ืขื“ื›ื•ืŸ PostgreSQL ืขื ืคื’ื™ืขื•ื™ื•ืช ืฉืชื•ืงื ื•

ื ื•ืฆืจื• ืขื“ื›ื•ื ื™ื ืžืชืงื ื™ื ืขื‘ื•ืจ ื›ืœ ืกื ื™ืคื™ PostgreSQL ื”ื ืชืžื›ื™ื: 13.3, 12.7, 11.12, 10.17 ื•-9.6.22. ืขื“ื›ื•ื ื™ื ืขื‘ื•ืจ ืกื ื™ืฃ 9.6 ื™ื•ืคืงื• ืขื“ ื ื•ื‘ืžื‘ืจ 2021, 10 ืขื“ ื ื•ื‘ืžื‘ืจ 2022, 11 ืขื“ ื ื•ื‘ืžื‘ืจ 2023, 12 ืขื“ ื ื•ื‘ืžื‘ืจ 2024, 13 ืขื“ ื ื•ื‘ืžื‘ืจ 2025. ื”ืžื”ื“ื•ืจื•ืช ื”ื—ื“ืฉื•ืช ืžื‘ื˜ืœื•ืช ืฉืœื•ืฉ ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื•ืžืชืงื ื•ืช ืฉื’ื™ืื•ืช ืฉื”ืฆื˜ื‘ืจื•.

ืคื’ื™ืขื•ืช CVE-2021-32027 ืขืœื•ืœื” ืœื’ืจื•ื ืœื›ืชื™ื‘ืช ืžืื’ืจ ืžื—ื•ืฅ ืœืชื—ื•ื ืขืงื‘ ื”ืฆืคืช ืžืกืคืจื™ื ืฉืœืžื™ื ื‘ืžื”ืœืš ื—ื™ืฉื•ื‘ื™ ืื™ื ื“ืงืก ืžืขืจืš. ืขืœ ื™ื“ื™ ืžื ื™ืคื•ืœืฆื™ื” ืฉืœ ืขืจื›ื™ ืžืขืจืš ื‘ืฉืื™ืœืชื•ืช SQL, ืชื•ืงืฃ ืขื ื’ื™ืฉื” ืœื‘ื™ืฆื•ืข ืฉืื™ืœืชื•ืช SQL ื™ื›ื•ืœ ืœื›ืชื•ื‘ ื›ืœ ื ืชื•ื ื™ื ืœืื–ื•ืจ ืฉืจื™ืจื•ืชื™ ืฉืœ ื–ื™ื›ืจื•ืŸ ื”ืชื”ืœื™ืš ื•ืœื”ืฉื™ื’ ื‘ื™ืฆื•ืข ืฉืœ ื”ืงื•ื“ ืฉืœื• ืขื ื”ื–ื›ื•ื™ื•ืช ืฉืœ ืฉืจืช DBMS. ืฉืชื™ ืคื’ื™ืขื•ื™ื•ืช ื ื•ืกืคื•ืช (CVE-2021-32028, CVE-2021-32029) ืžื•ื‘ื™ืœื•ืช ืœื“ืœื™ืคื” ืฉืœ ืชื•ื›ืŸ ื–ื™ื›ืจื•ืŸ ื”ืชื”ืœื™ืš ื‘ืขืช ืžื ื™ืคื•ืœืฆื™ื” ืฉืœ ื‘ืงืฉื•ืช "ื”ื›ื ืก ... ื‘ืงื•ื ืคืœื™ืงื˜ ... DO UPDATE" ื•-"ืขื“ื›ื•ืŸ ... ื—ื•ื–ืจ".

ืชื™ืงื•ื ื™ ืื™-ืคื’ื™ืขื•ืช ื›ื•ืœืœื™ื:

  • ื”ืกืจ ื—ื™ืฉื•ื‘ื™ื ืฉื’ื•ื™ื™ื ื‘ืขืช ื‘ื™ืฆื•ืข "ืขื“ื›ื•ืŸ...ื”ื—ื–ืจื”" ื›ื“ื™ ืœืขื“ื›ืŸ ื˜ื‘ืœืื•ืช ืžืจื•ืกืงื•ืช ืฉื”ืฆื˜ืจืคื•.
  • ืชืงืŸ ื›ืฉืœ ื‘ืคืงื•ื“ื” "ALTER TABLE ... ALTER CONSTRAINT" ื›ืืฉืจ ื™ืฉ ืื™ืœื•ืฆื™ ืžืคืชื— ื–ืจ ื‘ืฉื™ืœื•ื‘ ืขื ืฉื™ืžื•ืฉ ื‘ื˜ื‘ืœืื•ืช ืžื—ื•ืœืงื•ืช.
  • ื”ืคื•ื ืงืฆื™ื•ื ืœื™ื•ืช ืฉืœ "COMMIT AND CHAIN" ืฉื•ืคืจื”.
  • ืขื‘ื•ืจ ืžื”ื“ื•ืจื•ืช ื—ื“ืฉื•ืช ืฉืœ FreeBSD, ืžืฆื‘ fdatasync ืžื•ื’ื“ืจ ื›ืขืช ืœ-thatwal_sync_method ื›ื‘ืจื™ืจืช ืžื—ื“ืœ.
  • ื”ืคืจืžื˜ืจ vacuum_cleanup_index_scale_factor ืžื•ืฉื‘ืช ื›ื‘ืจื™ืจืช ืžื—ื“ืœ.
  • ืชื™ืงื•ืŸ ื“ืœื™ืคื•ืช ื–ื™ื›ืจื•ืŸ ื”ืžืชืจื—ืฉื•ืช ื‘ืขืช ืืชื—ื•ืœ ื—ื™ื‘ื•ืจื™ TLS.
  • ื‘ื“ื™ืงื•ืช ื ื•ืกืคื•ืช ื ื•ืกืคื• ืœ-pg_upgrade ืœื ื•ื›ื—ื•ืช ืกื•ื’ื™ ื ืชื•ื ื™ื ื‘ื˜ื‘ืœืื•ืช ืžืฉืชืžืฉื™ื ืฉืœื ื ื™ืชืŸ ืœืฉื“ืจื’.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”