From 0145ec9be92b2146e7b94f286cb3dab9eb77ef70 Mon Sep 17 00:00:00 2001 From: Tom Lane Date: Mon, 9 Aug 2021 14:41:00 -0400 Subject: [PATCH] Last-minute updates for release notes. Security: CVE-2021-3677 --- doc/src/sgml/release-13.sgml | 46 +++++++++++++++++++----------------- 1 file changed, 24 insertions(+), 22 deletions(-) diff --git a/doc/src/sgml/release-13.sgml b/doc/src/sgml/release-13.sgml index 6184269c891..434ddfca467 100644 --- a/doc/src/sgml/release-13.sgml +++ b/doc/src/sgml/release-13.sgml @@ -35,6 +35,30 @@ + + Fix mis-planning of repeated application of a projection step + (Tom Lane) + + + + The planner could create an incorrect plan in cases where two + ProjectionPaths were stacked on top of each other. The only known + way to trigger that situation involves parallel sort operations, but + there may be other instances. The result would be crashes or + incorrect query results. + Disclosure of server memory contents is also possible. + (CVE-2021-3677) + + + + + - - Fix mis-planning of repeated application of a projection step - (Tom Lane) - - - - The planner could create an incorrect plan in cases where two - ProjectionPaths were stacked on top of each other. The only known - way to trigger that situation involves parallel sort operations, but - there may be other instances. The result would be crashes or - incorrect query results. - - - - -