aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorTom Lane <tgl@sss.pgh.pa.us>2025-05-05 11:29:49 -0400
committerTom Lane <tgl@sss.pgh.pa.us>2025-05-05 11:29:49 -0400
commit5dff5ce8636660772f23493918e69af91c820321 (patch)
tree27f0d3d196e6c929c6595f248087316d2398867d
parentcbadeaca9271a1bade8ef9790bae09dc92e0ed30 (diff)
downloadpostgresql-5dff5ce8636660772f23493918e69af91c820321.tar.gz
postgresql-5dff5ce8636660772f23493918e69af91c820321.zip
Last-minute updates for release notes.
Security: CVE-2025-4207
-rw-r--r--doc/src/sgml/release-13.sgml35
1 files changed, 34 insertions, 1 deletions
diff --git a/doc/src/sgml/release-13.sgml b/doc/src/sgml/release-13.sgml
index 165d7067ac3..2bc1476d956 100644
--- a/doc/src/sgml/release-13.sgml
+++ b/doc/src/sgml/release-13.sgml
@@ -31,7 +31,7 @@
<para>
However, if you have any self-referential foreign key constraints on
partitioned tables, it may be necessary to recreate those constraints
- to ensure that they are being enforced correctly. See the first
+ to ensure that they are being enforced correctly. See the second
changelog entry below.
</para>
@@ -48,6 +48,39 @@
<listitem>
<!--
+Author: Noah Misch <noah@leadboat.com>
+Branch: master [627acc3ca] 2025-05-05 04:52:04 -0700
+Branch: REL_17_STABLE [ec5f89e8a] 2025-05-05 04:52:07 -0700
+Branch: REL_16_STABLE [d1264948f] 2025-05-05 04:52:07 -0700
+Branch: REL_15_STABLE [44ba3f55f] 2025-05-05 04:52:08 -0700
+Branch: REL_14_STABLE [3f2ab7393] 2025-05-05 04:52:08 -0700
+Branch: REL_13_STABLE [cbadeaca9] 2025-05-05 04:52:08 -0700
+Branch: master [5be213caa] 2025-05-05 04:52:04 -0700
+Branch: REL_17_STABLE [617d34908] 2025-05-05 04:52:07 -0700
+Branch: REL_16_STABLE [f3bb0b2c4] 2025-05-05 04:52:07 -0700
+Branch: REL_15_STABLE [45fe7e08f] 2025-05-05 04:52:08 -0700
+Branch: REL_14_STABLE [258cde839] 2025-05-05 04:52:08 -0700
+Branch: REL_13_STABLE [7279e5820] 2025-05-05 04:52:08 -0700
+-->
+ <para>
+ Avoid one-byte buffer overread when examining invalidly-encoded
+ strings that are claimed to be in GB18030 encoding
+ (Noah Misch, Andres Freund)
+ <ulink url="&commit_baseurl;cbadeaca9">&sect;</ulink>
+ <ulink url="&commit_baseurl;7279e5820">&sect;</ulink>
+ </para>
+
+ <para>
+ While unlikely, a SIGSEGV crash could occur if an incomplete
+ multibyte character appeared at the end of memory. This was
+ possible both in the server and
+ in <application>libpq</application>-using applications.
+ (CVE-2025-4207)
+ </para>
+ </listitem>
+
+ <listitem>
+<!--
Author: Álvaro Herrera <alvherre@kurilemu.de>
Branch: master [c83a38758] 2025-05-02 21:25:50 +0200
Branch: REL_17_STABLE [f51ae3187] 2025-05-02 21:25:50 +0200