First published: Tue Feb 01 2022(Updated: )
MariaDB before 10.6.5 has a sql_lex.cc integer overflow, leading to an application crash.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mariadb Mariadb | <10.2.41 | |
Mariadb Mariadb | >=10.3.0<10.3.32 | |
Mariadb Mariadb | >=10.4.0<10.4.22 | |
Mariadb Mariadb | >=10.5.0<10.5.13 | |
Mariadb Mariadb | >=10.6.0<10.6.5 | |
Fedoraproject Fedora | =34 | |
Fedoraproject Fedora | =35 | |
Fedoraproject Fedora | =36 | |
redhat/mariadb | <10.2.41 | 10.2.41 |
redhat/mariadb | <10.3.32 | 10.3.32 |
redhat/mariadb | <10.4.22 | 10.4.22 |
redhat/mariadb | <10.5.13 | 10.5.13 |
redhat/mariadb | <10.6.5 | 10.6.5 |
redhat/mariadb | <10.8.1 | 10.8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-46667 is a vulnerability in MariaDB before 10.6.5 that can lead to an application crash due to an integer overflow in sql_lex.cc.
CVE-2021-46667 has a severity rating of medium (5.5).
Versions of MariaDB up to 10.6.5 are affected by CVE-2021-46667.
To fix CVE-2021-46667, update MariaDB to version 10.6.5 or later.
You can find more information about CVE-2021-46667 in the references provided: [Reference 1](https://jira.mariadb.org/browse/MDEV-26350), [Reference 2](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DKJRBYJAQCOPHSED43A3HUPNKQLDTFGD/), [Reference 3](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EZFZVMJL5UDTOZMARLXQIMG3BTG6UNYW/)