Elasticsearch 9.5.1: false-positive matches in certain boolean queries
Aug 14, 09:22 UTCAug 20, 17:09 UTC
Duration
6d 7h
Impact
Major
Root cause
Not disclosed
Elastic, 90 days
27 incidents
Affected
Not listed by the vendor.
Final update
Elasticsearch 9.5.2 has been released and contains the fix for this issue. Customers running 9.5.0 or 9.5.1 should upgrade to 9.5.2. At this time we are considering this issue resolved and will be providing no further updates.
Timeline
- Resolved · Aug 20, 17:09 UTC
Elasticsearch 9.5.2 has been released and contains the fix for this issue. Customers running 9.5.0 or 9.5.1 should upgrade to 9.5.2. At this time we are considering this issue resolved and will be providing no further updates.
- Identified · Aug 14, 09:22 UTC
Elasticsearch 9.5.1 contains a known issue where boolean queries containing a must, filter, or should clause using a multi-value terms query, alongside a must_not clause on fields with disabled indexing, can still return false-positive matches. While the patch in 9.5.1 (https://github.com/elastic/elasticsearch/pull/155936) resolved the bulk-scorer defect for term and range query paths; multi-value terms queries utilize a different Lucene query type that was not covered by that fix. Time Series Data Streams (TSDB) and columnar indices/data streams remain affected for this query pattern, as indexing is disabled by default on those fields. Affected terms queries may return false-positive matches (including documents that should have been excluded) and report higher document counts than expected. No error is raised, so queries will appear to complete successfully. What you can do: - If you have not yet upgraded to 9.5.*, we recommend deferring the upgrade until version 9.5.2 is available. - If you are already running 9.5.*, contact Elastic Support if you need help determining whether your searches are affected. We have identified the root cause, a fix is in progress, and we are preparing a patch release. We will provide a further update when the fix is ready.
More from Elastic
Full history| Started | Incident | Impact | Duration |
|---|---|---|---|
| Sep 2314:04 UTC | Degraded Performance: Cloud Provisioning Delays | major | 1h 59m |
| Sep 1715:50 UTC | AutoOps node metrics temporarily unavailable in some regions | major | 41m |
| Sep 1613:17 UTC | Elastic Support Portal unavailable | major | 2h 21m |
| Sep 1223:21 UTC | Delayed Metrics in Cloud Console - GCP us-east4 | major | 8h 24m |
| Sep 1001:30 UTC | Kibana access restored for UI-assigned Organization Owners on Hosted deployments | major | 21h |
| Sep 920:44 UTC | Elastic Agent enrollment/check-in failures on 9.5.3 (and 9.4.6) with Fleet remote Elasticsearch output | major | 7d 13h |
From vendors' own status pages and disclosures. Times as reported. Logos via logo.dev; trademarks belong to their owners.