First published: Sat Jan 29 2022(Updated: )
get_sort_by_table in MariaDB before 10.6.2 allows an application crash via certain subquery uses of ORDER BY.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/mariadb | <10.6.2 | 10.6.2 |
redhat/mariadb | <10.2.39 | 10.2.39 |
redhat/mariadb | <10.3.30 | 10.3.30 |
redhat/mariadb | <10.4.20 | 10.4.20 |
redhat/mariadb | <10.5.11 | 10.5.11 |
MariaDB Server | >=5.5.20<=5.5.68 | |
MariaDB Server | >=10.0.0<10.2.39 | |
MariaDB Server | >=10.3.0<10.3.30 | |
MariaDB Server | >=10.4.0<10.4.20 | |
MariaDB Server | >=10.5.0<10.5.11 | |
MariaDB Server | >=10.6.0<10.6.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-46657 is a vulnerability that can cause application crashes in affected versions of MariaDB.
To fix CVE-2021-46657, upgrade MariaDB to version 10.6.2 or later.
CVE-2021-46657 affects MariaDB versions before 10.6.2 as well as several older versions.
The CVE-2021-46657 vulnerability can be triggered by specific subquery uses of the ORDER BY clause.
There are no known workarounds for CVE-2021-46657; upgrading is the recommended solution.