AWS Security ChangesHomeSearch

AWS redshift: Redshift patch 205 release notes add security and auth features

Service: redshift · 2026-09-27 · Documentation high

File: redshift/latest/mgmt/cluster-versions.md · Type: auth

Summary

Adds Amazon Redshift patch 205 release notes, including account lockout protection, configurable password minimum length, post-quantum TLS key exchange, IAM/Identity Center identity tracking, IAM_ROLE 'SESSION' support, CloudTrail queryUuid correlation, and a DEBUG permission for federated permissions catalog databases, plus various bug fixes.

Security assessment

The diff documents new authentication hardening (account lockout, password minimum length), encryption improvements (post-quantum TLS), and IAM/audit identity features. These are security-relevant feature additions and best-practice guidance, but the diff does not reference a specific vulnerability, CVE, or incident being fixed.

Evidence

+  * Added account lockout protection: User accounts are now temporarily locked after repeated consecutive failed sign-in attempts. Administrators can configure the threshold with `ALTER SYSTEM SET max_failed_login_attempts` (range 2–50, default 5).

Diff

diff --git a/redshift/latest/mgmt/cluster-versions.md b/redshift/latest/mgmt/cluster-versions.md
index c43bd6543..a6a6adec9 100644
--- a//redshift/latest/mgmt/cluster-versions.md
+++ b//redshift/latest/mgmt/cluster-versions.md
@@ -7 +7 @@
-Patch 204Patch 203Patch 202Patch 201Patch 200Patch 199Patch 198Patch 197Patch 196Patch 195Patch 194Patch 193Patch 192Patch 191Patch 190Patch 189Patch 188Patch 187Patch 186Patch 185Patch 184Patch 183Patch 182Patch 181Patch 180Patch 179Patch 178Patch 177Patch 176Patch 175Patch 174Patch 173Patch 172Patch 171Patch 170Patch 169Patch 168
+Patch 205Patch 204Patch 203Patch 202Patch 201Patch 200Patch 199Patch 198Patch 197Patch 196Patch 195Patch 194Patch 193Patch 192Patch 191Patch 190Patch 189Patch 188Patch 187Patch 186Patch 185Patch 184Patch 183Patch 182Patch 181Patch 180Patch 179Patch 178Patch 177Patch 176Patch 175Patch 174Patch 173Patch 172Patch 171Patch 170Patch 169Patch 168
@@ -25,0 +26,2 @@ Critical updates that affect Amazon Redshift behavior are introduced as Amazon R
+  * Amazon Redshift patch 205
+
@@ -102,0 +105,76 @@ Critical updates that affect Amazon Redshift behavior are introduced as Amazon R
+## Amazon Redshift patch 205
+
+Cluster versions in this patch:
+
+  * 1.0.434008 – **CURRENT Track** Amazon Redshift provisioned cluster version and Amazon Redshift Serverless workgroup version – Released September 16, 2026
+
+
+
+
+### New features and improvements in this patch
+
+  * Iceberg MV – Materialized views stored in Iceberg offering incremental refresh and full recompute.
+
+  * System tables now include an `external_user_id` column that records the durable IAM or IAM Identity Center identity associated with each query, enabling per-user filtering across cluster lifecycle events.
+
+  * Amazon Redshift Spectrum queries on external tables now support reading gzip and bzip2 compressed Text/CSV files.
+
+  * Added support for the IAM_ROLE 'SESSION' keyword for COPY and UNLOAD, allowing customers to use session-bound FAS credentials for Amazon S3 access instead of specifying an explicit IAM role ARN.
+
+  * Added `ALTER DATABASE ... INTEGRATION REFRESH REMEDIABLE TABLES`, which resynchronizes zero-ETL tables flagged with a duplicate-date warning on demand, optionally scoped to a schema.
+
+  * Added the `IntegrationLatestSourceCommit` Amazon CloudWatch metric for zero-ETL integrations, reporting the latest source commit time observed so you can distinguish an idle source from a stalled pipeline.
+
+  * Amazon Redshift now lets an administrator raise the minimum length required for database user passwords using `ALTER SYSTEM SET passwd_min_length = N` (8–32).
+
+  * Fixed an issue where `ALTER IDENTITY PROVIDER ... ENABLE` failed with an incorrect-parameters error on Azure identity providers configured to automatically create roles.
+
+  * Amazon Redshift now supports post-quantum hybrid key exchange (`X25519MLKEM768`) for TLS connections.
+
+  * Amazon Redshift now supports a `DEBUG` permission on federated permissions catalog databases, letting a global identity, an IAM Identity Center (IdC) group, or a consumer account's administrators view unredacted secure logging records for fine-grained access control (FGAC)-protected data.
+
+  * Amazon Redshift now supports scoped permissions with Metadata Security.
+
+  * Iceberg tables can now be created with a NOT NULL column constraint.
+
+  * Amazon CloudTrail audit events for Amazon Redshift-initiated API calls now include a `queryUuid` field for correlation with system tables.
+
+  * Renamed the `user_query_uuid` column to `query_uuid` in system tables and views for consistency.
+
+  * Improved query performance and availability on clusters with zero-ETL integrations under high query concurrency.
+
+  * Permission checks on tables with a large number of columns and few column-level permissions are now faster, which speeds up metadata queries and client tools that list table privileges.
+
+  * Enhanced stability for queries that use Lambda UDFs in Aggregates.
+
+  * Automatic bloat removal now lets the superblock shrink to fit its live header set, removing the need to reclaim bloat through Superblock Vacuum (SBV).
+
+  * Improved automatic table sort to reduce storage growth on tables with a large number of columns.
+
+  * Fixed an issue that could stop automatic vacuum from running on a cluster until the cluster was restarted.
+
+  * Fixed an issue that could cause a cluster restart during a vacuum operation on clusters using automatic workload management with concurrency scaling.
+
+  * Fixed a bug that could lead to errors with type inference for recursive CTEs containing string literals.
+
+  * Fixed an issue where federated PostgreSQL queries could hang on an unresponsive remote database and ignore cancellation requests.
+
+  * Fixed a rare cluster restart caused by a double-free in COPY load state management under memory pressure.
+
+  * Fixed an issue where `SHOW` discovery commands could not find results when given a long pattern in the `LIKE` clause.
+
+  * Fixed an issue where creating or publishing a datashare could fail on a cluster that had reached its maximum number of database roles.
+
+  * Canceling a `DROP DATABASE` command now ends the command with an error instead of causing an unexpected cluster restart.
+
+  * Improved reliability of stored procedures that query Iceberg tables multiple times followed by a query on a local table when concurrency scaling is in use.
+
+  * Improved reliability of sessions that mix Iceberg cursors with non-Iceberg queries when concurrency scaling is enabled.
+
+  * Added the capability to make the fdisk fetch-block IPC wait cancellable so a lost ACK becomes a killable query instead of an unkillable hang.
+
+  * Improved the reliability of the internal process used during Online Elastic Resize to make the process more deterministic/robust.
+
+
+
+
@@ -106,0 +185,4 @@ Cluster versions in this patch:
+  * 1.0.436211 – **TRAILING Track** Amazon Redshift provisioned cluster version and Amazon Redshift Serverless workgroup version – Released September 22, 2026
+
+  * 1.0.436211 – **CURRENT Track** Amazon Redshift provisioned cluster version and Amazon Redshift Serverless workgroup version – Released September 10, 2026
+
@@ -127,0 +210,2 @@ Cluster versions in this patch:
+  * Added account lockout protection: User accounts are now temporarily locked after repeated consecutive failed sign-in attempts. Administrators can configure the threshold with `ALTER SYSTEM SET max_failed_login_attempts` (range 2–50, default 5).
+
@@ -133,0 +218,2 @@ Cluster versions in this patch:
+  * Added new bin packing metrics columns to the `stl_fasma_data_cache_stats` system table for monitoring cache activity.
+
@@ -164,2 +249,0 @@ Cluster versions in this patch:
-  * Queries that reference user temporary tables can now utilize concurrency scaling.
-
@@ -270,2 +353,0 @@ Cluster versions in this patch:
-  * Improved the DROP USER error message to include the number of object ownerships and privileges that must be resolved before the user can be dropped.
-
@@ -454,2 +535,0 @@ Cluster versions in this patch:
-  * Improved the DROP USER error message to include the number of object ownerships and privileges that must be resolved before the user can be dropped. 
-