First published: Tue Feb 01 2022(Updated: )
MariaDB through 10.5.9 allows an application crash via certain long SELECT DISTINCT statements that improperly interact with storage-engine resource limitations for temporary data structures.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mariadb Mariadb | >=10.2.0<10.2.43 | |
Mariadb Mariadb | >=10.3.0<10.3.34 | |
Mariadb Mariadb | >=10.4.0<10.4.24 | |
Mariadb Mariadb | >=10.5.0<10.5.15 | |
Mariadb Mariadb | >=10.6.0<10.6.7 | |
Mariadb Mariadb | >=10.7.0<10.7.3 | |
Fedoraproject Fedora | =34 | |
Fedoraproject Fedora | =35 | |
Fedoraproject Fedora | =36 | |
redhat/mariadb | <10.5.15 | 10.5.15 |
redhat/mariadb | <10.6.7 | 10.6.7 |
redhat/mariadb | <10.7.3 | 10.7.3 |
redhat/mariadb | <10.8.2 | 10.8.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2021-46668.
The severity of CVE-2021-46668 is medium (5.5).
The affected software for CVE-2021-46668 is MariaDB versions 10.2.0 to 10.7.3, and Fedora versions 34 to 36.
CVE-2021-46668 allows an application crash via certain long SELECT DISTINCT statements that improperly interact with storage-engine resource limitations for temporary data structures.
Yes, a fix is available. Upgrade to MariaDB version 10.5.15, 10.6.7, or 10.7.3.