First published: Sat Jan 29 2022(Updated: )
MariaDB before 10.7.2 allows an application crash because it does not recognize that SELECT_LEX::nest_level is local to each VIEW.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/mariadb | <10.2.42 | 10.2.42 |
redhat/mariadb | <10.3.33 | 10.3.33 |
redhat/mariadb | <10.4.23 | 10.4.23 |
redhat/mariadb | <10.5.14 | 10.5.14 |
redhat/mariadb | <10.6.6 | 10.6.6 |
redhat/mariadb | <10.7.2 | 10.7.2 |
MariaDB | >=5.5.0<10.2.42 | |
MariaDB | >=10.3.0<10.3.33 | |
MariaDB | >=10.4.0<10.4.23 | |
MariaDB | >=10.5.0<10.5.14 | |
MariaDB | >=10.6.0<10.6.6 | |
MariaDB | >=10.7.0<10.7.2 | |
Red Hat Fedora | =34 | |
Red Hat Fedora | =35 | |
Red Hat Fedora | =36 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-46659 is considered to be high due to the potential application crash.
To fix CVE-2021-46659, upgrade to MariaDB version 10.7.2 or later.
CVE-2021-46659 affects MariaDB versions prior to 10.7.2 across several earlier versions.
CVE-2021-46659 is a denial of service vulnerability that can lead to an application crash.
There are no known effective workarounds for CVE-2021-46659 other than upgrading to a secure version.