CVE-2021-46658: Medium severity mariadb server vulnerability
savewindowfunctionvalues in MariaDB before 10.6.3 allows an application crash because of incorrect handling of withwindowfunc=true for a subquery.
Other sources
savewindowfunctionvalues in MariaDB before 10.6.3 allows an application crash because of incorrect handling of withwindowfunc=true for IN subquery.
Reference: https://jira.mariadb.org/browse/MDEV-25630 Upstream patch: http://lists.askmonty.org/pipermail/commits/2021-May/014627.html
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-46658?
CVE-2021-46658 has a high severity due to the potential for application crashes.
How do I fix CVE-2021-46658?
To fix CVE-2021-46658, upgrade MariaDB to version 10.6.3 or later.
Which versions of MariaDB are affected by CVE-2021-46658?
CVE-2021-46658 affects MariaDB versions before 10.6.3, specifically versions 10.2.0 to 10.2.40, 10.3.0 to 10.3.31, 10.4.0 to 10.4.21, and 10.5.0 to 10.5.12.
What is the impact of exploiting CVE-2021-46658?
Exploiting CVE-2021-46658 can lead to an application crash when handling subqueries with window functions.
Is there a workaround for CVE-2021-46658?
There are no known workarounds for CVE-2021-46658; the only solution is to update to the fixed version.