First published: Tue Feb 01 2022(Updated: )
MariaDB through 10.5.13 allows a ha_maria::extra application crash via certain SELECT statements.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/mariadb | <10.2.43 | 10.2.43 |
redhat/mariadb | <10.3.34 | 10.3.34 |
redhat/mariadb | <10.4.24 | 10.4.24 |
redhat/mariadb | <10.5.15 | 10.5.15 |
redhat/mariadb | <10.6.7 | 10.6.7 |
redhat/mariadb | <10.7.3 | 10.7.3 |
redhat/mariadb | <10.8.2 | 10.8.2 |
MariaDB | >=10.2.41<10.2.43 | |
MariaDB | >=10.3.32<10.3.34 | |
MariaDB | >=10.4.22<10.4.24 | |
MariaDB | >=10.5.9<10.5.15 | |
MariaDB | >=10.6.0<10.6.7 | |
MariaDB | >=10.7.0<10.7.3 | |
Red Hat Fedora | =34 | |
Red Hat Fedora | =35 | |
Red Hat Fedora | =36 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-46663 is classified as a vulnerability that could lead to application crashes under specific conditions.
To address CVE-2021-46663, upgrade MariaDB to version 10.2.43, 10.3.34, 10.4.24, 10.5.15, 10.6.7, or 10.7.3.
CVE-2021-46663 affects MariaDB versions up to and including 10.5.13.
If CVE-2021-46663 is not fixed, certain SELECT statements may cause the ha_maria application to crash.
There is no specific workaround for CVE-2021-46663; updating to a safe version is recommended.