↑↓ 选择 ↵ 打开 ⌫ 改范围 完整检索页

pgsql.cc 提供对 postgresql.org 官网内容的中文翻译,由 Pigsty 团队维护。

百科 / 版本发布

PostgreSQL 9.6

已停止支持 · 记录构建 9.6.24 · 2021-11-11

此大版本已停止支持,相关记录用于查阅历史;没有更新的安全记录不代表仍可安全运行。

首次正式发布
2016-09-29
支持结束
2021-11-11
已收录发布版本
25
原始发布说明条目
1105

手册与来源

PostgreSQL 9.6 本站手册 · 已加载 975 页。

手册加载时间:2026-09-27T00:10:45.258078。

发布说明快照:2026-09-26。安全证据快照:2026-09-26。PDF 链接按本地文件是否存在提供,历史版本的语言与 HTML 手册可能不同。生命周期参见官方版本政策。

升级注意事项

跨大版本升级需要导出/恢复或 pg_upgrade 等迁移方式,应阅读沿途大版本的发布说明与目标版本手册。小版本更新也可能要求额外操作,请核对对应发布的迁移说明。官方升级政策。

9.6.0 的兼容性变化 · 从首发到 9.6.24 的变化

9.6.0 的原始迁移说明

希望从任何之前的版本迁移数据的用户,需要使用pg_dumpall进行转储/恢复,或使用pg_upgrade。

版本 9.6 包含许多可能影响与以前版本兼容性的更改。注意以下不兼容之处:

发布历史

每次发布的原始变更均独立保留。CVE 数量表示发布说明中的提及,可能包含后续纠正,不等于本次新修复漏洞数。

版本日期/快照截止时间全部变化BUG 修复迁移条目提及 CVE
9.6.24 2021-11-11 401802
9.6.23 2021-08-12 471602
9.6.22 2021-05-13 231302
9.6.21 2021-02-11 361800
9.6.20 2020-11-12 361003
9.6.19 2020-08-13 271302
9.6.18 2020-05-14 381800
9.6.17 2020-02-13 331701
9.6.16 2019-11-14 532100
9.6.15 2019-08-08 261002
9.6.14 2019-06-20 171100
9.6.13 2019-05-09 331802
9.6.12 2019-02-14 442400
9.6.11 2018-11-08 572700
9.6.10 2018-08-09 331702
9.6.9 2018-05-10 432401
9.6.8 2018-03-01 8401
9.6.7 2018-02-08 372001
9.6.6 2017-11-09 382003
9.6.5 2017-08-31 10300
9.6.4 2017-08-10 603004
9.6.3 2017-05-11 483004
9.6.2 2017-02-09 764700
9.6.1 2016-10-27 281700
9.6.0 2016-09-29 2146130

首次发布变化

9.6.0 的原始条目,包含功能和兼容性变化。类别用于浏览,不是上游原始分类。

匹配 214 / 214 条原始变更。

安全证据

共 34 条记录,来自官方安全矩阵及发布说明的提及。只有安全快照明确列出此分支时才显示修复版本;仅有提及不能确定漏洞适用性或新修复。

CVE-2021-3449 · CVE-2021-3449

尚未记录本分支的修复版本。

发布说明中的提及:

CVE-2021-32028 · Memory disclosure in INSERT ... ON CONFLICT ... DO UPDATE · CVSS 6.5

Using an INSERT ... ON CONFLICT ... DO UPDATE command on a purpose-crafted table, an attacker can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can create prerequisite objects and complete this attack at will. A user lacking the CREATE and TEMPORARY privileges on all databases and the CREATE privilege on all schemas cannot use this attack at will. The PostgreSQL project thanks Andres Freund for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:9.6.22。组件:core server。

官方受影响分支记录:9.6。

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

发布说明中的提及:

CVE-2021-32027 · Buffer overrun from integer overflow in array subscripting calculations · CVSS 6.5

While modifying certain SQL array values, missing bounds checks let authenticated database users write arbitrary bytes to a wide area of server memory. The PostgreSQL project thanks Tom Lane for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:9.6.22。组件:core server。

官方受影响分支记录:9.6。

AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

发布说明中的提及:

CVE-2021-23222 · libpq processes unencrypted bytes from man-in-the-middle · CVSS 3.7

A man-in-the-middle attacker can inject false responses to the client's first few queries, despite the use of SSL certificate verification and encryption. If more preconditions hold, the attacker can exfiltrate the client's password or other confidential data that might be transmitted early in a session. The attacker must have a way to trick the client's intended server into making the confidential data accessible to the attacker. A known implementation having that property is a PostgreSQL configuration vulnerable to CVE-2021-23214 . As with any exploitation of CVE-2021-23214 , the server must be using trust authentication with a clientcert requirement or using cert authentication. To disclose a password, the client must be in possession of a password, which is atypical when using an authentication configuration vulnerable to CVE-2021-23214 . The attacker must have some other way to access the server to retrieve the exfiltrated data (a valid, unprivileged login account would be sufficient). The PostgreSQL project thanks Jacob Champion for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:9.6.24。组件:client。

官方受影响分支记录:9.6。

AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

发布说明中的提及:

CVE-2021-23214 · Server processes unencrypted bytes from man-in-the-middle · CVSS 8.1

When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption. This is similar to CVE-2011-0411 (different product). The PostgreSQL project thanks Jacob Champion for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:9.6.24。组件:core server。

官方受影响分支记录:9.6。

AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

发布说明中的提及:

CVE-2020-25696 · psql's \gset allows overwriting specially treated variables · CVSS 7.5

The \gset meta-command, which sets psql variables based on query results, does not distinguish variables that control psql behavior. If an interactive psql session uses \gset when querying a compromised server, the attacker can execute arbitrary code as the operating system account running psql . Using \gset with a prefix not found among specially treated variables, e.g. any lowercase string, precludes the attack in an unpatched psql . The PostgreSQL project thanks Nick Cleaton for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:9.6.20。组件:client。

官方受影响分支记录:9.6。

AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

发布说明中的提及:

CVE-2020-25695 · Multiple features escape "security restricted operation" sandbox · CVSS 8.8

An attacker having permission to create non-temporary objects in at least one schema can execute arbitrary SQL functions under the identity of a superuser. While promptly updating PostgreSQL is the best remediation for most users, a user unable to do that can work around the vulnerability by disabling autovacuum and not manually running ANALYZE , CLUSTER , REINDEX , CREATE INDEX , VACUUM FULL , REFRESH MATERIALIZED VIEW , or a restore from output of the pg_dump command. Performance may degrade quickly under this workaround. VACUUM without the FULL option is safe, and all commands are fine when a trusted user owns the target object. The PostgreSQL project thanks Etienne Stalmans for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:9.6.20。组件:core server。

官方受影响分支记录:9.6。

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

发布说明中的提及:

CVE-2020-25694 · Reconnection can downgrade connection security settings · CVSS 8.1

Many PostgreSQL-provided client applications have options that create additional database connections. Some of those applications reuse only the basic connection parameters (e.g. host , user , port ), dropping others. If this drops a security-relevant parameter (e.g. channel_binding , sslmode , requirepeer , gssencmode ), the attacker has an opportunity to complete a MITM attack or observe cleartext transmission. Affected applications are clusterdb , pg_dump , pg_restore , psql , reindexdb , and vacuumdb . The vulnerability arises only if one invokes an affected client application with a connection string containing a security-relevant parameter. This also fixes how the \connect command of psql reuses connection parameters, i.e. all non-overridden parameters from a previous connection string now re-used. The PostgreSQL project thanks Peter Eisentraut for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:9.6.20。组件:client。

官方受影响分支记录:9.6。

AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

发布说明中的提及:

CVE-2020-1720 · ALTER ... DEPENDS ON EXTENSION is missing authorization checks. · CVSS 3.1

The ALTER ... DEPENDS ON EXTENSION sub-commands do not perform authorization checks, which can allow an unprivileged user to drop any function, procedure, materialized view, index, or trigger under certain conditions. This attack is possible if an administrator has installed an extension and an unprivileged user can CREATE , or an extension owner either executes DROP EXTENSION predictably or can be convinced to execute DROP EXTENSION . The PostgreSQL project thanks Tom Lane for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:9.6.17。组件:core server。

官方受影响分支记录:9.6。

AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N

发布说明中的提及:

CVE-2020-14350 · Uncontrolled search path element in CREATE EXTENSION · CVSS 7.1

When a superuser runs certain CREATE EXTENSION statements, users may be able to execute arbitrary SQL functions under the identity of that superuser. The attacker must have permission to create objects in the new extension's schema or a schema of a prerequisite extension. Not all extensions are vulnerable. In addition to correcting the extensions provided with PostgreSQL, the PostgreSQL Global Development Group is issuing guidance for third-party extension authors to secure their own work. The PostgreSQL project thanks Andres Freund for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:9.6.19。组件:core server。

官方受影响分支记录:9.6。

AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

发布说明中的提及:

CVE-2020-10733 · Windows installer runs executables from uncontrolled directories · CVSS 6.7

The Windows installer for PostgreSQL invokes system-provided executables that do not have fully-qualified paths. Executables in the directory where the installer loads or the current working directory take precedence over the intended executables. An attacker having permission to add files into one of those directories can use this to execute arbitrary code with the installer's administrative rights. The PostgreSQL project thanks Hou JingYi (@hjy79425575) for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:9.6.18。组件:packaging。

官方受影响分支记录:9.6。

AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

CVE-2019-3466 · pg_ctlcluster script in postgresql-common does not drop privileges when creating socket/statistics temporary directories · CVSS 8.4

A PostgreSQL superuser could escalate to root using a deficiency in the pg_ctlcluster command. pg_ctlcluster is a utility provided by the "postgresql-common" package that is installed with PostgreSQL on Debian and Ubuntu platforms.

以上保留官方英文漏洞说明。

本分支修复于:9.6.16。组件:packaging。

官方受影响分支记录:9.6。

AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H

CVE-2019-10211 · Windows installer bundled OpenSSL executes code from unprotected directory · CVSS 7.8

When the database server or libpq client library initializes SSL, libeay32.dll attempts to read configuration from a hard-coded directory. Typically, the directory does not exist, but any local user could create it and inject configuration. This configuration can direct OpenSSL to load and execute arbitrary code as the user running a PostgreSQL server or client. Most PostgreSQL client tools and libraries use libpq , and one can encounter this vulnerability by using any of them. This vulnerability is much like CVE-2019-5443 , but it originated independently. One can work around the vulnerability by setting environment variable OPENSSL_CONF to "NUL:/openssl.cnf" or any other name that cannot exist as a file. The PostgreSQL project thanks Daniel Gustafsson of the curl security team for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:9.6.15。组件:packaging。

官方受影响分支记录:9.6。

AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVE-2019-10210 · Windows installer writes superuser password to unprotected temporary file · CVSS 6.7

The EnterpriseDB Windows installer writes a password to a temporary file in its installation directory, creates initial databases, and deletes the file. During those seconds while the file exists, a local attacker can read the PostgreSQL superuser password from the file. The PostgreSQL project thanks Noah Misch for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:9.6.15。组件:packaging。

官方受影响分支记录:9.6。

AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

CVE-2019-10208 · TYPE in pg_temp executes arbitrary SQL during SECURITY DEFINER execution · CVSS 7.5

Given a suitable SECURITY DEFINER function, an attacker can execute arbitrary SQL under the identity of the function owner. An attack requires EXECUTE permission on the function, which must itself contain a function call having inexact argument type match. For example, length('foo'::varchar) and length('foo') are inexact, while length('foo'::text) is exact. As part of exploiting this vulnerability, the attacker uses CREATE DOMAIN to create a type in a pg_temp schema. The attack pattern and fix are similar to that for CVE-2007-2138 . Writing SECURITY DEFINER functions continues to require following the considerations noted in the documentation: https://www.postgresql.org/docs/current/sql-createfunction.html#SQL-CREATEFUNCTION-SECURITY The PostgreSQL project thanks Tom Lane for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:9.6.15。组件:core server。

官方受影响分支记录:9.6。

AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

发布说明中的提及:

CVE-2019-10130 · Selectivity estimators bypass row security policies · CVSS 3.1

PostgreSQL maintains statistics for tables by sampling data available in columns; this data is consulted during the query planning process. Prior to this release, a user able to execute SQL queries with permissions to read a given column could craft a leaky operator that could read whatever data had been sampled from that column. If this happened to include values from rows that the user is forbidden to see by a row security policy, the user could effectively bypass the policy. This is fixed by only allowing a non-leakproof operator to use this data if there are no relevant row security policies for the table. The PostgreSQL project thanks Dean Rasheed for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:9.6.13。组件:core server。

官方受影响分支记录:9.6。

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

发布说明中的提及:

CVE-2019-10128 · EnterpriseDB Windows installer does not clear permissive ACL entries · CVSS 7.0

Due to both the EnterpriseDB and BigSQL Windows installers not locking down the permissions of the PostgreSQL binary installation directory and the data directory, an unprivileged Windows user account and an unprivileged PostgreSQL account could cause the PostgreSQL service account to execute arbitrary code. This vulnerability is present in all supported versions of PostgreSQL for these installers, and possibly exists in older versions. Both sets of installers have fixed the permissions for these directories for both new and existing installations. If you have installed PostgreSQL on Windows using other methods, we advise that you check that your PostgreSQL binary directories are writable only to trusted users and that your data directories are only accessible to trusted users. The PostgreSQL project thanks Conner Jones for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:9.6.13。组件:packaging。

官方受影响分支记录:9.6。

AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

CVE-2019-10127 · BigSQL Windows installer does not clear permissive ACL entries. · CVSS 7.0

Due to both the EnterpriseDB and BigSQL Windows installers not locking down the permissions of the PostgreSQL binary installation directory and the data directory, an unprivileged Windows user account and an unprivileged PostgreSQL account could cause the PostgreSQL service account to execute arbitrary code. This vulnerability is present in all supported versions of PostgreSQL for these installers, and possibly exists in older versions. Both sets of installers have fixed the permissions for these directories for both new and existing installations. If you have installed PostgreSQL on Windows using other methods, we advise that you check that your PostgreSQL binary directories are writable only to trusted users and that your data directories are only accessible to trusted users. The PostgreSQL project thanks Conner Jones for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:9.6.13。组件:packaging。

官方受影响分支记录:9.6。

AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

CVE-2018-1115 · Too-permissive access control list on function pg_logfile_rotate() · CVSS 3.1

本分支修复于:9.6.9。组件:contrib module。

官方受影响分支记录:9.6。

AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N

发布说明中的提及:

CVE-2018-10925 · Memory disclosure and missing authorization in INSERT ... ON CONFLICT DO UPDATE. · CVSS 7.1

本分支修复于:9.6.10。组件:core server。

官方受影响分支记录:9.6。

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

发布说明中的提及:

CVE-2018-10915 · Certain host connection parameters defeat client-side security defenses · CVSS 8.5

本分支修复于:9.6.10。组件:client。

官方受影响分支记录:9.6。

AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

发布说明中的提及:

CVE-2018-1058 · Uncontrolled search path element in pg_dump and other client applications · CVSS 8.8
CVE-2018-1053 · pg_upgrade creates file of sensitive metadata under prevailing umask · CVSS 6.7

本分支修复于:9.6.7。组件:client。

官方受影响分支记录:9.6。

AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

发布说明中的提及:

CVE-2017-7548 · lo_put() function ignores ACLs · CVSS 3.1

本分支修复于:9.6.4。组件:core server。

官方受影响分支记录:9.6。

AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N

发布说明中的提及:

CVE-2017-7547 · pg_user_mappings view discloses passwords to users lacking server privileges · CVSS 8.5
CVE-2017-7546 · empty password accepted in some authentication methods · CVSS 8.1

本分支修复于:9.6.4。组件:core server。

官方受影响分支记录:9.6。

AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

发布说明中的提及:

CVE-2017-7486 · pg_user_mappings view discloses foreign server passwords · CVSS 8.5
CVE-2017-7485 · libpq ignores PGREQUIRESSL environment variable · CVSS 8.1

本分支修复于:9.6.3。组件:client。

官方受影响分支记录:9.6。

AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

发布说明中的提及:

CVE-2017-7484 · selectivity estimators bypass SELECT privilege checks · CVSS 4.3

本分支修复于:9.6.3。组件:core server。

官方受影响分支记录:9.6。

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

发布说明中的提及:

CVE-2017-15099 · INSERT ... ON CONFLICT DO UPDATE fails to enforce SELECT privileges · CVSS 3.1

本分支修复于:9.6.6。组件:core server。

官方受影响分支记录:9.6。

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

发布说明中的提及:

CVE-2017-15098 · Memory disclosure in JSON functions · CVSS 4.3

本分支修复于:9.6.6。组件:core server。

官方受影响分支记录:9.6。

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

发布说明中的提及:

CVE-2017-12172 · Start scripts permit database administrator to modify root-owned files · CVSS 8.4

本分支修复于:9.6.6。组件:contrib module。

官方受影响分支记录:9.6。

AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H

发布说明中的提及:

CVE-2007-2138 · A vulnerability involving insecure search_path settings allows unprivileged users to gain the SQL privileges of the owner of any SECURITY DEFINER function they are allowed to call. Securing such a function requires both a software update and changes to the function definition.

尚未记录本分支的修复版本。

发布说明中的提及:

CVE-2006-2313 · An attacker able to submit crafted strings to an application that will embed those strings in SQL commands can use invalidly-encoded multibyte characters to bypass standard string-escaping methods, resulting in possible SQL injection.

导出此分支 JSON · 比较已收录的发布版本