{"format": 1, "mode": "release", "from_release": null, "to_release": {"date": "2025-02-20", "build": "17.4", "major": "17", "minor": 4, "manual": "17", "status": "stable", "doc_git": "", "version": "17.4", "eol_date": "2029-11-08", "date_text": "2025-02-20", "supported": true, "manual_url": "/docs/17/release-17-4.html", "source_url": "/docs/release/17.4/", "entry_count": 3, "placeholder": false, "content_hash": "13d99a993508f878b13d14e8e0bf3c5ea9a47998b967b844c83f32020c2e9d04", "manual_build": "17.11", "source_as_of": "", "changes_count": 3, "doc_loaded_at": "2026-09-26T02:56:35.922301", "migration_html": "<p>对于运行 17.X 的用户，无需执行转储/恢复。</p>\n<p>不过，如果你是从早于 17.1 的版本升级，请参见<a href=\"/docs/17/release-17-1.html\" title=\"E.11. 17.1 发布\">第 E.11 节</a>。</p>", "compatibility_count": 0, "label": "17.4", "status_label": "受支持版本", "eol": "2029-11-08", "age_days": 587, "support_days": 1135}, "groups": [{"date": "2025-02-20", "build": "17.4", "major": "17", "minor": 4, "manual": "17", "status": "stable", "doc_git": "", "version": "17.4", "eol_date": "2029-11-08", "date_text": "2025-02-20", "supported": true, "manual_url": "/docs/17/release-17-4.html", "source_url": "/docs/release/17.4/", "entry_count": 3, "placeholder": false, "content_hash": "13d99a993508f878b13d14e8e0bf3c5ea9a47998b967b844c83f32020c2e9d04", "manual_build": "17.11", "source_as_of": "", "changes_count": 3, "doc_loaded_at": "2026-09-26T02:56:35.922301", "migration_html": "<p>对于运行 17.X 的用户，无需执行转储/恢复。</p>\n<p>不过，如果你是从早于 17.1 的版本升级，请参见<a href=\"/docs/17/release-17-1.html\" title=\"E.11. 17.1 发布\">第 E.11 节</a>。</p>", "compatibility_count": 0, "label": "17.4", "status_label": "受支持版本", "eol": "2029-11-08", "age_days": 587, "support_days": 1135, "entries": [{"id": "17.4-d477ecad89a3b81e", "cves": ["CVE-2025-1094"], "html": "<p>改进 <span>libpq</span> 引用函数的行为（Andres Freund，Tom Lane）<a href=\"https://postgr.es/c/a92db3d02\">§</a> <a href=\"https://postgr.es/c/3abe6e04c\">§</a> <a href=\"https://postgr.es/c/3977bd298\">§</a></p>\n<p>为 CVE-2025-1094 所做的修改有一个严重的疏忽：<code>PQescapeLiteral()</code> 和 <code>PQescapeIdentifier()</code> 未能遵循其字符串长度参数，而是始终读取到输入字符串的末尾空字符。这导致在调用者打算通过长度参数截断字符串时，输出中包含了不需要的文本。在极端不幸的情况下，可能因读取超出内存末尾而导致崩溃。</p>\n<p>此外，修改了所有这些引用函数，使得在检测到无效编码时，仅替换假定字符的第一个字节为无效序列，而不是全部字节。这降低了在调用应用程序对引用后的字符串进行额外处理时出现问题的风险。</p>", "text": "改进 libpq 引用函数的行为（Andres Freund，Tom Lane）§ § § 为 CVE-2025-1094 所做的修改有一个严重的疏忽：PQescapeLiteral() 和 PQescapeIdentifier() 未能遵循其字符串长度参数，而是始终读取到输入字符串的末尾空字符。这导致在调用者打算通过长度参数截断字符串时，输出中包含了不需要的文本。在极端不幸的情况下，可能因读取超出内存末尾而导致崩溃。 此外，修改了所有这些引用函数，使得在检测到无效编码时，仅替换假定字符的第一个字节为无效序列，而不是全部字节。这降低了在调用应用程序对引用后的字符串进行额外处理时出现问题的风险。", "title": "改进 libpq 引用函数的行为", "commits": ["3977bd298", "3abe6e04c", "a92db3d02"], "section": "变更", "category": "security", "source_url": "/docs/release/17.4/#RELEASE-17-4-CHANGES", "source_hash": "df5454038007b88df8733584820a457d3ac17a4a51865df26d72027ea3fcd906", "section_path": ["变更"], "commit_groups": [["111f4dd27", "1f7a05324", "22ffbbf24", "985908df1", "a92db3d02", "efdadeb22"], ["2226a2e26", "3977bd298", "644b7d686", "9f052613e", "a7f95859e", "f864a4cdf"], ["3abe6e04c", "991a60a9f", "9f45e6a91", "c08309584", "d6d29b213", "e782a63cc"]], "identity_text": "Improve behavior of libpq's quoting functions (Andres Freund, Tom Lane) The changes made for CVE-2025-1094 had one serious oversight: PQescapeLiteral() and PQescapeIdentifier() failed to honor their string length parameter, instead always reading to the input string's trailing null. This resulted in including unwanted text in the output, if the caller intended to truncate the string via the length parameter. With very bad luck it could cause a crash due to reading off the end of memory. In addition, modify all these quoting functions so that when invalid encoding is detected, an invalid sequence is substituted for just the first byte of the presumed character, not all of it. This reduces the risk of problems if a calling application performs additional processing on the quoted string.", "commit_aliases": ["111f4dd27", "1f7a05324", "2226a2e26", "22ffbbf24", "3977bd298", "3abe6e04c", "644b7d686", "985908df1", "991a60a9f", "9f052613e", "9f45e6a91", "a7f95859e", "a92db3d02", "c08309584", "d6d29b213", "e782a63cc", "efdadeb22", "f864a4cdf"], "source_commits": ["3977bd298", "3abe6e04c", "a92db3d02"], "source_entry_id": "17.4/changes/001", "db_id": "c7960ab441796e11f499e5bba716166e", "patch_ids": ["0e981f968b952d9cf7d0d6a3a22cc247", "6f7805d8e67721bf35bd17443b6b5f5d", "b0ea6cce1c2d6113f422ff8aee23ccfc"], "statement_hash": "82ceafbe009cc55c8bbb783c79cd0468287302477d70ae849a35027e0bec658e", "relations": [{"rule": 2, "type": "equivalent", "target": "10e97b40c924a8c01435396c5cec5c41", "evidence": {"same_day": true, "patch_ids": ["0e981f968b952d9cf7d0d6a3a22cc247", "6f7805d8e67721bf35bd17443b6b5f5d", "b0ea6cce1c2d6113f422ff8aee23ccfc"], "statement_hash": "82ceafbe009cc55c8bbb783c79cd0468287302477d70ae849a35027e0bec658e"}}, {"rule": 2, "type": "equivalent", "target": "4646f216ed794505b943757978907404", "evidence": {"same_day": true, "patch_ids": ["0e981f968b952d9cf7d0d6a3a22cc247", "6f7805d8e67721bf35bd17443b6b5f5d", "b0ea6cce1c2d6113f422ff8aee23ccfc"], "statement_hash": "82ceafbe009cc55c8bbb783c79cd0468287302477d70ae849a35027e0bec658e"}}, {"rule": 2, "type": "equivalent", "target": "93606c971fb27b15f66a071ba02ed94f", "evidence": {"same_day": true, "patch_ids": ["0e981f968b952d9cf7d0d6a3a22cc247", "6f7805d8e67721bf35bd17443b6b5f5d", "b0ea6cce1c2d6113f422ff8aee23ccfc"], "statement_hash": "82ceafbe009cc55c8bbb783c79cd0468287302477d70ae849a35027e0bec658e"}}, {"rule": 2, "type": "equivalent", "target": "9f693cbaa1b27909dc5ea6b2372ebffc", "evidence": {"same_day": true, "patch_ids": ["0e981f968b952d9cf7d0d6a3a22cc247", "6f7805d8e67721bf35bd17443b6b5f5d", "b0ea6cce1c2d6113f422ff8aee23ccfc"], "statement_hash": "82ceafbe009cc55c8bbb783c79cd0468287302477d70ae849a35027e0bec658e"}}], "version": "17.4", "category_label": "安全相关", "also_in": [], "variants": [], "related_changes": [{"db_id": "10e97b40c924a8c01435396c5cec5c41", "kind": "equivalent", "version": "16.8", "label": "16.8", "title": "改进 libpq 引用函数的行为", "evidence": {"same_day": true, "patch_ids": ["0e981f968b952d9cf7d0d6a3a22cc247", "6f7805d8e67721bf35bd17443b6b5f5d", "b0ea6cce1c2d6113f422ff8aee23ccfc"], "statement_hash": "82ceafbe009cc55c8bbb783c79cd0468287302477d70ae849a35027e0bec658e"}, "url": "/docs/compare/?release=16.8#16.8-37cc8c2afc9a961e", "source_url": "/docs/release/16.8/#RELEASE-16-8-CHANGES"}, {"db_id": "4646f216ed794505b943757978907404", "kind": "equivalent", "version": "15.12", "label": "15.12", "title": "改进 libpq 引用函数的行为", "evidence": {"same_day": true, "patch_ids": ["0e981f968b952d9cf7d0d6a3a22cc247", "6f7805d8e67721bf35bd17443b6b5f5d", "b0ea6cce1c2d6113f422ff8aee23ccfc"], "statement_hash": "82ceafbe009cc55c8bbb783c79cd0468287302477d70ae849a35027e0bec658e"}, "url": "/docs/compare/?release=15.12#15.12-43f9b4124d940cad", "source_url": "/docs/release/15.12/#ZH-AUTO-RELEASE-15-SECT2-12"}, {"db_id": "93606c971fb27b15f66a071ba02ed94f", "kind": "equivalent", "version": "14.17", "label": "14.17", "title": "改进 libpq 引用函数的行为", "evidence": {"same_day": true, "patch_ids": ["0e981f968b952d9cf7d0d6a3a22cc247", "6f7805d8e67721bf35bd17443b6b5f5d", "b0ea6cce1c2d6113f422ff8aee23ccfc"], "statement_hash": "82ceafbe009cc55c8bbb783c79cd0468287302477d70ae849a35027e0bec658e"}, "url": "/docs/compare/?release=14.17#14.17-5608e94c3b2dd6d1", "source_url": "/docs/release/14.17/#ZH-AUTO-RELEASE-14-SECT2-12"}, {"db_id": "9f693cbaa1b27909dc5ea6b2372ebffc", "kind": "equivalent", "version": "13.20", "label": "13.20", "title": "改进 libpq 引用函数的行为", "evidence": {"same_day": true, "patch_ids": ["0e981f968b952d9cf7d0d6a3a22cc247", "6f7805d8e67721bf35bd17443b6b5f5d", "b0ea6cce1c2d6113f422ff8aee23ccfc"], "statement_hash": "82ceafbe009cc55c8bbb783c79cd0468287302477d70ae849a35027e0bec658e"}, "url": "/docs/compare/?release=13.20#13.20-27312e34c6df83be", "source_url": "/docs/release/13.20/#id-1.11.6.9.6"}]}, {"id": "17.4-e0c81d2cba126652", "cves": [], "html": "<p>修复 <span>pg_createsubscriber</span> 中的轻微内存泄漏（Ranier Vilela）<a href=\"https://postgr.es/c/ff6d9cfcb\">§</a></p>", "text": "修复 pg_createsubscriber 中的轻微内存泄漏（Ranier Vilela）§", "title": "修复 pg_createsubscriber 中的轻微内存泄漏", "commits": ["ff6d9cfcb"], "section": "变更", "category": "bugfix", "source_url": "/docs/release/17.4/#RELEASE-17-4-CHANGES", "source_hash": "073a114dab6fe74cf6560ff8ec461b817b393df59b97f84635889267d27cdcd6", "section_path": ["变更"], "commit_groups": [["5b94e2753", "ff6d9cfcb"]], "identity_text": "Fix small memory leak in pg_createsubscriber (Ranier Vilela)", "commit_aliases": ["5b94e2753", "ff6d9cfcb"], "source_commits": ["ff6d9cfcb"], "source_entry_id": "17.4/changes/002", "db_id": "285be6e0e7a74086c0b57f74d1b0ff80", "patch_ids": ["c1239f7bac6a8a540403b6538c9eec5d"], "statement_hash": "a256c57eadaf80bcdda9ec79418d7a98a24f6675a91f9e1d4b7846e393d4187e", "relations": [], "version": "17.4", "category_label": "BUG 修复", "also_in": [], "variants": [], "related_changes": []}, {"id": "17.4-1a6bc652fff7cf0a", "cves": [], "html": "<p>修复 meson 构建系统以正确检测 <code>bsd_auth.h</code> 系统头文件的可用性（Nazir Bilal Yavuz）<a href=\"https://postgr.es/c/c9a1d2135\">§</a></p>", "text": "修复 meson 构建系统以正确检测 bsd_auth.h 系统头文件的可用性（Nazir Bilal Yavuz）§", "title": "修复 meson 构建系统以正确检测 bsd_auth.h 系统头文件的可用性", "commits": ["c9a1d2135"], "section": "变更", "category": "bugfix", "source_url": "/docs/release/17.4/#RELEASE-17-4-CHANGES", "source_hash": "f1132bd20ed901b3818c8e83245485c4d2597cc573b4348ce38ec44f93d57241", "section_path": ["变更"], "commit_groups": [["01cdb98e4", "b64d83115", "c9a1d2135"]], "identity_text": "Fix meson build system to correctly detect availability of the bsd_auth.h system header (Nazir Bilal Yavuz)", "commit_aliases": ["01cdb98e4", "b64d83115", "c9a1d2135"], "source_commits": ["c9a1d2135"], "source_entry_id": "17.4/changes/003", "db_id": "9fc8fdde993a4a48701d10e07034570f", "patch_ids": ["61b1915751100c13bd760999fb17ec00"], "statement_hash": "d3d3194505718a731f276d47517f983f0dda2b954325e29cd9a0fe9452bb30c6", "relations": [{"rule": 2, "type": "equivalent", "target": "597a9c1610cbb9c827ee1a00c45c22e2", "evidence": {"same_day": true, "patch_ids": ["61b1915751100c13bd760999fb17ec00"], "statement_hash": "d3d3194505718a731f276d47517f983f0dda2b954325e29cd9a0fe9452bb30c6"}}], "version": "17.4", "category_label": "BUG 修复", "also_in": [], "variants": [], "related_changes": [{"db_id": "597a9c1610cbb9c827ee1a00c45c22e2", "kind": "equivalent", "version": "16.8", "label": "16.8", "title": "修复 meson 构建系统以正确检测 bsd_auth.h 系统头文件的可用性", "evidence": {"same_day": true, "patch_ids": ["61b1915751100c13bd760999fb17ec00"], "statement_hash": "d3d3194505718a731f276d47517f983f0dda2b954325e29cd9a0fe9452bb30c6"}, "url": "/docs/compare/?release=16.8#16.8-18729901882dd169", "source_url": "/docs/release/16.8/#RELEASE-16-8-CHANGES"}]}]}], "stats": [{"key": "all", "label": "全部变更", "count": 3}, {"key": "feature", "label": "新功能", "count": 0}, {"key": "bugfix", "label": "BUG 修复", "count": 2}, {"key": "security", "label": "安全相关", "count": 1}, {"key": "performance", "label": "性能改进", "count": 0}, {"key": "compatibility", "label": "兼容性变化", "count": 0}, {"key": "improvement", "label": "其他改进", "count": 0}], "total": 3, "release_count": 1, "cross_major": false, "cve_count": 1, "cves": [{"id": "CVE-2025-1094", "url": "https://www.postgresql.org/support/security/CVE-2025-1094/", "fixed": {"13": "13.19", "14": "14.16", "15": "15.11", "16": "16.7", "17": "17.3"}, "score": 8.1, "title": "改进 libpq 引用函数的行为", "vector": "AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", "cna_url": "https://cveawg.mitre.org/api/cve/CVE-2025-1094", "affected": {"13": "13", "14": "14", "15": "15", "16": "16", "17": "17"}, "component": "core server", "published": {"13": "2025-02-13", "14": "2025-02-13", "15": "2025-02-13", "16": "2025-02-13", "17": "2025-02-13"}, "introduced": {}, "cvss_version": "3.0", "description_en": "Improper neutralization of quoting syntax in PostgreSQL libpq functions PQescapeLiteral(), PQescapeIdentifier(), PQescapeString(), and PQescapeStringConn() allows a database input provider to achieve SQL injection in certain usage patterns. Specifically, SQL injection requires the application to use the function result to construct input to psql, the PostgreSQL interactive terminal. Similarly, improper neutralization of quoting syntax in PostgreSQL command line utility programs allows a source of command line arguments to achieve SQL injection when client_encoding is BIG5 and server_encoding is one of EUC_TW or MULE_INTERNAL. Versions before PostgreSQL 17.3, 16.7, 15.11, 14.16, and 13.19 are affected.", "affected_ranges": [{"from": "0", "until": "13.19"}, {"from": "14", "until": "14.16"}, {"from": "15", "until": "15.11"}, {"from": "16", "until": "16.7"}, {"from": "17", "until": "17.3"}], "first_published": "2025-02-13", "fixed_version": "17.3"}], "cve_available": true, "remaining_cves": [], "security_regressions": [], "warnings": [], "candidate_count": 3, "already_in_source_count": 0, "duplicate_count": 0, "excluded_count": 0, "exclusions": [], "source_as_of": "2026-09-26", "security_as_of": "2026-09-26"}