CVE-2022-24048: MariaDB CONNECT Storage Engine Stack-based Buffer Overflow Privilege Escalation Vulnerability
MariaDB CONNECT Storage Engine Stack-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of SQL queries. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the service account.
References: https://www.zerodayinitiative.com/advisories/ZDI-22-363/ https://mariadb.com/kb/en/security/ https://security.netapp.com/advisory/ntap-20220318-0004/
Other sources
MariaDB CONNECT Storage Engine Stack-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of SQL queries. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the service account. Was ZDI-CAN-16191.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/mariadbto a version that resolves this vulnerability.Fixed in 10.8.1 - Upgrade
Upgrade
redhat/mariadbto a version that resolves this vulnerability.Fixed in 10.7.2 - Upgrade
Upgrade
redhat/mariadbto a version that resolves this vulnerability.Fixed in 10.6.6 - Upgrade
Upgrade
redhat/mariadbto a version that resolves this vulnerability.Fixed in 10.5.14 - Upgrade
Upgrade
redhat/mariadbto a version that resolves this vulnerability.Fixed in 10.4.23 - Upgrade
Upgrade
redhat/mariadbto a version that resolves this vulnerability.Fixed in 10.3.33 - Upgrade
Upgrade
redhat/mariadbto a version that resolves this vulnerability.Fixed in 10.2.42
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-24048.
What is the severity of CVE-2022-24048?
CVE-2022-24048 has a severity score of 7.8 (High).
Who is affected by CVE-2022-24048?
Users of MariaDB versions 10.2.0 to 10.7.2 are affected by CVE-2022-24048.
How can this vulnerability be exploited?
This vulnerability can be exploited by local attackers with authentication to escalate privileges on affected installations of MariaDB.
How do I fix CVE-2022-24048?
To fix CVE-2022-24048, update to a version of MariaDB that includes the fix, such as version 10.8.1.