Pgpool-II 4.5.4, 4.4.9, 4.3.12, 4.2.19 and 4.1.22 released. - Mailing list pgsql-announce

From Pgpool Global Development Group via PostgreSQL Announce
Subject Pgpool-II 4.5.4, 4.4.9, 4.3.12, 4.2.19 and 4.1.22 released.
Date
Msg-id 172587308013.711.14343159959213596020@wrigleys.postgresql.org
Whole thread Raw
List pgsql-announce
 

Pgpool-II 4.5.4, 4.4.9, 4.3.12, 4.2.19 and 4.1.22 released.

What is Pgpool-II?

Pgpool-II is a tool to add useful features to PostgreSQL, including:

  • connection pooling
  • load balancing
  • automatic failover and more.

Minor releases

Pgpool Global Development Group is pleased to announce the availability of following versions of Pgpool-II:

  • 4.5.4
  • 4.4.9
  • 4.3.12
  • 4.2.19
  • 4.1.22

This release contains a security fix.

When the query cache feature is enabled, it was possible that a database user can read rows from tables that should not be visible for the user through query cache (CVE-2024-45624).

All versions of Pgpool-II older than 4.5.4, 4.4.9, 4.3.12, 4.2.19, 4.1.22, and all older versions that has the query cache feature (the query cache feature was implemented in 3.2) are affected by the vulnerability.

It is strongly recommend to upgrade to Pgpool-II 4.5.4, 4.4.9, 4.3.12, 4.2.19 and 4.1.22 or later. Or you should better turn off the query cache feature.

Please take a look at release notes.

You can download the source code and RPMs.

 

pgsql-announce by date:

Previous
From: Nordic PGDay via PostgreSQL Announce
Date:
Subject: Nordic PGDay 2025 - Call for papers open and accepting sponsors
Next
From: Philippe Beaudoin via PostgreSQL Announce
Date:
Subject: Announcing E-Maj 4.5.0.