PostgreSQL 11
已停止支持 · 记录构建 11.22 · 2023-11-09
此大版本已停止支持,相关记录用于查阅历史;没有更新的安全记录不代表仍可安全运行。
- 首次正式发布
- 2018-10-18
- 支持结束
- 2023-11-09
- 已收录发布版本
- 23
- 原始发布说明条目
- 1141
手册与来源
PostgreSQL 11 本站手册 · 已加载 1049 页。
手册加载时间:2026-09-27T00:10:45.258078。
发布说明快照:2026-09-26。安全证据快照:2026-09-26。PDF 链接按本地文件是否存在提供,历史版本的语言与 HTML 手册可能不同。生命周期参见官方版本政策。
升级注意事项
跨大版本升级需要导出/恢复或 pg_upgrade 等迁移方式,应阅读沿途大版本的发布说明与目标版本手册。小版本更新也可能要求额外操作,请核对对应发布的迁移说明。官方升级政策。
11.0 的原始迁移说明
对于希望从任何先前版本迁移数据的用户,需要使用pg_dumpall进行导出/恢复,或使用pg_upgrade或逻辑复制。有关迁移到新主版本的一般信息,请参见第 18.6 节。
版本 11 包含许多可能影响与先前版本兼容性的变更。请注意以下不兼容性:
发布历史
每次发布的原始变更均独立保留。CVE 数量表示发布说明中的提及,可能包含后续纠正,不等于本次新修复漏洞数。
| 版本 | 日期/快照截止时间 | 全部变化 | BUG 修复 | 迁移条目 | 提及 CVE |
|---|---|---|---|---|---|
| 11.22 | 2023-11-09 | 31 | 10 | 0 | 3 |
| 11.21 | 2023-08-10 | 29 | 11 | 0 | 1 |
| 11.20 | 2023-05-11 | 44 | 22 | 0 | 2 |
| 11.19 | 2023-02-09 | 29 | 12 | 0 | 0 |
| 11.18 | 2022-11-10 | 32 | 15 | 0 | 0 |
| 11.17 | 2022-08-11 | 37 | 14 | 0 | 2 |
| 11.16 | 2022-05-12 | 32 | 16 | 0 | 1 |
| 11.15 | 2022-02-10 | 29 | 13 | 0 | 0 |
| 11.14 | 2021-11-11 | 58 | 27 | 0 | 2 |
| 11.13 | 2021-08-12 | 63 | 20 | 0 | 3 |
| 11.12 | 2021-05-13 | 33 | 17 | 0 | 3 |
| 11.11 | 2021-02-11 | 56 | 26 | 0 | 1 |
| 11.10 | 2020-11-12 | 46 | 17 | 0 | 3 |
| 11.9 | 2020-08-13 | 43 | 22 | 0 | 3 |
| 11.8 | 2020-05-14 | 55 | 23 | 0 | 0 |
| 11.7 | 2020-02-13 | 56 | 29 | 0 | 2 |
| 11.6 | 2019-11-14 | 67 | 31 | 0 | 0 |
| 11.5 | 2019-08-08 | 47 | 18 | 0 | 3 |
| 11.4 | 2019-06-20 | 26 | 16 | 0 | 1 |
| 11.3 | 2019-05-09 | 63 | 40 | 0 | 3 |
| 11.2 | 2019-02-14 | 73 | 37 | 0 | 0 |
| 11.1 | 2018-11-08 | 22 | 12 | 0 | 1 |
| 11.0 | 2018-10-18 | 170 | 1 | 20 | 0 |
首次发布变化
11.0 的原始条目,包含功能和兼容性变化。类别用于浏览,不是上游原始分类。
匹配 170 / 170 条原始变更。
使pg_dump转储数据库的属性,而不只是内容 · 兼容性变化 · 迁移说明
使pg_dump转储数据库的属性,而不只是内容(Haribabu Kommi)
以前,数据库本身的属性,例如数据库级
GRANT/REVOKE权限和ALTER DATABASE SET变量设置,只能由pg_dumpall转储。现在,pg_dump --create和pg_restore --create除恢复数据库内的对象外,也会恢复这些数据库属性。pg_dumpall -g现在仅转储角色和表空间相关属性。pg_dumpall 的完整输出(不带-g)保持不变。如果没有指定
--create,pg_dump 和 pg_restore 不再转储/恢复数据库级注释和安全标签;这些内容现在被视为数据库的属性。pg_dumpall 的输出脚本现在始终使用数据库原有的区域设置和编码创建数据库,因此如果目标系统不认识该区域设置或编码名称,操作就会失败。以前,如果数据库的区域设置和编码与旧集群的默认值一致,输出的
CREATE DATABASE就不会包含这些指定。pg_dumpall --clean现在会恢复postgres和template1数据库的原始区域设置和编码,以及用户创建数据库的相应设置。原始发布条目 ·
11.0/migration/001在消除函数引用与列引用之间的歧义时,考虑语法形式 · 兼容性变化 · 迁移说明
在消除函数引用与列引用之间的歧义时,考虑语法形式(Tom Lane)
当
x是表名或复合列时,PostgreSQL 传统上将语法形式和f(x)视为等价,从而允许编写函数后,将其当作按需求值的列来使用。然而,如果两种解释都可行,以前总会选择列解释;当用户本意是调用函数时,这会产生意外结果。现在,若存在歧义,会选择与语法形式相符的解释。x.f原始发布条目 ·
11.0/migration/002全面强制表约束名和域约束名的唯一性 · 兼容性变化 · 迁移说明
全面强制表约束名和域约束名的唯一性(Tom Lane)
PostgreSQL 要求同一表的约束名称各不相同,域的约束名称也是如此。但以前对此没有严格强制检查,存在可创建重复名称的边界情况。
原始发布条目 ·
11.0/migration/003使 power(numeric, numeric) 和 power(float8, float8) 按照 POSIX 标准处理 NaN 输入 · 兼容性变化 · 迁移说明
使
power(numeric, numeric)和power(float8, float8)按照 POSIX 标准处理NaN输入(Tom Lane,Dang Minh Huong)POSIX 规定
NaN ^ 0 = 1且1 ^ NaN = 1,但其他所有包含NaN输入的情况都应返回NaN。power(numeric, numeric)以前在所有此类情况下都返回NaN,现在会遵循这两个例外。只要 C 库符合标准,power(float8, float8)就会符合标准;但某些旧 Unix 平台的库不符合标准,某些 Windows 版本上也存在问题。原始发布条目 ·
11.0/migration/004当模板分隔符不匹配时,防止 to_number() 消耗字符 · 兼容性变化 · 迁移说明
当模板分隔符不匹配时,防止
to_number()消耗字符(Oliver Ford)具体而言,
SELECT to_number('1234', '9,999')以前返回134,现在会返回1234。L和TH现在只消耗数字、正负号、小数点和逗号以外的字符。原始发布条目 ·
11.0/migration/005调整 to_char()、to_number() 和 to_timestamp() 对模板字符串中双引号内反斜线的处理。 · 兼容性变化 · 迁移说明
调整
to_char()、to_number()和to_timestamp()对模板字符串中双引号内反斜线的处理。这种反斜线现在会转义其后的字符,尤其是双引号或另一个反斜线。
原始发布条目 ·
11.0/migration/007正确处理 xmltable()、xpath() 及其他 XML 处理函数中的相对路径表达式 · 兼容性变化 · 迁移说明
正确处理
xmltable()、xpath()及其他 XML 处理函数中的相对路径表达式(Markus Winand)按照 SQL 标准,相对路径从 XML 输入文档的文档节点开始,而非像这些函数以前那样从根节点开始。
原始发布条目 ·
11.0/migration/008在扩展查询协议中,使 statement_timeout 分别应用于每条 Execute 消息,而非应用于 Sync 之前的所有命令 · 兼容性变化 · 迁移说明
在扩展查询协议中,使
statement_timeout分别应用于每条 Execute 消息,而非应用于 Sync 之前的所有命令(Tatsuo Ishii,Andres Freund)原始发布条目 ·
11.0/migration/009从系统目录 pg_class 中移除 relhaspkey 列 · 兼容性变化 · 迁移说明
从系统目录
pg_class中移除relhaspkey列(Peter Eisentraut)需要检查主键的应用应查询
pg_index。原始发布条目 ·
11.0/migration/010将系统目录 pg_proc 的 proisagg 和 proiswindow 列替换为 prokind · 兼容性变化 · 迁移说明
将系统目录
pg_proc的proisagg和proiswindow列替换为prokind(Peter Eisentraut)这个新列更清楚地区分了函数、过程、聚合和窗口函数。
原始发布条目 ·
11.0/migration/011修正信息模式列 tables.table_type,使其返回 FOREIGN 而非 FOREIGN TABLE · 兼容性变化 · 迁移说明
修正信息模式列
tables.table_type,使其返回FOREIGN而非FOREIGN TABLE(Peter Eisentraut)这种新输出符合 SQL 标准。
原始发布条目 ·
11.0/migration/012更改 ps 进程显示中的后台工作进程标签,使其与 pg_stat_activity.backend_type 标签一致 · 兼容性变化 · 迁移说明
更改 ps 进程显示中的后台工作进程标签,使其与
pg_stat_activity.backend_type标签一致(Peter Eisentraut)原始发布条目 ·
11.0/migration/013防止非超级用户重建共享目录的索引 · 兼容性变化 · 迁移说明
防止非超级用户重建共享目录的索引(Michael Paquier,Robert Haas)
以前,数据库所有者也被允许这样做,但现在认为这超出了其权限范围。
原始发布条目 ·
11.0/migration/015遵循双引号内命令选项的大小写 · 兼容性变化 · 迁移说明
遵循双引号内命令选项的大小写(Daniel Gustafsson)
以前,某些 SQL 命令中的选项名即使以双引号输入,也会被强制转换为小写;因此,例如
"FillFactor"会被接受为索引存储选项,尽管其正确名称应为小写。现在,此类情况将产生错误。原始发布条目 ·
11.0/migration/017移除服务器参数 replacement_sort_tuples · 兼容性变化 · 迁移说明
移除服务器参数
replacement_sort_tuples(Peter Geoghegan)经判断,置换排序已不再有用。
原始发布条目 ·
11.0/migration/018移除 CREATE FUNCTION 中的 WITH 子句 · 兼容性变化 · 迁移说明
移除
CREATE FUNCTION中的WITH子句(Michael Paquier)PostgreSQL 很早以前就已支持更符合标准的语法来实现此功能。
原始发布条目 ·
11.0/migration/019在 PL/pgSQL 触发器函数中,未赋值的 OLD 和 NEW 变量现在读取为 NULL · 兼容性变化 · 迁移说明
在 PL/pgSQL 触发器函数中,未赋值的
OLD和NEW变量现在读取为 NULL(Tom Lane)以前,对这些变量的引用可以解析,但无法执行。
原始发布条目 ·
11.0/migration/020支持分区表上的索引 · 新功能
支持分区表上的索引(Álvaro Herrera,Amit Langote)
分区表上的“索引”并非跨越整个分区表的物理索引,而是用于在表的每个分区上自动创建类似索引的模板。
如果索引列集合包含分区键,则可以将分区索引声明为
UNIQUE。它将表示覆盖整个分区表的有效唯一约束,尽管每个物理索引只在其自身分区内实施唯一性。新命令
ALTER INDEX ATTACH PARTITION将分区上的现有索引与其分区表的匹配索引模板关联起来。这为给现有分区表设置新的分区索引提供了灵活性。原始发布条目 ·
11.0/changes/002允许在分区表上定义 FOR EACH ROW 触发器 · 新功能
允许在分区表上定义
FOR EACH ROW触发器(Álvaro Herrera)在分区表上创建触发器,会自动在所有现有和未来分区上创建触发器。这也使分区表能够使用延迟唯一约束。
原始发布条目 ·
11.0/changes/004允许分区表具有默认分区 · 新功能
允许分区表具有默认分区(Jeevan Ladhe,Beena Emerson,Ashutosh Bapat,Rahila Syed,Robert Haas)
默认分区存储不匹配其他任何已定义分区的行,并据此被搜索。
原始发布条目 ·
11.0/changes/005更改分区键列的 UPDATE 语句现在会将受影响的行移动到适当的分区 · 新功能
更改分区键列的
UPDATE语句现在会将受影响的行移动到适当的分区(Amit Khandekar)原始发布条目 ·
11.0/changes/006允许分区表上的 INSERT、UPDATE 和 COPY 将行正确路由到外部分区 · 新功能
允许分区表上的
INSERT、UPDATE和COPY将行正确路由到外部分区(Etsuro Fujita,Amit Langote)postgres_fdw外部表支持此功能。由于为此调用ExecForeignInsert回调函数的方式与以前不同,外部数据包装器必须相应修改以适应此更改。原始发布条目 ·
11.0/changes/007加快查询处理期间的分区排除 · 性能改进
加快查询处理期间的分区排除(Amit Langote,David Rowley,Dilip Kumar)
这加快了对具有大量分区的分区表的访问。
原始发布条目 ·
11.0/changes/008允许在查询执行期间排除分区 · 新功能
允许在查询执行期间排除分区(David Rowley,Beena Emerson)
以前,分区排除仅在规划时进行,因此许多连接和预备查询无法使用分区排除。
原始发布条目 ·
11.0/changes/009在分区表之间的等值连接中,允许直接连接匹配的分区 · 新功能
在分区表之间的等值连接中,允许直接连接匹配的分区(Ashutosh Bapat)
此特性默认禁用,但可以通过更改
enable_partitionwise_join启用。原始发布条目 ·
11.0/changes/010允许对分区表上的聚合函数按分区分别求值,随后合并结果 · 新功能
允许对分区表上的聚合函数按分区分别求值,随后合并结果(Jeevan Chalke,Ashutosh Bapat,Robert Haas)
此特性默认禁用,但可以通过更改
enable_partitionwise_aggregate启用。原始发布条目 ·
11.0/changes/011允许 postgres_fdw 将聚合下推到作为分区的外部表 · 新功能
允许
postgres_fdw将聚合下推到作为分区的外部表(Jeevan Chalke)原始发布条目 ·
11.0/changes/012允许并行构建 B-树索引 · 新功能
允许并行构建 B-树索引(Peter Geoghegan,Rushabh Lathia,Heikki Linnakangas)
原始发布条目 ·
11.0/changes/013如果各条 SELECT 无法分别并行化,则允许 UNION 并行运行各条 SELECT · 新功能
如果各条
SELECT无法分别并行化,则允许UNION并行运行各条SELECT(Amit Khandekar,Robert Haas,Amul Sul)原始发布条目 ·
11.0/changes/015允许分区扫描更高效地使用并行工作进程 · 新功能
允许分区扫描更高效地使用并行工作进程(Amit Khandekar,Robert Haas,Amul Sul)
原始发布条目 ·
11.0/changes/016允许将 LIMIT 传递给并行工作进程 · 新功能
允许将
LIMIT传递给并行工作进程(Robert Haas,Tom Lane)这使工作进程能够减少返回结果,并使用有针对性的索引扫描。
原始发布条目 ·
11.0/changes/017允许单次求值查询(例如 WHERE 子句中的聚合查询)以及目标列表中的函数并行执行 · 新功能
允许单次求值查询(例如
WHERE子句中的聚合查询)以及目标列表中的函数并行执行(Amit Kapila,Robert Haas)原始发布条目 ·
11.0/changes/018添加服务器参数 parallel_leader_participation,以控制领导者是否也执行子计划 · 新功能
添加服务器参数
parallel_leader_participation,以控制领导者是否也执行子计划(Thomas Munro)默认启用,意味着领导者将执行子计划。
原始发布条目 ·
11.0/changes/019允许并行执行 CREATE TABLE ... AS、SELECT INTO 和 CREATE MATERIALIZED VIEW 命令 · 新功能
允许并行执行
CREATE TABLE ... AS、SELECT INTO和CREATE MATERIALIZED VIEW命令(Haribabu Kommi)原始发布条目 ·
11.0/changes/020在 EXPLAIN 中添加并行工作进程排序活动的报告 · 新功能
在
EXPLAIN中添加并行工作进程排序活动的报告(Robert Haas,Tom Lane)原始发布条目 ·
11.0/changes/022允许 B-树索引包含不属于搜索键或唯一约束、但可供仅索引扫描读取的列 · 新功能
允许 B-树索引包含不属于搜索键或唯一约束、但可供仅索引扫描读取的列(Anastasia Lubennikova,Alexander Korotkov,Teodor Sigaev)
这通过
CREATE INDEX的新INCLUDE子句启用。它便于构建优化特定查询类型的“覆盖索引”。即使列的数据类型不支持 B-树,也可以将其包含在内。原始发布条目 ·
11.0/changes/023为 hash、GiST 和 GIN 索引添加谓词锁定 · 新功能
为 hash、GiST 和 GIN 索引添加谓词锁定(Shubham Barai)
这降低了可串行化模式事务发生串行化冲突的可能性。
原始发布条目 ·
11.0/changes/026添加前缀匹配操作符 text ^@ text,并由 SP-GiST 支持 · 新功能
添加前缀匹配操作符
text^@text,并由 SP-GiST 支持(Ildus Kurbangaliev)这类似于配合 B-树索引使用
varLIKE 'word%',但效率更高。原始发布条目 ·
11.0/changes/027允许使用 SP-GiST 对多边形建立索引 · 新功能
允许使用 SP-GiST 对多边形建立索引(Nikita Glukhov,Alexander Korotkov)
原始发布条目 ·
11.0/changes/028允许 SP-GiST 对叶子键使用有损表示 · 新功能
允许 SP-GiST 对叶子键使用有损表示(Teodor Sigaev,Heikki Linnakangas,Alexander Korotkov,Nikita Glukhov)
原始发布条目 ·
11.0/changes/029改进统计信息中高频值的选择 · 新功能
改进统计信息中高频值的选择(Jeff Janes,Dean Rasheed)
以前,根据某个值相对于所有列值的频率来识别高频值(MCV)。现在,根据其相对于非 MCV 值的频率选择 MCV。这提高了算法在均匀分布和非均匀分布下的稳健性。
原始发布条目 ·
11.0/changes/030改进 >= 和 <= 的选择率估算 · 新功能
改进
>=和<=的选择率估算(Tom Lane)以前,除非比较常量为 MCV,这些情况分别采用与
>和<相同的选择率估算。此更改对涉及小范围BETWEEN的查询尤其有帮助。原始发布条目 ·
11.0/changes/031在等价的情况下,将 var = var 简化为 var IS NOT NULL · 新功能
在等价的情况下,将
var=var简化为varIS NOT NULL(Tom Lane)这会改善选择率估算。
原始发布条目 ·
11.0/changes/032改进优化器对 EXISTS 和 NOT EXISTS 查询的行数估算 · 新功能
改进优化器对
EXISTS和NOT EXISTS查询的行数估算(Tom Lane)原始发布条目 ·
11.0/changes/033在 VACUUM 期间更新空闲空间映射 · 性能改进
在
VACUUM期间更新空闲空间映射(Claudio Freire)这使空闲空间能够更快地被复用。
原始发布条目 ·
11.0/changes/037允许 VACUUM 避免不必要的索引扫描 · 性能改进
允许
VACUUM避免不必要的索引扫描(Masahiko Sawada,Alexander Korotkov)原始发布条目 ·
11.0/changes/038允许 postgres_fdw 将使用连接的 UPDATE 和 DELETE 下推到外部服务器 · 性能改进
允许
postgres_fdw将使用连接的UPDATE和DELETE下推到外部服务器(Etsuro Fujita)以前,只会下推不含连接的
UPDATE和DELETE。原始发布条目 ·
11.0/changes/042添加对 Windows 上大页的支持 · 性能改进
添加对 Windows 上大页的支持(Takayuki Tsunakawa,Thomas Munro)
这由 huge_pages 配置参数控制。
原始发布条目 ·
11.0/changes/043在 log_statement_stats、log_parser_stats、log_planner_stats 和 log_executor_stats 的输出中显示内存用量 · 新功能
在
log_statement_stats、log_parser_stats、log_planner_stats和log_executor_stats的输出中显示内存用量(Justin Pryzby,Peter Eisentraut)原始发布条目 ·
11.0/changes/044添加 pg_stat_activity.backend_type 列,以显示后台工作进程的类型 · 新功能
添加
pg_stat_activity.backend_type列,以显示后台工作进程的类型(Peter Eisentraut)该类型在 ps 输出中也可见。
原始发布条目 ·
11.0/changes/045使 log_autovacuum_min_duration 记录因正被并发删除而跳过的表 · 新功能
使
log_autovacuum_min_duration记录因正被并发删除而跳过的表(Nathan Bossart)原始发布条目 ·
11.0/changes/046添加与表约束和触发器相关的 information_schema 列 · 新功能
添加与表约束和触发器相关的
information_schema列(Peter Eisentraut)具体而言,
triggers.action_order、triggers.action_reference_old_table和triggers.action_reference_new_table现在会填入值,而以前始终为空。此外,table_constraints.enforced列现在已存在,但尚未填入有用的值。原始发布条目 ·
11.0/changes/047允许 LDAP 认证使用加密的 LDAP · 新功能
允许 LDAP 认证使用加密的 LDAP(Thomas Munro)
以前已可通过
ldaptls=1支持基于 TLS 的 LDAP。这种用于加密 LDAP 的新 TLS LDAP 方式,通过ldapscheme=ldaps或ldapurl=ldaps://启用。原始发布条目 ·
11.0/changes/049允许通过 GRANT/REVOKE 权限控制对文件系统函数的访问,取代超级用户检查 · 新功能
允许通过
GRANT/REVOKE权限控制对文件系统函数的访问,取代超级用户检查(Stephen Frost)具体而言,修改了以下函数:
pg_ls_dir()、pg_read_file()、pg_read_binary_file()、pg_stat_file()。原始发布条目 ·
11.0/changes/052使用 GRANT/REVOKE 控制对 lo_import() 和 lo_export() 的访问 · 新功能
使用
GRANT/REVOKE控制对lo_import()和lo_export()的访问(Michael Paquier,Tom Lane)以前,只有超级用户获准访问这些函数。
编译时选项
ALLOW_DANGEROUS_LO_FUNCTIONS已被移除。原始发布条目 ·
11.0/changes/053在阻止以非密码方式访问 postgres_fdw 表时,使用视图所有者而非会话所有者 · 新功能
在阻止以非密码方式访问
postgres_fdw表时,使用视图所有者而非会话所有者(Robert Haas)PostgreSQL 只允许超级用户在不使用密码的情况下访问
postgres_fdw表,例如通过peer认证。以前,要允许此类访问,会话所有者必须是超级用户;现在改为检查视图所有者。原始发布条目 ·
11.0/changes/054修复对视图执行 SELECT FOR UPDATE 时无效的锁定权限检查 · BUG 修复
修复对视图执行
SELECT FOR UPDATE时无效的锁定权限检查(Tom Lane)原始发布条目 ·
11.0/changes/055添加服务器设置 ssl_passphrase_command,以允许为 SSL 密钥文件提供口令 · 新功能
添加服务器设置
ssl_passphrase_command,以允许为 SSL 密钥文件提供口令(Peter Eisentraut)同时添加
ssl_passphrase_command_supports_reload,用于指定服务器配置重新加载期间,是否应重新加载 SSL 配置并调用ssl_passphrase_command。原始发布条目 ·
11.0/changes/056添加存储参数 toast_tuple_target,以控制开始考虑 TOAST 存储的最小元组长度 · 新功能
添加存储参数
toast_tuple_target,以控制开始考虑 TOAST 存储的最小元组长度(Simon Riggs)默认的 TOAST 阈值没有改变。
原始发布条目 ·
11.0/changes/057允许以字节为单位指定与内存和文件大小相关的服务器选项 · 新功能
允许以字节为单位指定与内存和文件大小相关的服务器选项(Beena Emerson)
新增单位后缀为 “B”,与现有的 “kB”、“MB”、“GB” 和 “TB” 并用。
原始发布条目 ·
11.0/changes/058允许在 initdb 期间设置 WAL 文件大小 · 新功能
允许在 initdb 期间设置 WAL 文件大小(Beena Emerson)
以前,16MB 的默认值只能在编译时更改。
原始发布条目 ·
11.0/changes/059仅保留一个检查点周期的 WAL 数据 · 新功能
仅保留一个检查点周期的 WAL 数据(Simon Riggs)
以前,会保留两个检查点周期的 WAL。
原始发布条目 ·
11.0/changes/060将被强制切换的 WAL 段文件的未使用部分填零,以提高可压缩性 · 新功能
将被强制切换的 WAL 段文件的未使用部分填零,以提高可压缩性(Chapman Flack)
原始发布条目 ·
11.0/changes/061使用逻辑复制时复制 TRUNCATE 操作 · 新功能
使用逻辑复制时复制
TRUNCATE操作(Simon Riggs,Marco Nenciarini,Peter Eisentraut)原始发布条目 ·
11.0/changes/062从流式基础备份中排除不记录 WAL 的表、临时表和 pg_internal.init 文件 · 新功能
从流式基础备份中排除不记录 WAL 的表、临时表和
pg_internal.init文件(David Steele)没有必要复制此类文件。
原始发布条目 ·
11.0/changes/064允许以编程方式推进复制槽,而无需由订阅者消费 · 新功能
允许以编程方式推进复制槽,而无需由订阅者消费(Petr Jelinek)
这使复制槽在内容无需被消费时能够高效推进。相应操作通过
pg_replication_slot_advance()执行。原始发布条目 ·
11.0/changes/066向 backup_label 文件添加时间线信息 · 新功能
向
backup_label文件添加时间线信息(Michael Paquier)同时添加检查,确保 WAL 时间线与
backup_label文件的时间线匹配。原始发布条目 ·
11.0/changes/067向 pg_stat_wal_receiver 系统视图添加主机和端口连接信息 · 新功能
向
pg_stat_wal_receiver系统视图添加主机和端口连接信息(Haribabu Kommi)原始发布条目 ·
11.0/changes/068允许 ALTER TABLE 添加具有非空默认值的列,而无需重写表 · 新功能
允许
ALTER TABLE添加具有非空默认值的列,而无需重写表(Andrew Dunstan,Serge Rielau)默认值为常量时会启用此优化。
原始发布条目 ·
11.0/changes/069允许 ALTER INDEX 设置表达式索引的统计收集目标 · 新功能
允许
ALTER INDEX设置表达式索引的统计收集目标(Alexander Korotkov,Adrien Nayrat)在 psql 中,
\d+现在会显示索引的统计目标。原始发布条目 ·
11.0/changes/071允许在一条 VACUUM 或 ANALYZE 命令中指定多个表 · 新功能
允许在一条
VACUUM或ANALYZE命令中指定多个表(Nathan Bossart)此外,如果
VACUUM中提到的任何表使用了列列表,就必须提供ANALYZE关键字;以前,此类情况会隐含执行ANALYZE。原始发布条目 ·
11.0/changes/072为 ANALYZE 添加括号包围的选项语法 · 新功能
为
ANALYZE添加括号包围的选项语法(Nathan Bossart)这与
VACUUM支持的语法类似。原始发布条目 ·
11.0/changes/073添加 CREATE AGGREGATE 选项,以指定聚合最终函数的行为 · 新功能
添加
CREATE AGGREGATE选项,以指定聚合最终函数的行为(Tom Lane)这有助于优化用户定义的聚合函数,并使其能够用作窗口函数。
原始发布条目 ·
11.0/changes/074支持基于复合类型的域 · 新功能
支持基于复合类型的域(Tom Lane)
同时允许 PL/Perl、PL/Python 和 PL/Tcl 处理复合类型域的函数参数和结果,并改进 PL/Python 的域处理。
原始发布条目 ·
11.0/changes/076添加从 JSONB 标量到数值和布尔数据类型的类型转换 · 新功能
添加从
JSONB标量到数值和布尔数据类型的类型转换(Anastasia Lubennikova)原始发布条目 ·
11.0/changes/077添加文本检索函数 websearch_to_tsquery(),支持类似网页搜索引擎所用的查询语法 · 新功能
添加文本检索函数
websearch_to_tsquery(),支持类似网页搜索引擎所用的查询语法(Victor Drobny,Dmitry Ivanov)原始发布条目 ·
11.0/changes/082添加函数 json(b)_to_tsvector(),以创建用于匹配 JSON/JSONB 值的文本检索查询 · 新功能
添加函数
json(b)_to_tsvector(),以创建用于匹配JSON/JSONB值的文本检索查询(Dmitry Dolgov)原始发布条目 ·
11.0/changes/083添加 SQL 级过程,使其能够开始并提交自己的事务 · 新功能
添加 SQL 级过程,使其能够开始并提交自己的事务(Peter Eisentraut)
它们使用新的
CREATE PROCEDURE命令创建,并通过CALL调用。新的
ALTER/DROP ROUTINE命令允许更改/删除所有例程类对象,包括过程、函数和聚合。另外,在
CREATE OPERATOR和CREATE TRIGGER中,现在推荐使用FUNCTION而非PROCEDURE,因为所引用的对象必须是函数,而不能是过程。不过,为保持兼容,仍然接受旧语法。原始发布条目 ·
11.0/changes/084为 PL/pgSQL、PL/Perl、PL/Python、PL/Tcl 和 SPI 服务器端语言添加事务控制 · 新功能
为 PL/pgSQL、PL/Perl、PL/Python、PL/Tcl 和 SPI 服务器端语言添加事务控制(Peter Eisentraut)
事务控制仅可用于事务顶层的过程,以及嵌套的
DO和CALL块;嵌套层次中只能包含其他DO和CALL块。原始发布条目 ·
11.0/changes/085添加将 PL/pgSQL 复合类型变量定义为非空、常量或带初始值的能力 · 新功能
添加将 PL/pgSQL 复合类型变量定义为非空、常量或带初始值的能力(Tom Lane)
原始发布条目 ·
11.0/changes/086允许 PL/pgSQL 处理同一会话中首次和后续函数执行之间发生的复合类型(如 record、row)变更 · 新功能
允许 PL/pgSQL 处理同一会话中首次和后续函数执行之间发生的复合类型(如 record、row)变更(Tom Lane)
以前,这类情况会产生错误。
原始发布条目 ·
11.0/changes/087添加扩展 jsonb_plpython,以在 JSONB 和 PL/Python 类型之间进行转换 · 新功能
添加扩展
jsonb_plpython,以在JSONB和 PL/Python 类型之间进行转换(Anthony Bykov)原始发布条目 ·
11.0/changes/088添加扩展 jsonb_plperl,以在 JSONB 和 PL/Perl 类型之间进行转换 · 新功能
添加扩展
jsonb_plperl,以在JSONB和 PL/Perl 类型之间进行转换(Anthony Bykov)原始发布条目 ·
11.0/changes/089更改 libpq,使其默认禁用压缩 · 新功能
更改 libpq,使其默认禁用压缩(Peter Eisentraut)
现代 OpenSSL 版本已禁用压缩,因此 libpq 的这一设置对这些库并无影响。
原始发布条目 ·
11.0/changes/090为 ecpg 的 WHENEVER 语句添加 DO CONTINUE 选项 · 新功能
为 ecpg 的
WHENEVER语句添加DO CONTINUE选项(Vinayak Pokale)这会生成 C
continue语句,在指定条件发生时返回所在循环的顶部。原始发布条目 ·
11.0/changes/091添加 ecpg 模式,以启用 Oracle Pro*C 风格的字符数组处理。 · 新功能
添加 ecpg 模式,以启用 Oracle Pro*C 风格的字符数组处理。
此模式通过
-C启用。原始发布条目 ·
11.0/changes/092添加 psql 命令 \gdesc,以显示查询结果中各列的名称和类型 · 新功能
添加 psql 命令
\gdesc,以显示查询结果中各列的名称和类型(Pavel Stehule)原始发布条目 ·
11.0/changes/093添加 psql 变量,以报告查询活动和错误 · 新功能
添加 psql 变量,以报告查询活动和错误(Fabien Coelho)
具体新增变量为
ERROR、SQLSTATE、ROW_COUNT、LAST_ERROR_MESSAGE和LAST_ERROR_SQLSTATE。原始发布条目 ·
11.0/changes/094允许 psql 测试变量是否存在 · 新功能
允许 psql 测试变量是否存在(Fabien Coelho)
具体而言,语法
:{?variable_name}允许在\if语句中测试变量是否存在。原始发布条目 ·
11.0/changes/095允许环境变量 PSQL_PAGER 控制 psql 的分页器 · 新功能
允许环境变量
PSQL_PAGER控制 psql 的分页器(Pavel Stehule)这允许用独立的环境变量指定 psql 的默认分页器,将其与其他应用的分页器设置分开。如果未设置
PSQL_PAGER,仍会遵循PAGER。原始发布条目 ·
11.0/changes/096使 psql 的 \d+ 命令始终显示表的分区信息 · 新功能
使 psql 的
\d+命令始终显示表的分区信息(Amit Langote,Ashutosh Bapat)以前,如果分区表没有分区,就不会显示其分区信息。现在还会指出哪些分区本身也是分区表。
原始发布条目 ·
11.0/changes/097确保 psql 在提示输入密码时显示正确的用户名 · 新功能
确保 psql 在提示输入密码时显示正确的用户名(Tom Lane)
以前,同时使用
-U和嵌入 URI 的用户名会导致显示错误的用户名。另外,在指定--password时,不再在密码提示前显示用户名。原始发布条目 ·
11.0/changes/098在此前没有输入的情况下,允许 quit 和 exit 退出 psql · 新功能
在此前没有输入的情况下,允许
quit和exit退出 psql(Bruce Momjian)当输入缓冲区非空,而
quit和exit单独出现在一行时,也会输出如何退出的提示。为help添加类似提示。原始发布条目 ·
11.0/changes/099当 \q 单独输入在一行上却被忽略时,让 psql 提示使用 control-D · 新功能
当
\q单独输入在一行上却被忽略时,让 psql 提示使用 control-D(Bruce Momjian)例如,在字符串内输入
\q不会退出。原始发布条目 ·
11.0/changes/100改进 ALTER INDEX RESET/SET 的 Tab 补全 · 新功能
改进
ALTER INDEX RESET/SET的 Tab 补全(Masahiko Sawada)原始发布条目 ·
11.0/changes/101添加基础支持,使 psql 能够根据服务器版本调整 Tab 补全查询 · 新功能
添加基础支持,使 psql 能够根据服务器版本调整 Tab 补全查询(Tom Lane)
以前,对旧版服务器执行 Tab 补全查询可能失败。
原始发布条目 ·
11.0/changes/102为 pgbench 表达式添加对 NULL、布尔值以及某些函数和操作符的支持 · 新功能
为 pgbench 表达式添加对 NULL、布尔值以及某些函数和操作符的支持(Fabien Coelho)
原始发布条目 ·
11.0/changes/103允许在 pgbench 变量名中使用非 ASCII 字符 · 新功能
允许在 pgbench 变量名中使用非 ASCII 字符(Fabien Coelho)
原始发布条目 ·
11.0/changes/105添加 pgbench 选项 --init-steps,以控制执行哪些初始化步骤 · 新功能
添加 pgbench 选项
--init-steps,以控制执行哪些初始化步骤(Masahiko Sawada)原始发布条目 ·
11.0/changes/106为 pgbench 添加近似服从 Zipf 分布的随机数生成器 · 新功能
为 pgbench 添加近似服从 Zipf 分布的随机数生成器(Alik Khilazhev)
原始发布条目 ·
11.0/changes/107允许 pgbench 使用 pow() 和 power() 执行幂运算 · 新功能
允许 pgbench 使用
pow()和power()执行幂运算(Raúl Marín Rodríguez)原始发布条目 ·
11.0/changes/109提高使用 --latency-limit 和 --rate 时 pgbench 统计信息的准确性 · 新功能
提高使用
--latency-limit和--rate时 pgbench 统计信息的准确性(Fabien Coelho)原始发布条目 ·
11.0/changes/111为pg_basebackup添加创建命名复制槽的选项 · 新功能
为pg_basebackup添加创建命名复制槽的选项(Michael Banck)
使用 WAL 流式方法(
--wal-method=stream)时,--create-slot选项会创建指定名称的复制槽(--slot)。原始发布条目 ·
11.0/changes/112允许initdb为数据目录设置组读取权限 · 新功能
允许initdb为数据目录设置组读取权限(David Steele)
这通过新的 initdb 选项
--allow-group-access完成。管理员也可以在运行 initdb 之前,为空数据目录设置组权限。服务器变量data_directory_mode允许读取数据目录的组权限。原始发布条目 ·
11.0/changes/113添加pg_verify_checksums工具,以在离线状态下验证数据库校验和 · 新功能
添加pg_verify_checksums工具,以在离线状态下验证数据库校验和(Magnus Hagander)
原始发布条目 ·
11.0/changes/114允许pg_resetwal通过 --wal-segsize 更改 WAL 段大小 · 新功能
允许pg_resetwal通过
--wal-segsize更改 WAL 段大小(Nathan Bossart)原始发布条目 ·
11.0/changes/115为 pg_resetwal 和 pg_controldata 添加长选项 · 新功能
为 pg_resetwal 和 pg_controldata 添加长选项(Nathan Bossart,Peter Eisentraut)
原始发布条目 ·
11.0/changes/116为pg_receivewal添加 --no-sync 选项,用于测试时禁止同步 WAL 写入 · 新功能
为pg_receivewal添加
--no-sync选项,用于测试时禁止同步 WAL 写入(Michael Paquier)原始发布条目 ·
11.0/changes/117添加 pg_receivewal 选项 --endpos,以指定何时停止接收 WAL · 新功能
添加 pg_receivewal 选项
--endpos,以指定何时停止接收 WAL(Michael Paquier)原始发布条目 ·
11.0/changes/118添加 pg_dumpall 选项 --encoding,以控制输出编码 · 新功能
添加 pg_dumpall 选项
--encoding,以控制输出编码(Michael Paquier)pg_dump 已有此选项。
原始发布条目 ·
11.0/changes/122添加 pg_dump 选项 --load-via-partition-root,强制将数据加载到分区的根表,而非原分区 · 新功能
添加 pg_dump 选项
--load-via-partition-root,强制将数据加载到分区的根表,而非原分区(Rushabh Lathia)当加载目标系统具有不同的排序规则定义或字节序,可能需要将行存储到与以前不同的分区时,此选项很有用。
原始发布条目 ·
11.0/changes/123添加禁止转储和恢复数据库对象注释的选项 · 新功能
添加禁止转储和恢复数据库对象注释的选项(Robins Tharakan)
pg_dump、pg_dumpall 和 pg_restore 的新选项为
--no-comments。原始发布条目 ·
11.0/changes/124为 PGXS 添加安装包含文件的支持 · 新功能
为 PGXS 添加安装包含文件的支持(Andrew Gierth)
这支持创建依赖其他模块的扩展模块。以前,依赖模块没有简单的方法找到被引用模块的包含文件。若干定义了数据类型的现有
contrib模块已作调整,以安装相关文件。此外,PL/Perl 和 PL/Python 现在也会安装其包含文件,以支持创建这些语言的转换模块。原始发布条目 ·
11.0/changes/125安装 errcodes.txt,使扩展可以访问 PostgreSQL 已知的错误码列表 · 新功能
安装
errcodes.txt,使扩展可以访问 PostgreSQL 已知的错误码列表(Thomas Munro)原始发布条目 ·
11.0/changes/126将文档转换为 DocBook XML · 新功能
将文档转换为 DocBook XML(Peter Eisentraut,Alexander Lakhin,Jürgen Purtz)
为与旧分支保持兼容,文件名仍使用
sgml扩展名。原始发布条目 ·
11.0/changes/127在适用的平台(即大多数平台)上,使用 stdbool.h 定义 bool 类型 · 新功能
在适用的平台(即大多数平台)上,使用
stdbool.h定义bool类型(Peter Eisentraut)这消除了需要包含
stdbool.h的扩展模块的一项编码隐患。原始发布条目 ·
11.0/changes/128全面调整初始系统目录内容的定义方式 · 新功能
全面调整初始系统目录内容的定义方式(John Naylor)
初始数据现在用 Perl 数据结构表示,更便于机械化处理。
原始发布条目 ·
11.0/changes/129禁止扩展创建接受带引号值列表的自定义服务器参数 · 新功能
禁止扩展创建接受带引号值列表的自定义服务器参数(Tom Lane)
目前无法支持这种功能,因为在加载扩展之前就必须知道该参数的这一属性。
原始发布条目 ·
11.0/changes/130添加对 ARMv8 上硬件 CRC 计算的支持 · 新功能
添加对 ARMv8 上硬件 CRC 计算的支持(Yuqi Gu,Heikki Linnakangas,Thomas Munro)
原始发布条目 ·
11.0/changes/133添加针对顺序分配/释放优化的分代内存分配器 · 新功能
添加针对顺序分配/释放优化的分代内存分配器(Tomas Vondra)
这减少了逻辑解码的内存用量。
原始发布条目 ·
11.0/changes/137使 VACUUM 对 pg_class.reltuples 的计算与 ANALYZE 一致 · 新功能
使
VACUUM对pg_class.reltuples的计算与ANALYZE一致(Tomas Vondra)原始发布条目 ·
11.0/changes/138更新为使用 perltidy 20170521 版 · 新功能
更新为使用 perltidy
20170521版(Tom Lane,Peter Eisentraut)原始发布条目 ·
11.0/changes/139允许扩展 pg_prewarm 在启动时恢复先前的共享缓冲区内容 · 新功能
允许扩展
pg_prewarm在启动时恢复先前的共享缓冲区内容(Mithun Cy,Robert Haas)实现方式是让
pg_prewarm在服务器运行期间不时地、并在关闭时,将共享缓冲区的关系和块号数据存储到磁盘。原始发布条目 ·
11.0/changes/140允许使用 ~> 操作符获取 cube 坐标的负值 · 新功能
允许使用
~>操作符获取 cube 坐标的负值(Alexander Korotkov)这对按降序查找坐标的 KNN-GiST 搜索很有用。
原始发布条目 ·
11.0/changes/144将 pg_stat_statement 的查询 ID 扩为 64 位 · 新功能
将
pg_stat_statement的查询 ID 扩为 64 位(Robert Haas)这大幅降低了查询 ID hash 冲突的概率。查询 ID 现在可能显示为负值。
原始发布条目 ·
11.0/changes/148移除已不再推荐使用的 contrib/start-scripts/osx 脚本(改用 contrib/start-scripts/macos) · 新功能
移除已不再推荐使用的
contrib/start-scripts/osx脚本(改用contrib/start-scripts/macos)(Tom Lane)原始发布条目 ·
11.0/changes/149移除 chkpass 扩展 · 新功能
移除
chkpass扩展(Peter Eisentraut)此扩展不再被视为可用的安全工具或编写扩展的示例。
原始发布条目 ·
11.0/changes/150
安全证据
共 38 条记录,来自官方安全矩阵及发布说明的提及。只有安全快照明确列出此分支时才显示修复版本;仅有提及不能确定漏洞适用性或新修复。
CVE-2023-5870 · Role "pg_signal_backend" can signal certain superuser processes · CVSS 2.2
Documentation says the pg_signal_backend role cannot signal "a backend owned by a superuser". On the contrary, it can signal background workers, including the logical replication launcher. It can signal autovacuum workers and the autovacuum launcher. Signaling autovacuum workers and those two launchers provides no meaningful exploit, so exploiting this vulnerability requires a non-core extension with a less-resilient background worker. For example, a non-core background worker that does not auto-restart would experience a denial of service with respect to that particular background worker. The PostgreSQL project thanks Hemanth Sandrana and Mahendrakar Srinivasarao for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:11.22。组件:core server。
官方受影响分支记录:11。
AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L
发布说明中的提及:
CVE-2023-5869 · Buffer overrun from integer overflow in array modification · CVSS 8.8
While modifying certain SQL array values, missing overflow checks let authenticated database users write arbitrary bytes to a memory area that facilitates arbitrary code execution. Missing overflow checks also let authenticated database users read a wide area of server memory. The CVE-2021-32027 fix covered some attacks of this description, but it missed others. The PostgreSQL project thanks Pedro Gallegos for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:11.22。组件:core server。
官方受影响分支记录:11。
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2023-5868 · Memory disclosure in aggregate function calls · CVSS 4.3
Certain aggregate function calls receiving "unknown"-type arguments could disclose bytes of server memory from the end of the "unknown"-type value to the next zero byte. One typically gets an "unknown"-type value via a string literal having no type designation. We have not confirmed or ruled out viability of attacks that arrange for presence of notable, confidential information in disclosed bytes. The PostgreSQL project thanks Jingzhou Fu for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:11.22。组件:core server。
官方受影响分支记录:11。
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
发布说明中的提及:
CVE-2023-39417 · Extension script @substitutions@ within quoting allow SQL injection · CVSS 7.5
An extension script is vulnerable if it uses @extowner@ , @extschema@ , or @extschema:...@ inside a quoting construct (dollar quoting, '' , or "" ). No bundled extension is vulnerable. Vulnerable uses do appear in a documentation example and in non-bundled extensions. Hence, the attack prerequisite is an administrator having installed files of a vulnerable, trusted, non-bundled extension. Subject to that prerequisite, this enables an attacker having database-level CREATE privilege to execute arbitrary code as the bootstrap superuser. PostgreSQL will block this attack in the core server, so there's no need to modify individual extensions. The PostgreSQL project thanks Micah Gates, Valerie Woolard, Tim Carey-Smith, and Christoph Berg for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:11.21。组件:core server。
官方受影响分支记录:11。
AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2023-2455 · Row security policies disregard user ID changes after inlining · CVSS 4.2
While CVE-2016-2193 fixed most interaction between row security and user ID changes, it missed a scenario involving function inlining. This leads to potentially incorrect policies being applied in cases where role-specific policies are used and a given query is planned under one role and then executed under other roles. This scenario can happen under security definer functions or when a common user and query is planned initially and then re-used across multiple SET ROLE s. Applying an incorrect policy may permit a user to complete otherwise-forbidden reads and modifications. This affects only databases that have used CREATE POLICY to define a row security policy. The PostgreSQL project thanks Wolfgang Walther for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:11.20。组件:core server。
官方受影响分支记录:11。
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
发布说明中的提及:
CVE-2023-2454 · CREATE SCHEMA ... schema_element defeats protective search_path changes · CVSS 7.2
This enabled an attacker having database-level CREATE privilege to execute arbitrary code as the bootstrap superuser. Database owners have that right by default, and explicit grants may extend it to other users. The PostgreSQL project thanks Alexander Lakhin for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:11.20。组件:core server。
官方受影响分支记录:11。
AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2022-2625 · Extension scripts replace objects not belonging to the extension · CVSS 7.1
Some extensions use CREATE OR REPLACE or CREATE IF NOT EXISTS commands. Some don't adhere to the documented rule to target only objects known to be extension members already. An attack requires permission to create non-temporary objects in at least one schema, ability to lure or wait for an administrator to create or update an affected extension in that schema, and ability to lure or wait for a victim to use the object targeted in CREATE OR REPLACE or CREATE IF NOT EXISTS . Given all three prerequisites, the attacker can run arbitrary code as the victim role, which may be a superuser. Known-affected extensions include both PostgreSQL-bundled and non-bundled extensions. PostgreSQL is blocking this attack in the core server, so there's no need to modify individual extensions. The PostgreSQL project thanks Sven Klemm for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:11.17。组件:core server。
官方受影响分支记录:11。
AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2022-1552 · Autovacuum, REINDEX, and others omit "security restricted operation" sandbox · CVSS 8.8
Autovacuum, REINDEX , CREATE INDEX , REFRESH MATERIALIZED VIEW , CLUSTER , and pg_amcheck made incomplete efforts to operate safely when a privileged user is maintaining another user's objects. Those commands activated relevant protections too late or not at all. An attacker having permission to create non-temp objects in at least one schema could execute arbitrary SQL functions under a superuser identity. While promptly updating PostgreSQL is the best remediation for most users, a user unable to do that can work around the vulnerability by disabling autovacuum, not manually running the above commands, and not restoring from output of the pg_dump command. Performance may degrade quickly under this workaround. VACUUM is safe, and all commands are fine when a trusted user owns the target object. The PostgreSQL project thanks Alexander Lakhin for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:11.16。组件:core server。
官方受影响分支记录:11。
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2021-3677 · Memory disclosure in certain queries · CVSS 6.5
A purpose-crafted query can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can complete this attack at will. The attack does not require the ability to create objects. If server settings include max_worker_processes=0 , the known versions of this attack are infeasible. However, undiscovered variants of the attack may be independent of that setting.
以上保留官方英文漏洞说明。
本分支修复于:11.13。组件:core server。
官方受影响分支记录:11。
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
发布说明中的提及:
CVE-2021-3449 · CVE-2021-3449
CVE-2021-3393 · Partition constraint violation errors leak values of denied columns · CVSS 3.1
A user having an UPDATE privilege on a partitioned table but lacking the SELECT privilege on some column may be able to acquire denied-column values from an error message. This is similar to CVE-2014-8161 , but the conditions to exploit are more rare. The PostgreSQL project thanks Heikki Linnakangas for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:11.11。组件:core server。
官方受影响分支记录:11。
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
发布说明中的提及:
CVE-2021-32029 · Memory disclosure in partitioned-table UPDATE ... RETURNING · CVSS 6.5
Using an UPDATE ... RETURNING on a purpose-crafted partitioned table, an attacker can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can create prerequisite objects and complete this attack at will. A user lacking the CREATE and TEMPORARY privileges on all databases and the CREATE privilege on all schemas typically cannot use this attack at will. The PostgreSQL project thanks Tom Lane for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:11.12。组件:core server。
官方受影响分支记录:11。
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
发布说明中的提及:
CVE-2021-32028 · Memory disclosure in INSERT ... ON CONFLICT ... DO UPDATE · CVSS 6.5
Using an INSERT ... ON CONFLICT ... DO UPDATE command on a purpose-crafted table, an attacker can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can create prerequisite objects and complete this attack at will. A user lacking the CREATE and TEMPORARY privileges on all databases and the CREATE privilege on all schemas cannot use this attack at will. The PostgreSQL project thanks Andres Freund for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:11.12。组件:core server。
官方受影响分支记录:11。
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
发布说明中的提及:
CVE-2021-32027 · Buffer overrun from integer overflow in array subscripting calculations · CVSS 6.5
While modifying certain SQL array values, missing bounds checks let authenticated database users write arbitrary bytes to a wide area of server memory. The PostgreSQL project thanks Tom Lane for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:11.12。组件:core server。
官方受影响分支记录:11。
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
发布说明中的提及:
CVE-2021-23222 · libpq processes unencrypted bytes from man-in-the-middle · CVSS 3.7
A man-in-the-middle attacker can inject false responses to the client's first few queries, despite the use of SSL certificate verification and encryption. If more preconditions hold, the attacker can exfiltrate the client's password or other confidential data that might be transmitted early in a session. The attacker must have a way to trick the client's intended server into making the confidential data accessible to the attacker. A known implementation having that property is a PostgreSQL configuration vulnerable to CVE-2021-23214 . As with any exploitation of CVE-2021-23214 , the server must be using trust authentication with a clientcert requirement or using cert authentication. To disclose a password, the client must be in possession of a password, which is atypical when using an authentication configuration vulnerable to CVE-2021-23214 . The attacker must have some other way to access the server to retrieve the exfiltrated data (a valid, unprivileged login account would be sufficient). The PostgreSQL project thanks Jacob Champion for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:11.14。组件:client。
官方受影响分支记录:11。
AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
发布说明中的提及:
CVE-2021-23214 · Server processes unencrypted bytes from man-in-the-middle · CVSS 8.1
When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption. This is similar to CVE-2011-0411 (different product). The PostgreSQL project thanks Jacob Champion for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:11.14。组件:core server。
官方受影响分支记录:11。
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2020-25696 · psql's \gset allows overwriting specially treated variables · CVSS 7.5
The \gset meta-command, which sets psql variables based on query results, does not distinguish variables that control psql behavior. If an interactive psql session uses \gset when querying a compromised server, the attacker can execute arbitrary code as the operating system account running psql . Using \gset with a prefix not found among specially treated variables, e.g. any lowercase string, precludes the attack in an unpatched psql . The PostgreSQL project thanks Nick Cleaton for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:11.10。组件:client。
官方受影响分支记录:11。
AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2020-25695 · Multiple features escape "security restricted operation" sandbox · CVSS 8.8
An attacker having permission to create non-temporary objects in at least one schema can execute arbitrary SQL functions under the identity of a superuser. While promptly updating PostgreSQL is the best remediation for most users, a user unable to do that can work around the vulnerability by disabling autovacuum and not manually running ANALYZE , CLUSTER , REINDEX , CREATE INDEX , VACUUM FULL , REFRESH MATERIALIZED VIEW , or a restore from output of the pg_dump command. Performance may degrade quickly under this workaround. VACUUM without the FULL option is safe, and all commands are fine when a trusted user owns the target object. The PostgreSQL project thanks Etienne Stalmans for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:11.10。组件:core server。
官方受影响分支记录:11。
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2020-25694 · Reconnection can downgrade connection security settings · CVSS 8.1
Many PostgreSQL-provided client applications have options that create additional database connections. Some of those applications reuse only the basic connection parameters (e.g. host , user , port ), dropping others. If this drops a security-relevant parameter (e.g. channel_binding , sslmode , requirepeer , gssencmode ), the attacker has an opportunity to complete a MITM attack or observe cleartext transmission. Affected applications are clusterdb , pg_dump , pg_restore , psql , reindexdb , and vacuumdb . The vulnerability arises only if one invokes an affected client application with a connection string containing a security-relevant parameter. This also fixes how the \connect command of psql reuses connection parameters, i.e. all non-overridden parameters from a previous connection string now re-used. The PostgreSQL project thanks Peter Eisentraut for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:11.10。组件:client。
官方受影响分支记录:11。
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2020-1720 · ALTER ... DEPENDS ON EXTENSION is missing authorization checks. · CVSS 3.1
The ALTER ... DEPENDS ON EXTENSION sub-commands do not perform authorization checks, which can allow an unprivileged user to drop any function, procedure, materialized view, index, or trigger under certain conditions. This attack is possible if an administrator has installed an extension and an unprivileged user can CREATE , or an extension owner either executes DROP EXTENSION predictably or can be convinced to execute DROP EXTENSION . The PostgreSQL project thanks Tom Lane for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:11.7。组件:core server。
官方受影响分支记录:11。
AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
发布说明中的提及:
CVE-2020-14350 · Uncontrolled search path element in CREATE EXTENSION · CVSS 7.1
When a superuser runs certain CREATE EXTENSION statements, users may be able to execute arbitrary SQL functions under the identity of that superuser. The attacker must have permission to create objects in the new extension's schema or a schema of a prerequisite extension. Not all extensions are vulnerable. In addition to correcting the extensions provided with PostgreSQL, the PostgreSQL Global Development Group is issuing guidance for third-party extension authors to secure their own work. The PostgreSQL project thanks Andres Freund for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:11.9。组件:core server。
官方受影响分支记录:11。
AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2020-14349 · Uncontrolled search path element in logical replication · CVSS 7.5
The PostgreSQL search_path setting determines schemas searched for tables, functions, operators, etc. The CVE-2018-1058 fix caused most PostgreSQL-provided client applications to sanitize search_path , but logical replication continued to leave search_path unchanged. Users of a replication publisher or subscriber database can create objects in the public schema and harness them to execute arbitrary SQL functions under the identity running replication, often a superuser. Installations having adopted a documented secure schema usage pattern are not vulnerable. The PostgreSQL project thanks Noah Misch for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:11.9。组件:core server。
官方受影响分支记录:11。
AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2020-10733 · Windows installer runs executables from uncontrolled directories · CVSS 6.7
The Windows installer for PostgreSQL invokes system-provided executables that do not have fully-qualified paths. Executables in the directory where the installer loads or the current working directory take precedence over the intended executables. An attacker having permission to add files into one of those directories can use this to execute arbitrary code with the installer's administrative rights. The PostgreSQL project thanks Hou JingYi (@hjy79425575) for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:11.8。组件:packaging。
官方受影响分支记录:11。
AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
CVE-2019-3466 · pg_ctlcluster script in postgresql-common does not drop privileges when creating socket/statistics temporary directories · CVSS 8.4
A PostgreSQL superuser could escalate to root using a deficiency in the pg_ctlcluster command. pg_ctlcluster is a utility provided by the "postgresql-common" package that is installed with PostgreSQL on Debian and Ubuntu platforms.
以上保留官方英文漏洞说明。
本分支修复于:11.6。组件:packaging。
官方受影响分支记录:11。
AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
CVE-2019-10211 · Windows installer bundled OpenSSL executes code from unprotected directory · CVSS 7.8
When the database server or libpq client library initializes SSL, libeay32.dll attempts to read configuration from a hard-coded directory. Typically, the directory does not exist, but any local user could create it and inject configuration. This configuration can direct OpenSSL to load and execute arbitrary code as the user running a PostgreSQL server or client. Most PostgreSQL client tools and libraries use libpq , and one can encounter this vulnerability by using any of them. This vulnerability is much like CVE-2019-5443 , but it originated independently. One can work around the vulnerability by setting environment variable OPENSSL_CONF to "NUL:/openssl.cnf" or any other name that cannot exist as a file. The PostgreSQL project thanks Daniel Gustafsson of the curl security team for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:11.5。组件:packaging。
官方受影响分支记录:11。
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE-2019-10210 · Windows installer writes superuser password to unprotected temporary file · CVSS 6.7
The EnterpriseDB Windows installer writes a password to a temporary file in its installation directory, creates initial databases, and deletes the file. During those seconds while the file exists, a local attacker can read the PostgreSQL superuser password from the file. The PostgreSQL project thanks Noah Misch for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:11.5。组件:packaging。
官方受影响分支记录:11。
AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
CVE-2019-10209 · Memory disclosure in cross-type comparison for hashed subplan · CVSS 3.1
In a database containing hypothetical, user-defined hash equality operators, an attacker could read arbitrary bytes of server memory. For an attack to become possible, a superuser would need to create unusual operators. It is possible for operators not purpose-crafted for attack to have the properties that enable an attack, but we are not aware of specific examples. The PostgreSQL project thanks Andreas Seltenreich for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:11.5。组件:core server。
官方受影响分支记录:11。
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
发布说明中的提及:
CVE-2019-10208 · TYPE in pg_temp executes arbitrary SQL during SECURITY DEFINER execution · CVSS 7.5
Given a suitable SECURITY DEFINER function, an attacker can execute arbitrary SQL under the identity of the function owner. An attack requires EXECUTE permission on the function, which must itself contain a function call having inexact argument type match. For example, length('foo'::varchar) and length('foo') are inexact, while length('foo'::text) is exact. As part of exploiting this vulnerability, the attacker uses CREATE DOMAIN to create a type in a pg_temp schema. The attack pattern and fix are similar to that for CVE-2007-2138 . Writing SECURITY DEFINER functions continues to require following the considerations noted in the documentation: https://www.postgresql.org/docs/current/sql-createfunction.html#SQL-CREATEFUNCTION-SECURITY The PostgreSQL project thanks Tom Lane for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:11.5。组件:core server。
官方受影响分支记录:11。
AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2019-10164 · Stack-based buffer overflow via setting a password · CVSS 7.5
An authenticated user could create a stack-based buffer overflow by changing their own password to a purpose-crafted value. In addition to the ability to crash the PostgreSQL server, this could be further exploited to execute arbitrary code as the PostgreSQL operating system account. Additionally, a rogue server could send a specifically crafted message during the SCRAM authentication process and cause a libpq-enabled client to either crash or execute arbitrary code as the client's operating system account. This issue is fixed by upgrading and restarting your PostgreSQL server as well as your libpq installations. The PostgreSQL Project thanks Alexander Lakhin for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:11.4。组件:core server。
官方受影响分支记录:11。
AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2019-10130 · Selectivity estimators bypass row security policies · CVSS 3.1
PostgreSQL maintains statistics for tables by sampling data available in columns; this data is consulted during the query planning process. Prior to this release, a user able to execute SQL queries with permissions to read a given column could craft a leaky operator that could read whatever data had been sampled from that column. If this happened to include values from rows that the user is forbidden to see by a row security policy, the user could effectively bypass the policy. This is fixed by only allowing a non-leakproof operator to use this data if there are no relevant row security policies for the table. The PostgreSQL project thanks Dean Rasheed for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:11.3。组件:core server。
官方受影响分支记录:11。
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
发布说明中的提及:
CVE-2019-10129 · Memory disclosure in partition routing · CVSS 6.5
Prior to this release, a user running PostgreSQL 11 can read arbitrary bytes of server memory by executing a purpose-crafted INSERT statement to a partitioned table.
以上保留官方英文漏洞说明。
本分支修复于:11.3。组件:core server。
官方受影响分支记录:11。
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
发布说明中的提及:
CVE-2019-10128 · EnterpriseDB Windows installer does not clear permissive ACL entries · CVSS 7.0
Due to both the EnterpriseDB and BigSQL Windows installers not locking down the permissions of the PostgreSQL binary installation directory and the data directory, an unprivileged Windows user account and an unprivileged PostgreSQL account could cause the PostgreSQL service account to execute arbitrary code. This vulnerability is present in all supported versions of PostgreSQL for these installers, and possibly exists in older versions. Both sets of installers have fixed the permissions for these directories for both new and existing installations. If you have installed PostgreSQL on Windows using other methods, we advise that you check that your PostgreSQL binary directories are writable only to trusted users and that your data directories are only accessible to trusted users. The PostgreSQL project thanks Conner Jones for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:11.3。组件:packaging。
官方受影响分支记录:11。
AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE-2019-10127 · BigSQL Windows installer does not clear permissive ACL entries. · CVSS 7.0
Due to both the EnterpriseDB and BigSQL Windows installers not locking down the permissions of the PostgreSQL binary installation directory and the data directory, an unprivileged Windows user account and an unprivileged PostgreSQL account could cause the PostgreSQL service account to execute arbitrary code. This vulnerability is present in all supported versions of PostgreSQL for these installers, and possibly exists in older versions. Both sets of installers have fixed the permissions for these directories for both new and existing installations. If you have installed PostgreSQL on Windows using other methods, we advise that you check that your PostgreSQL binary directories are writable only to trusted users and that your data directories are only accessible to trusted users. The PostgreSQL project thanks Conner Jones for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:11.3。组件:packaging。
官方受影响分支记录:11。
AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE-2018-16850 · SQL injection in pg_upgrade and pg_dump, via CREATE TRIGGER ... REFERENCING. · CVSS 8.8
CVE-2018-1058 · Uncontrolled search path element in pg_dump and other client applications · CVSS 8.8
尚未记录本分支的修复版本。组件:client。
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2017-7484 · selectivity estimators bypass SELECT privilege checks · CVSS 4.3
尚未记录本分支的修复版本。组件:core server。
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
发布说明中的提及: