Opened 6 weeks ago

Closed 5 weeks ago

#21123 closed enhancement (fixed)

postgresql-17.4

Reported by: Douglas R. Reno Owned by: Douglas R. Reno
Priority: elevated Milestone: 12.3
Component: BOOK Version: git
Severity: normal Keywords:
Cc:

Description

New minor version

This fixes serious regressions with the last release:

  • Improve behavior of quoting functions in libpq. The fix for CVE-2025-1094 caused the quoting functions to not honor their string length parameters and, in some cases, cause crashes. This problem could be noticeable from a PostgreSQL client library, based on how it is integrated with libpq.
  • Fix small memory leak in pg_createsubscriber.

Change History (5)

comment:1 by Douglas R. Reno, 5 weeks ago

Priority: normalelevated

Marking as Elevated because of the severity of the regression from the security update

comment:2 by Xi Ruoyao, 5 weeks ago

Milestone: 12.412.3

Promote the security fixes for 12.3 following the decision to make another tagging round.

comment:3 by Douglas R. Reno, 5 weeks ago

Owner: changed from blfs-book to Douglas R. Reno
Status: newassigned

comment:4 by Douglas R. Reno, 5 weeks ago

Fixed at 48d3638bdd8388f8f7f6ec4d47f5da9567b86159

Security advisory coming shortly

comment:5 by Douglas R. Reno, 5 weeks ago

Resolution: fixed
Status: assignedclosed

SA-12.2-088 issued

Note: See TracTickets for help on using tickets.