From: Tom Lane Date: Mon, 9 May 2022 18:29:53 +0000 (-0400) Subject: Last-minute updates for release notes. X-Git-Tag: REL_12_11~1 X-Git-Url: http://git.ipfire.org/?a=commitdiff_plain;h=b4516b1aea7ac98bc21b47a66ad384f50c2bd2b7;p=thirdparty%2Fpostgresql.git Last-minute updates for release notes. Security: CVE-2022-1552 --- diff --git a/doc/src/sgml/release-12.sgml b/doc/src/sgml/release-12.sgml index e3ea4d4635e..1ce9a20f9b5 100644 --- a/doc/src/sgml/release-12.sgml +++ b/doc/src/sgml/release-12.sgml @@ -35,6 +35,49 @@ + + Confine additional operations within security restricted + operation sandboxes (Sergey Shinderuk, Noah Misch) + + + + Autovacuum, CLUSTER, CREATE + INDEX, REINDEX, REFRESH + MATERIALIZED VIEW, + and pg_amcheck activated + the security restricted operation protection + mechanism too late, or even not at all in some code paths. + A user having permission to create non-temporary objects within a + database could define an object that would execute arbitrary SQL + code with superuser permissions the next time that autovacuum + processed the object, or that some superuser ran one of the affected + commands against it. + + + + The PostgreSQL Project thanks + Alexander Lakhin for reporting this problem. + (CVE-2022-1552) + + + + + - - Disallow infinite endpoints in the timestamp variants - of generate_series() (Tom Lane) - - - - Previously, such a call would run until canceled (or - out-of-disk-space). The numeric variant already threw an error for - an infinite endpoint value, so do likewise for timestamps. - - - - - + + Avoid core dump in parser for a VALUES clause with + zero columns (Tom Lane) + + + + +