CVE-2021-46666: Medium severity mariadb server vulnerability
Published Feb 1, 2022
·Updated
MariaDB before 10.6.2 allows an application crash because of mishandling of a pushdown from a HAVING clause to a WHERE clause.
Affected Software
11 affected componentsFixes available
redhat/mariadb<10.2.39
10.2.39
redhat/mariadb<10.3.30
10.3.30
redhat/mariadb<10.4.20
10.4.20
redhat/mariadb<10.5.11
10.5.11
redhat/mariadb<10.6.2
10.6.2
redhat/mariadb<10.8.1
10.8.1
MariaDB MariaDB<10.2.39
MariaDB MariaDB>=10.3.0<10.3.30
MariaDB MariaDB>=10.4.0<10.4.20
MariaDB MariaDB>=10.5.0<10.5.11
MariaDB MariaDB>=10.6.0<10.6.2
Remediation
Patch Available
Event History
Feb 1, 2022
CVE Published
via MITRE·01:47 AM
Data Sourced
via MITRE·01:47 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2021-46666.
2
What is the severity of CVE-2021-46666?
The severity of CVE-2021-46666 is medium.
3
What is the affected software for CVE-2021-46666?
The affected software for CVE-2021-46666 is MariaDB versions before 10.6.2.
4
How can CVE-2021-46666 be exploited?
CVE-2021-46666 can be exploited by triggering mishandling of a pushdown from a HAVING clause to a WHERE clause in MariaDB.
5
Are there any remediation steps available for CVE-2021-46666?
Yes, upgrading to MariaDB version 10.6.2 or higher will remediate CVE-2021-46666.