Re: [EXTERNAL] Re: Asking for OK for a nasty trick to resolve PG CVE-2025-1094 i - Mailing list pgsql-general

From Laurenz Albe
Subject Re: [EXTERNAL] Re: Asking for OK for a nasty trick to resolve PG CVE-2025-1094 i
Date
Msg-id a141ae990b72eadcdbcf79efaa268ac5696f7bdb.camel@cybertec.at
Whole thread Raw
In response to Re: [EXTERNAL] Re: Asking for OK for a nasty trick to resolve PG CVE-2025-1094 i  ("Abraham, Danny" <danny_abraham@bmc.com>)
List pgsql-general
On Thu, 2025-03-06 at 09:33 +0000, Abraham, Danny wrote:
> We have hundreds of pg servers (mainly linux).
> App is 7×24.
> We think that patching the server to 15.12.will cost about 30 times
> more compared to patching the pg client ( mainly qa effort).

I don't think so.  Don't do any QA when installing a PostgreSQL patch
(just roll it out on the test systems first to see if your installation
procedure works).

Down time because of data corruption will cost *way* more than patching.

Yours,
Laurenz Albe



pgsql-general by date:

Previous
From: Laurenz Albe
Date:
Subject: Re: Quesion about querying distributed databases
Next
From: Greg Sabino Mullane
Date:
Subject: Re: Quesion about querying distributed databases