diff --git a/doc/src/sgml/release-9.6.sgml b/doc/src/sgml/release-9.6.sgml
index 54d1cf7a380..a273c649a2d 100644
--- a/doc/src/sgml/release-9.6.sgml
+++ b/doc/src/sgml/release-9.6.sgml
@@ -35,6 +35,30 @@
+
+ Add missing permissions checks for ALTER ... DEPENDS ON
+ EXTENSION (Álvaro Herrera)
+
+
+
+ Marking an object as dependent on an extension did not have any
+ privilege check whatsoever. This oversight allowed any user to mark
+ routines, triggers, materialized views, or indexes as droppable by
+ anyone able to drop an extension. Require that the calling user own
+ the specified object (and hence have privilege to drop it).
+ (CVE-2020-1720)
+
+
+
+
+
+
+ Apply more thorough syntax checking
+ to createuser's
+ option (Álvaro Herrera)
+
+
+
+
+