Hi,

CVE-2025-1094[1] introduced a regression that was reported fairly shortly after the release[2]. Based on the nature of the report and the fact it's in libpq, the release team was unsure of what the overall prevalence of the issue given its client-facing, and decided to have an out-of-cycle release on 2025-02-20[3] to handle this sooner than the regularly scheduled release[4].

Per standard release process, any patches being committed for this release must be in by 2025-02-15 12:00 UTC to ensure they have ample time to get through the buildfarm.

Thanks,

Jonathan

[1] https://www.postgresql.org/support/security/CVE-2025-1094/
[2] https://www.postgresql.org/message-id/Z64jD3u46gObCo1p%40pryzbyj2023
[3] https://www.postgresql.org/about/news/out-of-cycle-release-scheduled-for-february-20-2025-3016/
[4] https://www.postgresql.org/developer/roadmap/

Attachment: OpenPGP_signature.asc
Description: OpenPGP digital signature

Reply via email to