL library version used by the server (Peter Eisentraut) §

    Original release occurrence · 12.0/changes/072

  • Add server parameter shared_memory_type to control the type of shared memory to use Features

    Add server parameter shared_memory_type to control the type of shared memory to use (Andres Freund) §

    This allows selection of System V shared memory, if desired.

    Original release occurrence · 12.0/changes/073

  • Allow some recovery parameters to be changed with reload Features

    Allow some recovery parameters to be changed with reload (Peter Eisentraut) §

    These parameters are archive_cleanup_command, promote_trigger_file, recovery_end_command, and recovery_min_apply_delay.

    Original release occurrence · 12.0/changes/074

  • Allow the streaming replication timeout (wal_sender_timeout) to be set per connection Features

    Allow the streaming replication timeout (wal_sender_timeout) to be set per connection (Takayuki Tsunakawa) §

    Previously, this could only be set cluster-wide.

    Original release occurrence · 12.0/changes/075

  • Add function pg_promote() to promote standbys to primaries Features

    Add function pg_promote() to promote standbys to primaries (Laurenz Albe, Michaël Paquier) § §

    Previously, this operation was only possible by using pg_ctl or creating a trigger file.

    Original release occurrence · 12.0/changes/076

  • Allow replication slots to be copied Features

    Allow replication slots to be copied (Masahiko Sawada) §

    The functions for this are pg_copy_physical_replication_slot() and pg_copy_logical_replication_slot().

    Original release occurrence · 12.0/changes/077

  • Make max_wal_senders not count as part of max_connections Features

    Make max_wal_senders not count as part of max_connections (Alexander Kukushkin) §

    Original release occurrence · 12.0/changes/078

  • Add an explicit value of current for recovery_target_timeline Features

    Add an explicit value of current for recovery_target_timeline (Peter Eisentraut) §

    Original release occurrence · 12.0/changes/079

  • Make recovery fail if a two-phase transaction status file is corrupt Features

    Make recovery fail if a two-phase transaction status file is corrupt (Michaël Paquier) §

    Previously, a warning was logged and recovery continued, allowing the transaction to be lost.

    Original release occurrence · 12.0/changes/080

  • Add REINDEX CONCURRENTLY option to allow reindexing without locking out writes Features

    Add REINDEX CONCURRENTLY option to allow reindexing without locking out writes (Michaël Paquier, Andreas Karlsson, Peter Eisentraut) §

    This is also controlled by the reindexdb application's --concurrently option.

    Original release occurrence · 12.0/changes/081

  • Add support for generated columns Features

    Add support for generated columns (Peter Eisentraut) §

    The content of generated columns are computed from expressions (including references to other columns in the same table) rather than being specified by INSERT or UPDATE commands.

    Original release occurrence · 12.0/changes/082

  • Add a WHERE clause to COPY FROM to control which rows are accepted Features

    Add a WHERE clause to COPY FROM to control which rows are accepted (Surafel Temesgen) §

    This provides a simple way to filter incoming data.

    Original release occurrence · 12.0/changes/083

  • Allow enumerated values to be added more flexibly Features

    Allow enumerated values to be added more flexibly (Andrew Dunstan, Tom Lane, Thomas Munro) §

    Previously, ALTER TYPE ... ADD VALUE could not be called in a transaction block, unless it was part of the same transaction that created the enumerated type. Now it can be called in a later transaction, so long as the new enumerated value is not referenced until after it is committed.

    Original release occurrence · 12.0/changes/084

  • Add commands to end a transaction and start a new one Features

    Add commands to end a transaction and start a new one (Peter Eisentraut) §

    The commands are COMMIT AND CHAIN and ROLLBACK AND CHAIN.

    Original release occurrence · 12.0/changes/085

  • Add VACUUM and CREATE TABLE options to prevent VACUUM from truncating trailing empty pages Features

    Add VACUUM and CREATE TABLE options to prevent VACUUM from truncating trailing empty pages (Takayuki Tsunakawa) § §

    These options are vacuum_truncate and toast.vacuum_truncate. Use of these options reduces VACUUM's locking requirements, but prevents returning disk space to the operating system.

    Original release occurrence · 12.0/changes/086

  • Allow VACUUM to skip index cleanup Features

    Allow VACUUM to skip index cleanup (Masahiko Sawada) § §

    This change adds a VACUUM command option INDEX_CLEANUP as well as a table storage option vacuum_index_cleanup. Use of this option reduces the ability to reclaim space and can lead to index bloat, but it is helpful when the main goal is to freeze old tuples.

    Original release occurrence · 12.0/changes/087

  • Add the ability to skip VACUUM and ANALYZE operations on tables that cannot be locked immediately Features

    Add the ability to skip VACUUM and ANALYZE operations on tables that cannot be locked immediately (Nathan Bossart) §

    This option is called SKIP_LOCKED.

    Original release occurrence · 12.0/changes/088

  • Allow VACUUM and ANALYZE to take optional Boolean argument specifications Features

    Allow VACUUM and ANALYZE to take optional Boolean argument specifications (Masahiko Sawada) §

    Original release occurrence · 12.0/changes/089

  • Prevent TRUNCATE, VACUUM and ANALYZE from requesting a lock on tables for which the user lacks permission Features

    Prevent TRUNCATE, VACUUM and ANALYZE from requesting a lock on tables for which the user lacks permission (Michaël Paquier) § §

    This prevents unauthorized locking, which could interfere with user queries.

    Original release occurrence · 12.0/changes/090

  • Add EXPLAIN option SETTINGS to output non-default optimizer settings Features

    Add EXPLAIN option SETTINGS to output non-default optimizer settings (Tomas Vondra) §

    This output can also be obtained when using auto_explain by setting auto_explain.log_settings.

    Original release occurrence · 12.0/changes/091

  • Add OR REPLACE option to CREATE AGGREGATE Features

    Add OR REPLACE option to CREATE AGGREGATE (Andrew Gierth) §

    Original release occurrence · 12.0/changes/092

  • Allow modifications of system catalogs' options using ALTER TABLE Features

    Allow modifications of system catalogs' options using ALTER TABLE (Peter Eisentraut) §

    Modifications of catalogs' reloptions and autovacuum settings are now supported. (Setting allow_system_table_mods is still required.)

    Original release occurrence · 12.0/changes/093

  • Use all key columns' names when selecting default constraint names for foreign keys Features

    Use all key columns' names when selecting default constraint names for foreign keys (Peter Eisentraut) §

    Previously, only the first column name was included in the constraint name, resulting in ambiguity for multi-column foreign keys.

    Original release occurrence · 12.0/changes/094

  • Update assorted knowledge about Unicode to match Unicode 12.1.0 Features

    Update assorted knowledge about Unicode to match Unicode 12.1.0 (Peter Eisentraut) § §

    This fixes, for example, cases where psql would misformat output involving combining characters.

    Original release occurrence · 12.0/changes/095

  • Update Snowball stemmer dictionaries with support for new languages Features

    Update Snowball stemmer dictionaries with support for new languages (Arthur Zakirov) §

    This adds word stemming support for Arabic, Indonesian, Irish, Lithuanian, Nepali, and Tamil to full text search.

    Original release occurrence · 12.0/changes/096

  • Allow creation of collations that report string equality for strings that are not bit-wise equal Features

    Allow creation of collations that report string equality for strings that are not bit-wise equal (Peter Eisentraut) §

    This feature supports “nondeterministic” collations that can define case- and accent-agnostic equality comparisons. Thus, for example, a case-insensitive uniqueness constraint on a text column can be made more easily than before. This is only supported for ICU collations.

    Original release occurrence · 12.0/changes/097

  • Add support for ICU collation attributes on older ICU versions Features

    Add support for ICU collation attributes on older ICU versions (Peter Eisentraut) §

    This allows customization of the collation rules in a consistent way across all ICU versions.

    Original release occurrence · 12.0/changes/098

  • Allow data type name to more seamlessly be compared to other text types Features

    Allow data type name to more seamlessly be compared to other text types (Tom Lane) §

    Type name now behaves much like a domain over type text that has default collation “C”. This allows cross-type comparisons to be processed more efficiently.

    Original release occurrence · 12.0/changes/099

  • Add support for the SQL/JSON path language Features

    Add support for the SQL/JSON path language (Nikita Glukhov, Teodor Sigaev, Alexander Korotkov, Oleg Bartunov, Liudmila Mantrova) § § §

    This allows execution of complex queries on JSON values using an SQL-standard language.

    Original release occurrence · 12.0/changes/100

  • Add support for hyperbolic functions Features

    Add support for hyperbolic functions (Lætitia Avrot) §

    Also add log10() as an alias for log(), for standards compliance.

    Original release occurrence · 12.0/changes/101

  • Improve the accuracy of statistical aggregates like variance() by using more precise algorithms Features

    Improve the accuracy of statistical aggregates like variance() by using more precise algorithms (Dean Rasheed) §

    Original release occurrence · 12.0/changes/102

  • Allow date_trunc() to have an additional argument to control the time zone Features

    Allow date_trunc() to have an additional argument to control the time zone (Vik Fearing, Tom Lane) §

    This is faster and simpler than using the AT TIME ZONE clause.

    Original release occurrence · 12.0/changes/103

  • Adjust to_timestamp()/to_date() functions to be more forgiving of template mismatches Features

    Adjust to_timestamp()/to_date() functions to be more forgiving of template mismatches (Artur Zakirov, Alexander Korotkov, Liudmila Mantrova) §

    This new behavior more closely matches the Oracle functions of the same name.

    Original release occurrence · 12.0/changes/104

  • Fix assorted bugs in XML functions Bug fixes

    Fix assorted bugs in XML functions (Pavel Stehule, Markus Winand, Chapman Flack) §

    Specifically, in XMLTABLE, xpath(), and xmlexists(), fix some cases where nothing was output for a node, or an unexpected error was thrown, or necessary escaping of XML special characters was omitted.

    Original release occurrence · 12.0/changes/105

  • Allow the BY VALUE clause in XMLEXISTS and XMLTABLE Features

    Allow the BY VALUE clause in XMLEXISTS and XMLTABLE (Chapman Flack) §

    This SQL-standard clause has no effect in PostgreSQL's implementation, but it was unnecessarily being rejected.

    Original release occurrence · 12.0/changes/106

  • Prevent current_schema() and current_schemas() from being run by parallel workers, as they are not parallel-safe Features

    Prevent current_schema() and current_schemas() from being run by parallel workers, as they are not parallel-safe (Michaël Paquier) §

    Original release occurrence · 12.0/changes/107

  • Allow RECORD and RECORD[] to be used as column types in a query's column definition list for a table function that is declared to return RECORD Features

    Allow RECORD and RECORD[] to be used as column types in a query's column definition list for a table function that is declared to return RECORD (Elvis Pranskevichus) §

    Original release occurrence · 12.0/changes/108

  • Allow SQL commands and variables with the same names as those commands to be used in the same PL/pgSQL function Features

    Allow SQL commands and variables with the same names as those commands to be used in the same PL/pgSQL function (Tom Lane) §

    For example, allow a variable called comment to exist in a function that calls the COMMENT SQL command. Previously this combination caused a parse error.

    Original release occurrence · 12.0/changes/109

  • Add new optional warning and error checks to PL/pgSQL Features

    Add new optional warning and error checks to PL/pgSQL (Pavel Stehule) §

    The new checks allow for run-time validation of INTO column counts and single-row results.

    Original release occurrence · 12.0/changes/110

  • Add connection parameter tcp_user_timeout to control libpq's TCP timeout Features

    Add connection parameter tcp_user_timeout to control libpq's TCP timeout (Ryohei Nagaura) §

    Original release occurrence · 12.0/changes/111

  • Allow libpq (and thus psql) to report only the SQLSTATE value in error messages Features

    Allow libpq (and thus psql) to report only the SQLSTATE value in error messages (Didier Gautheron) §

    Original release occurrence · 12.0/changes/112

  • Add libpq function PQresultMemorySize() to report the memory used by a query result Features

    Add libpq function PQresultMemorySize() to report the memory used by a query result (Lars Kanis, Tom Lane) §

    Original release occurrence · 12.0/changes/113

  • Remove the no-display/debug flag from libpq's options connection parameter Features

    Remove the no-display/debug flag from libpq's options connection parameter (Peter Eisentraut) §

    This allows this parameter to be set by postgres_fdw.

    Original release occurrence · 12.0/changes/114

  • Allow ecpg to create variables of data type bytea Features

    Allow ecpg to create variables of data type bytea (Ryo Matsumura) §

    This allows ECPG clients to interact with bytea data directly, rather than using an encoded form.

    Original release occurrence · 12.0/changes/115

  • Add PREPARE AS support to ECPG Features

    Add PREPARE AS support to ECPG (Ryo Matsumura) §

    Original release occurrence · 12.0/changes/116

  • Allow vacuumdb to select tables for vacuum based on their wraparound horizon Features

    Allow vacuumdb to select tables for vacuum based on their wraparound horizon (Nathan Bossart) §

    The options are --min-xid-age and --min-mxid-age.

    Original release occurrence · 12.0/changes/117

  • Allow vacuumdb to disable waiting for locks or skipping all-visible pages Features

    Allow vacuumdb to disable waiting for locks or skipping all-visible pages (Nathan Bossart) §

    The options are --skip-locked and --disable-page-skipping.

    Original release occurrence · 12.0/changes/118

  • Add colorization to the output of command-line utilities Features

    Add colorization to the output of command-line utilities (Peter Eisentraut) §

    This is enabled by setting the environment variable PG_COLOR to always or auto. The specific colors used can be adjusted by setting the environment variable PG_COLORS, using ANSI escape codes for colors. For example, the default behavior is equivalent to PG_COLORS="error=01;31:warning=01;35:locus=01".

    Original release occurrence · 12.0/changes/119

  • Add CSV table output mode in psql Features

    Add CSV table output mode in psql (Daniel Vérité) §

    This is controlled by \pset format csv or the command-line --csv option.

    Original release occurrence · 12.0/changes/120

  • Show the manual page URL in psql's \help output for a SQL command Features

    Show the manual page URL in psql's \help output for a SQL command (Peter Eisentraut) §

    Original release occurrence · 12.0/changes/121

  • Display the IP address in psql's \conninfo Features

    Display the IP address in psql's \conninfo (Fabien Coelho) § §

    Original release occurrence · 12.0/changes/122

  • Improve tab completion of CREATE TABLE, CREATE TRIGGER, CREATE EVENT TRIGGER, ANALYZE, EXPLAIN, VACUUM, ALTER TABLE, ALTER INDEX, ALTER DATABASE, and ALTER INDEX ALTER COLUMN Features

    Improve tab completion of CREATE TABLE, CREATE TRIGGER, CREATE EVENT TRIGGER, ANALYZE, EXPLAIN, VACUUM, ALTER TABLE, ALTER INDEX, ALTER DATABASE, and ALTER INDEX ALTER COLUMN (Dagfinn Ilmari Mannsåker, Tatsuro Yamada, Michaël Paquier, Tom Lane, Justin Pryzby) § § § § § § § § §

    Original release occurrence · 12.0/changes/123

  • Allow values produced by queries to be assigned to pgbench variables Features

    Allow values produced by queries to be assigned to pgbench variables (Fabien Coelho, Álvaro Herrera) § §

    The command for this is \gset.

    Original release occurrence · 12.0/changes/124

  • Improve precision of pgbench's --rate option Features

    Improve precision of pgbench's --rate option (Tom Lane) §

    Original release occurrence · 12.0/changes/125

  • Improve pgbench's error reporting with clearer messages and return codes Features

    Improve pgbench's error reporting with clearer messages and return codes (Peter Eisentraut) §

    Original release occurrence · 12.0/changes/126

  • Allow control of log file rotation via pg_ctl Features

    Allow control of log file rotation via pg_ctl (Kyotaro Horiguchi, Alexander Kuzmenkov, Alexander Korotkov) §

    Previously, this was only possible via an SQL function or a process signal.

    Original release occurrence · 12.0/changes/127

  • Properly detach the new server process during pg_ctl start Features

    Properly detach the new server process during pg_ctl start (Paul Guo) §

    This prevents the server from being shut down if the shell script that invoked pg_ctl is interrupted later.

    Original release occurrence · 12.0/changes/128

  • Allow pg_upgrade to use the file system's cloning feature, if there is one Features

    Allow pg_upgrade to use the file system's cloning feature, if there is one (Peter Eisentraut) §

    The --clone option has the advantages of --link, while preventing the old cluster from being changed after the new cluster has started.

    Original release occurrence · 12.0/changes/129

  • Allow specification of the socket directory to use in pg_upgrade Features

    Allow specification of the socket directory to use in pg_upgrade (Daniel Gustafsson) §

    This is controlled by --socketdir; the default is the current directory.

    Original release occurrence · 12.0/changes/130

  • Allow pg_checksums to disable fsync operations Features

    Allow pg_checksums to disable fsync operations (Michaël Paquier) §

    This is controlled by the --no-sync option.

    Original release occurrence · 12.0/changes/131

  • Allow pg_rewind to disable fsync operations Features

    Allow pg_rewind to disable fsync operations (Michaël Paquier) §

    Original release occurrence · 12.0/changes/132

  • Fix pg_test_fsync to report accurate open_datasync durations on Windows Bug fixes

    Fix pg_test_fsync to report accurate open_datasync durations on Windows (Laurenz Albe) § §

    Original release occurrence · 12.0/changes/133

  • When pg_dump emits data with INSERT commands rather than COPY, allow more than one data row to be included in each INSERT Features

    When pg_dump emits data with INSERT commands rather than COPY, allow more than one data row to be included in each INSERT (Surafel Temesgen, David Rowley) § §

    The option controlling this is --rows-per-insert.

    Original release occurrence · 12.0/changes/134

  • Allow pg_dump to emit INSERT ... ON CONFLICT DO NOTHING Features

    Allow pg_dump to emit INSERT ... ON CONFLICT DO NOTHING (Surafel Temesgen) §

    This avoids conflict failures during restore. The option is --on-conflict-do-nothing.

    Original release occurrence · 12.0/changes/135

  • Decouple the order of operations in a parallel pg_dump from the order used by a subsequent parallel pg_restore Features

    Decouple the order of operations in a parallel pg_dump from the order used by a subsequent parallel pg_restore (Tom Lane) §

    This allows pg_restore to perform more-fully-parallelized parallel restores, especially in cases where the original dump was not done in parallel. Scheduling of a parallel pg_dump is also somewhat improved.

    Original release occurrence · 12.0/changes/136

  • Allow the extra_float_digits setting to be specified for pg_dump and pg_dumpall Features

    Allow the extra_float_digits setting to be specified for pg_dump and pg_dumpall (Andrew Dunstan) §

    This is primarily useful for making dumps that are exactly comparable across different source server versions. It is not recommended for normal use, as it may result in loss of precision when the dump is restored.

    Original release occurrence · 12.0/changes/137

  • Add --exclude-database option to pg_dumpall Features

    Add --exclude-database option to pg_dumpall (Andrew Dunstan) §

    Original release occurrence · 12.0/changes/138

  • Add CREATE ACCESS METHOD command to create new table types Features

    Add CREATE ACCESS METHOD command to create new table types (Andres Freund, Haribabu Kommi, Álvaro Herrera, Alexander Korotkov, Dmitry Dolgov) § § § § § § § § §

    This enables the development of new table access methods, which can optimize storage for different use cases. The existing heap access method remains the default.

    Original release occurrence · 12.0/changes/139

  • Add planner support function interfaces to improve optimizer estimates, inlining, and indexing for functions Features

    Add planner support function interfaces to improve optimizer estimates, inlining, and indexing for functions (Tom Lane) § § §

    This allows extensions to create planner support functions that can provide function-specific selectivity, cost, and row-count estimates that can depend on the function's arguments. Support functions can also supply simplified representations and index conditions, greatly expanding optimization possibilities.

    Original release occurrence · 12.0/changes/140

  • Simplify renumbering manually-assigned OIDs, and establish a new project policy for management of such OIDs Features

    Simplify renumbering manually-assigned OIDs, and establish a new project policy for management of such OIDs (John Naylor, Tom Lane) § §

    Patches that manually assign OIDs for new built-in objects (such as new functions) should now randomly choose OIDs in the range 8000—9999. At the end of a development cycle, the OIDs used by committed patches will be renumbered down to lower numbers, currently somewhere in the 4xxx range, using the new renumber_oids.pl script. This approach should greatly reduce the odds of OID collisions between different in-process patches.

    While there is no specific policy reserving any OIDs for external use, it is recommended that forks and other projects needing private manually-assigned OIDs use numbers in the high 7xxx range. This will avoid conflicts with recently-merged patches, and it should be a long time before the core project reaches that range.

    Original release occurrence · 12.0/changes/141

  • Build Cygwin binaries using dynamic instead of static libraries Features

    Build Cygwin binaries using dynamic instead of static libraries (Marco Atzeri) §

    Original release occurrence · 12.0/changes/142

  • Remove configure switch --disable-strong-random Features

    Remove configure switch --disable-strong-random (Michaël Paquier) §

    A strong random-number source is now required.

    Original release occurrence · 12.0/changes/143

  • printf-family functions, as well as strerror and strerror_r, now behave uniformly across platforms within Postgres code Features

    printf-family functions, as well as strerror and strerror_r, now behave uniformly across platforms within Postgres code (Tom Lane) § § § §

    Notably, printf understands %m everywhere; on Windows, strerror copes with Winsock error codes (it used to do so in backend but not frontend code); and strerror_r always follows the GNU return convention.

    Original release occurrence · 12.0/changes/144

  • Require a C99-compliant compiler, and MSVC 2013 or later on Windows Features

    Require a C99-compliant compiler, and MSVC 2013 or later on Windows (Andres Freund) §

    Original release occurrence · 12.0/changes/145

  • Use pandoc, not lynx, for generating plain-text documentation output files Features

    Use pandoc, not lynx, for generating plain-text documentation output files (Peter Eisentraut) § §

    This affects only the INSTALL file generated during make dist and the seldom-used plain-text postgres.txt output file. Pandoc produces better output than lynx and avoids some locale/encoding issues. Pandoc version 1.13 or later is required.

    Original release occurrence · 12.0/changes/146

  • Support use of images in the PostgreSQL documentation Features

    Support use of images in the PostgreSQL documentation (Jürgen Purtz) §

    Original release occurrence · 12.0/changes/147

  • Allow ORDER BY sorts and LIMIT clauses to be pushed to postgres_fdw foreign servers in more cases Features

    Allow ORDER BY sorts and LIMIT clauses to be pushed to postgres_fdw foreign servers in more cases (Etsuro Fujita) § §

    Original release occurrence · 12.0/changes/148

  • Improve optimizer cost accounting for postgres_fdw queries Features

    Improve optimizer cost accounting for postgres_fdw queries (Etsuro Fujita) § § §

    Original release occurrence · 12.0/changes/149

  • Properly honor WITH CHECK OPTION on views that reference postgres_fdw tables Features

    Properly honor WITH CHECK OPTION on views that reference postgres_fdw tables (Etsuro Fujita) §

    While CHECK OPTIONs on postgres_fdw tables are ignored (because the reference is foreign), views on such tables are considered local, so this change enforces CHECK OPTIONs on them. Previously, only INSERTs and UPDATEs with RETURNING clauses that returned CHECK OPTION values were validated.

    Original release occurrence · 12.0/changes/150

  • Allow pg_stat_statements_reset() to be more granular Features

    Allow pg_stat_statements_reset() to be more granular (Haribabu Kommi, Amit Kapila) §

    The function now allows reset of statistics for specific databases, users, and queries.

    Original release occurrence · 12.0/changes/151

  • Allow control of the auto_explain log level Features

    Allow control of the auto_explain log level (Tom Dunstan, Andrew Dunstan) §

    The default is LOG.

    Original release occurrence · 12.0/changes/152

  • Update unaccent rules with new punctuation and symbols Features

    Update unaccent rules with new punctuation and symbols (Hugh Ranalli, Michaël Paquier) §

    Original release occurrence · 12.0/changes/153

  • Allow unaccent to handle some accents encoded as combining characters Features

    Allow unaccent to handle some accents encoded as combining characters (Hugh Ranalli) §

    Original release occurrence · 12.0/changes/154

  • Allow unaccent to remove accents from Greek characters Features

    Allow unaccent to remove accents from Greek characters (Tasos Maschalidis) §

    Original release occurrence · 12.0/changes/155

  • Add a parameter to amcheck's bt_index_parent_check() function to check each index tuple from the root of the tree Features

    Add a parameter to amcheck's bt_index_parent_check() function to check each index tuple from the root of the tree (Peter Geoghegan) §

    Original release occurrence · 12.0/changes/156

  • Improve oid2name and vacuumlo option handling to match other commands Features

    Improve oid2name and vacuumlo option handling to match other commands (Tatsuro Yamada) § §

    Original release occurrence · 12.0/changes/157

Security evidence

34 records from the official security matrix and release-note mentions. A fixed version is shown only when the security snapshot explicitly names this branch. A mention alone does not establish applicability or a new fix.

CVE-2024-7348 · PostgreSQL relation replacement during pg_dump executes arbitrary SQL CVSS 8.8

Time-of-check Time-of-use (TOCTOU) race condition in pg_dump in PostgreSQL allows an object creator to execute arbitrary SQL functions as the user running pg_dump, which is often a superuser. The attack involves replacing another relation type with a view or foreign table. The attack requires waiting for pg_dump to start, but winning the race condition is trivial if the attacker retains an open transaction. Versions before PostgreSQL 16.4, 15.8, 14.13, 13.16, and 12.20 are affected. The PostgreSQL project thanks Noah Misch for reporting this problem.

Fixed in this branch: 12.20. Component: core server.

Official affected-branch entry: 12.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2024-10979 · PostgreSQL PL/Perl environment variable changes execute arbitrary code CVSS 8.8

Incorrect control of environment variables in PostgreSQL PL/Perl allows an unprivileged database user to change sensitive process environment variables (e.g. PATH ). That often suffices to enable arbitrary code execution, even if the attacker lacks a database server operating system user. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected. The PostgreSQL project thanks Coby Abrams for reporting this problem.

Fixed in this branch: 12.21. Component: core server.

Official affected-branch entry: 12.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2024-10978 · PostgreSQL SET ROLE, SET SESSION AUTHORIZATION reset to wrong user ID CVSS 4.2

Incorrect privilege assignment in PostgreSQL allows a less-privileged application user to view or change different rows from those intended. An attack requires the application to use SET ROLE , SET SESSION AUTHORIZATION , or an equivalent feature. The problem arises when an application query uses parameters from the attacker or conveys query results to the attacker. If that query reacts to current_setting('role') or the current user ID, it may modify or return data as though the session had not used SET ROLE or SET SESSION AUTHORIZATION . The attacker does not control which incorrect user ID applies. Query text from less-privileged sources is not a concern here, because SET ROLE and SET SESSION AUTHORIZATION are not sandboxes for unvetted queries. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected. The PostgreSQL project thanks Tom Lane for reporting this problem.

Fixed in this branch: 12.21. Component: core server.

Official affected-branch entry: 12.

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

Release-note mentions:

CVE-2024-10977 · PostgreSQL libpq retains an error message from man-in-the-middle CVSS 3.1

Client use of server error message in PostgreSQL allows a server not trusted under current SSL or GSS settings to furnish arbitrary non-NUL bytes to the libpq application. For example, a man-in-the-middle attacker could send a long error message that a human or screen-scraper user of psql mistakes for valid query results. This is probably not a concern for clients where the user interface unambiguously indicates the boundary between one error message and other text. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected. The PostgreSQL project thanks Jacob Champion for reporting this problem.

Fixed in this branch: 12.21. Component: client.

Official affected-branch entry: 12.

AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N

Release-note mentions:

CVE-2024-10976 · PostgreSQL row security below e.g. subqueries disregards user ID changes CVSS 4.2

Incomplete tracking in PostgreSQL of tables with row security allows a reused query to view or change different rows from those intended. CVE-2023-2455 and CVE-2016-2193 fixed most interaction between row security and user ID changes. They missed cases where a subquery, WITH query, security invoker view, or SQL-language function references a table with a row-level security policy. This has the same consequences as the two earlier CVEs. That is to say, it leads to potentially incorrect policies being applied in cases where role-specific policies are used and a given query is planned under one role and then executed under other roles. This scenario can happen under security definer functions or when a common user and query is planned initially and then re-used across multiple SET ROLEs. Applying an incorrect policy may permit a user to complete otherwise-forbidden reads and modifications. This affects only databases that have used CREATE POLICY to define a row security policy. An attacker must tailor an attack to a particular application's pattern of query plan reuse, user ID changes, and role-specific row security policies. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected.

Fixed in this branch: 12.21. Component: core server.

Official affected-branch entry: 12.

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

Release-note mentions:

CVE-2024-0985 · PostgreSQL non-owner REFRESH MATERIALIZED VIEW CONCURRENTLY executes arbitrary SQL CVSS 8.0

UPDATE (June 19, 2024) : Added v16 as impacted. Updated description to clarify the attack vector. Late privilege drop in REFRESH MATERIALIZED VIEW CONCURRENTLY in PostgreSQL allows an object creator to execute arbitrary SQL functions as the command issuer. The command intends to run SQL functions as the owner of the materialized view, enabling safe refresh of untrusted materialized views. The victim is a superuser or member of one of the attacker's roles. The attack requires luring the victim into running REFRESH MATERIALIZED VIEW CONCURRENTLY on the attacker's materialized view.

Fixed in this branch: 12.18. Component: core server.

Official affected-branch entry: 12.

AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2023-5870 · Role "pg_signal_backend" can signal certain superuser processes CVSS 2.2

Documentation says the pg_signal_backend role cannot signal "a backend owned by a superuser". On the contrary, it can signal background workers, including the logical replication launcher. It can signal autovacuum workers and the autovacuum launcher. Signaling autovacuum workers and those two launchers provides no meaningful exploit, so exploiting this vulnerability requires a non-core extension with a less-resilient background worker. For example, a non-core background worker that does not auto-restart would experience a denial of service with respect to that particular background worker. The PostgreSQL project thanks Hemanth Sandrana and Mahendrakar Srinivasarao for reporting this problem.

Fixed in this branch: 12.17. Component: core server.

Official affected-branch entry: 12.

AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L

Release-note mentions:

CVE-2023-5869 · Buffer overrun from integer overflow in array modification CVSS 8.8

While modifying certain SQL array values, missing overflow checks let authenticated database users write arbitrary bytes to a memory area that facilitates arbitrary code execution. Missing overflow checks also let authenticated database users read a wide area of server memory. The CVE-2021-32027 fix covered some attacks of this description, but it missed others. The PostgreSQL project thanks Pedro Gallegos for reporting this problem.

Fixed in this branch: 12.17. Component: core server.

Official affected-branch entry: 12.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2023-5868 · Memory disclosure in aggregate function calls CVSS 4.3

Certain aggregate function calls receiving "unknown"-type arguments could disclose bytes of server memory from the end of the "unknown"-type value to the next zero byte. One typically gets an "unknown"-type value via a string literal having no type designation. We have not confirmed or ruled out viability of attacks that arrange for presence of notable, confidential information in disclosed bytes. The PostgreSQL project thanks Jingzhou Fu for reporting this problem.

Fixed in this branch: 12.17. Component: core server.

Official affected-branch entry: 12.

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2023-39417 · Extension script @substitutions@ within quoting allow SQL injection CVSS 7.5

An extension script is vulnerable if it uses @extowner@ , @extschema@ , or @extschema:...@ inside a quoting construct (dollar quoting, '' , or "" ). No bundled extension is vulnerable. Vulnerable uses do appear in a documentation example and in non-bundled extensions. Hence, the attack prerequisite is an administrator having installed files of a vulnerable, trusted, non-bundled extension. Subject to that prerequisite, this enables an attacker having database-level CREATE privilege to execute arbitrary code as the bootstrap superuser. PostgreSQL will block this attack in the core server, so there's no need to modify individual extensions. The PostgreSQL project thanks Micah Gates, Valerie Woolard, Tim Carey-Smith, and Christoph Berg for reporting this problem.

Fixed in this branch: 12.16. Component: core server.

Official affected-branch entry: 12.

AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2023-2455 · Row security policies disregard user ID changes after inlining CVSS 4.2

While CVE-2016-2193 fixed most interaction between row security and user ID changes, it missed a scenario involving function inlining. This leads to potentially incorrect policies being applied in cases where role-specific policies are used and a given query is planned under one role and then executed under other roles. This scenario can happen under security definer functions or when a common user and query is planned initially and then re-used across multiple SET ROLE s. Applying an incorrect policy may permit a user to complete otherwise-forbidden reads and modifications. This affects only databases that have used CREATE POLICY to define a row security policy. The PostgreSQL project thanks Wolfgang Walther for reporting this problem.

Fixed in this branch: 12.15. Component: core server.

Official affected-branch entry: 12.

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

Release-note mentions:

CVE-2023-2454 · CREATE SCHEMA ... schema_element defeats protective search_path changes CVSS 7.2

This enabled an attacker having database-level CREATE privilege to execute arbitrary code as the bootstrap superuser. Database owners have that right by default, and explicit grants may extend it to other users. The PostgreSQL project thanks Alexander Lakhin for reporting this problem.

Fixed in this branch: 12.15. Component: core server.

Official affected-branch entry: 12.

AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2022-41862 · Client memory disclosure when connecting, with Kerberos, to modified server CVSS 3.7

A modified, unauthenticated server can send an unterminated string during the establishment of Kerberos transport encryption. When a libpq client application has a Kerberos credential cache and doesn't explicitly disable option gssencmode , a server can cause libpq to over-read and report an error message containing uninitialized bytes from and following its receive buffer. If libpq's caller somehow makes that message accessible to the attacker, this achieves a disclosure of the over-read bytes. We have not confirmed or ruled out viability of attacks that arrange for a crash or for presence of notable, confidential information in disclosed bytes. The PostgreSQL project thanks Jacob Champion for reporting this problem.

Fixed in this branch: 12.14. Component: client.

Official affected-branch entry: 12.

AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2022-2625 · Extension scripts replace objects not belonging to the extension CVSS 7.1

Some extensions use CREATE OR REPLACE or CREATE IF NOT EXISTS commands. Some don't adhere to the documented rule to target only objects known to be extension members already. An attack requires permission to create non-temporary objects in at least one schema, ability to lure or wait for an administrator to create or update an affected extension in that schema, and ability to lure or wait for a victim to use the object targeted in CREATE OR REPLACE or CREATE IF NOT EXISTS . Given all three prerequisites, the attacker can run arbitrary code as the victim role, which may be a superuser. Known-affected extensions include both PostgreSQL-bundled and non-bundled extensions. PostgreSQL is blocking this attack in the core server, so there's no need to modify individual extensions. The PostgreSQL project thanks Sven Klemm for reporting this problem.

Fixed in this branch: 12.12. Component: core server.

Official affected-branch entry: 12.

AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2022-1552 · Autovacuum, REINDEX, and others omit "security restricted operation" sandbox CVSS 8.8

Autovacuum, REINDEX , CREATE INDEX , REFRESH MATERIALIZED VIEW , CLUSTER , and pg_amcheck made incomplete efforts to operate safely when a privileged user is maintaining another user's objects. Those commands activated relevant protections too late or not at all. An attacker having permission to create non-temp objects in at least one schema could execute arbitrary SQL functions under a superuser identity. While promptly updating PostgreSQL is the best remediation for most users, a user unable to do that can work around the vulnerability by disabling autovacuum, not manually running the above commands, and not restoring from output of the pg_dump command. Performance may degrade quickly under this workaround. VACUUM is safe, and all commands are fine when a trusted user owns the target object. The PostgreSQL project thanks Alexander Lakhin for reporting this problem.

Fixed in this branch: 12.11. Component: core server.

Official affected-branch entry: 12.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2021-3677 · Memory disclosure in certain queries CVSS 6.5

A purpose-crafted query can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can complete this attack at will. The attack does not require the ability to create objects. If server settings include max_worker_processes=0 , the known versions of this attack are infeasible. However, undiscovered variants of the attack may be independent of that setting.

Fixed in this branch: 12.8. Component: core server.

Official affected-branch entry: 12.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Release-note mentions:

CVE-2021-3449 · CVE-2021-3449

No fixed version for this branch is recorded.

Release-note mentions:

CVE-2021-3393 · Partition constraint violation errors leak values of denied columns CVSS 3.1

A user having an UPDATE privilege on a partitioned table but lacking the SELECT privilege on some column may be able to acquire denied-column values from an error message. This is similar to CVE-2014-8161 , but the conditions to exploit are more rare. The PostgreSQL project thanks Heikki Linnakangas for reporting this problem.

Fixed in this branch: 12.6. Component: core server.

Official affected-branch entry: 12.

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2021-32029 · Memory disclosure in partitioned-table UPDATE ... RETURNING CVSS 6.5

Using an UPDATE ... RETURNING on a purpose-crafted partitioned table, an attacker can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can create prerequisite objects and complete this attack at will. A user lacking the CREATE and TEMPORARY privileges on all databases and the CREATE privilege on all schemas typically cannot use this attack at will. The PostgreSQL project thanks Tom Lane for reporting this problem.

Fixed in this branch: 12.7. Component: core server.

Official affected-branch entry: 12.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Release-note mentions:

CVE-2021-32028 · Memory disclosure in INSERT ... ON CONFLICT ... DO UPDATE CVSS 6.5

Using an INSERT ... ON CONFLICT ... DO UPDATE command on a purpose-crafted table, an attacker can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can create prerequisite objects and complete this attack at will. A user lacking the CREATE and TEMPORARY privileges on all databases and the CREATE privilege on all schemas cannot use this attack at will. The PostgreSQL project thanks Andres Freund for reporting this problem.

Fixed in this branch: 12.7. Component: core server.

Official affected-branch entry: 12.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Release-note mentions:

CVE-2021-32027 · Buffer overrun from integer overflow in array subscripting calculations CVSS 6.5

While modifying certain SQL array values, missing bounds checks let authenticated database users write arbitrary bytes to a wide area of server memory. The PostgreSQL project thanks Tom Lane for reporting this problem.

Fixed in this branch: 12.7. Component: core server.

Official affected-branch entry: 12.

AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Release-note mentions:

CVE-2021-23222 · libpq processes unencrypted bytes from man-in-the-middle CVSS 3.7

A man-in-the-middle attacker can inject false responses to the client's first few queries, despite the use of SSL certificate verification and encryption. If more preconditions hold, the attacker can exfiltrate the client's password or other confidential data that might be transmitted early in a session. The attacker must have a way to trick the client's intended server into making the confidential data accessible to the attacker. A known implementation having that property is a PostgreSQL configuration vulnerable to CVE-2021-23214 . As with any exploitation of CVE-2021-23214 , the server must be using trust authentication with a clientcert requirement or using cert authentication. To disclose a password, the client must be in possession of a password, which is atypical when using an authentication configuration vulnerable to CVE-2021-23214 . The attacker must have some other way to access the server to retrieve the exfiltrated data (a valid, unprivileged login account would be sufficient). The PostgreSQL project thanks Jacob Champion for reporting this problem.

Fixed in this branch: 12.9. Component: client.

Official affected-branch entry: 12.

AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2021-23214 · Server processes unencrypted bytes from man-in-the-middle CVSS 8.1

When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption. This is similar to CVE-2011-0411 (different product). The PostgreSQL project thanks Jacob Champion for reporting this problem.

Fixed in this branch: 12.9. Component: core server.

Official affected-branch entry: 12.

AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2020-25696 · psql's \gset allows overwriting specially treated variables CVSS 7.5

The \gset meta-command, which sets psql variables based on query results, does not distinguish variables that control psql behavior. If an interactive psql session uses \gset when querying a compromised server, the attacker can execute arbitrary code as the operating system account running psql . Using \gset with a prefix not found among specially treated variables, e.g. any lowercase string, precludes the attack in an unpatched psql . The PostgreSQL project thanks Nick Cleaton for reporting this problem.

Fixed in this branch: 12.5. Component: client.

Official affected-branch entry: 12.

AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2020-25695 · Multiple features escape "security restricted operation" sandbox CVSS 8.8

An attacker having permission to create non-temporary objects in at least one schema can execute arbitrary SQL functions under the identity of a superuser. While promptly updating PostgreSQL is the best remediation for most users, a user unable to do that can work around the vulnerability by disabling autovacuum and not manually running ANALYZE , CLUSTER , REINDEX , CREATE INDEX , VACUUM FULL , REFRESH MATERIALIZED VIEW , or a restore from output of the pg_dump command. Performance may degrade quickly under this workaround. VACUUM without the FULL option is safe, and all commands are fine when a trusted user owns the target object. The PostgreSQL project thanks Etienne Stalmans for reporting this problem.

Fixed in this branch: 12.5. Component: core server.

Official affected-branch entry: 12.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2020-25694 · Reconnection can downgrade connection security settings CVSS 8.1

Many PostgreSQL-provided client applications have options that create additional database connections. Some of those applications reuse only the basic connection parameters (e.g. host , user , port ), dropping others. If this drops a security-relevant parameter (e.g. channel_binding , sslmode , requirepeer , gssencmode ), the attacker has an opportunity to complete a MITM attack or observe cleartext transmission. Affected applications are clusterdb , pg_dump , pg_restore , psql , reindexdb , and vacuumdb . The vulnerability arises only if one invokes an affected client application with a connection string containing a security-relevant parameter. This also fixes how the \connect command of psql reuses connection parameters, i.e. all non-overridden parameters from a previous connection string now re-used. The PostgreSQL project thanks Peter Eisentraut for reporting this problem.

Fixed in this branch: 12.5. Component: client.

Official affected-branch entry: 12.

AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2020-1720 · ALTER ... DEPENDS ON EXTENSION is missing authorization checks. CVSS 3.1

The ALTER ... DEPENDS ON EXTENSION sub-commands do not perform authorization checks, which can allow an unprivileged user to drop any function, procedure, materialized view, index, or trigger under certain conditions. This attack is possible if an administrator has installed an extension and an unprivileged user can CREATE , or an extension owner either executes DROP EXTENSION predictably or can be convinced to execute DROP EXTENSION . The PostgreSQL project thanks Tom Lane for reporting this problem.

Fixed in this branch: 12.2. Component: core server.

Official affected-branch entry: 12.

AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N

Release-note mentions:

CVE-2020-14350 · Uncontrolled search path element in CREATE EXTENSION CVSS 7.1

When a superuser runs certain CREATE EXTENSION statements, users may be able to execute arbitrary SQL functions under the identity of that superuser. The attacker must have permission to create objects in the new extension's schema or a schema of a prerequisite extension. Not all extensions are vulnerable. In addition to correcting the extensions provided with PostgreSQL, the PostgreSQL Global Development Group is issuing guidance for third-party extension authors to secure their own work. The PostgreSQL project thanks Andres Freund for reporting this problem.

Fixed in this branch: 12.4. Component: core server.

Official affected-branch entry: 12.

AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2020-14349 · Uncontrolled search path element in logical replication CVSS 7.5

The PostgreSQL search_path setting determines schemas searched for tables, functions, operators, etc. The CVE-2018-1058 fix caused most PostgreSQL-provided client applications to sanitize search_path , but logical replication continued to leave search_path unchanged. Users of a replication publisher or subscriber database can create objects in the public schema and harness them to execute arbitrary SQL functions under the identity running replication, often a superuser. Installations having adopted a documented secure schema usage pattern are not vulnerable. The PostgreSQL project thanks Noah Misch for reporting this problem.

Fixed in this branch: 12.4. Component: core server.

Official affected-branch entry: 12.

AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2020-10733 · Windows installer runs executables from uncontrolled directories CVSS 6.7

The Windows installer for PostgreSQL invokes system-provided executables that do not have fully-qualified paths. Executables in the directory where the installer loads or the current working directory take precedence over the intended executables. An attacker having permission to add files into one of those directories can use this to execute arbitrary code with the installer's administrative rights. The PostgreSQL project thanks Hou JingYi (@hjy79425575) for reporting this problem.

Fixed in this branch: 12.3. Component: packaging.

Official affected-branch entry: 12.

AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

CVE-2019-3466 · pg_ctlcluster script in postgresql-common does not drop privileges when creating socket/statistics temporary directories CVSS 8.4

A PostgreSQL superuser could escalate to root using a deficiency in the pg_ctlcluster command. pg_ctlcluster is a utility provided by the "postgresql-common" package that is installed with PostgreSQL on Debian and Ubuntu platforms.

Fixed in this branch: 12.1. Component: packaging.

Official affected-branch entry: 12.

AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H

CVE-2018-1058 · Uncontrolled search path element in pg_dump and other client applications CVSS 8.8

No fixed version for this branch is recorded. Component: client.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2017-7484 · selectivity estimators bypass SELECT privilege checks CVSS 4.3

No fixed version for this branch is recorded. Component: core server.

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2006-2313 · An attacker able to submit crafted strings to an application that will embed those strings in SQL commands can use invalidly-encoded multibyte characters to bypass standard string-escaping methods, resulting in possible SQL injection.

Export this branch as JSON · Compare any two indexed releases