CVE-2021-46657: Medium severity mariadb server vulnerability
getsortbytable in MariaDB before 10.6.2 allows an application crash via certain subquery uses of ORDER BY.
Other sources
getsortbytable() in MariaDB before 10.6.2 allows an application crash via certain subquery uses of ORDER BY.
References: 1. https://jira.mariadb.org/browse/MDEV-25629 2. https://bugzilla.suse.com/1195325
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-46657?
CVE-2021-46657 is a vulnerability that can cause application crashes in affected versions of MariaDB.
How do I fix CVE-2021-46657?
To fix CVE-2021-46657, upgrade MariaDB to version 10.6.2 or later.
Which versions of MariaDB are affected by CVE-2021-46657?
CVE-2021-46657 affects MariaDB versions before 10.6.2 as well as several older versions.
What triggers the CVE-2021-46657 vulnerability?
The CVE-2021-46657 vulnerability can be triggered by specific subquery uses of the ORDER BY clause.
Is there any workaround for CVE-2021-46657?
There are no known workarounds for CVE-2021-46657; upgrading is the recommended solution.