CVE-2022-27377: Use After Free
Last updated 24 July 2024
Other sources
MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component Itemfuncin::cleanup(), which is exploited via specially crafted SQL statements.
— Launchpad
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-27377.
What is the severity of CVE-2022-27377?
The severity of CVE-2022-27377 is high with a CVSS score of 7.5.
What software versions are affected by CVE-2022-27377?
MariaDB Server versions 10.2.0 to 10.2.44, 10.3.0 to 10.3.35, 10.4.0 to 10.4.25, 10.5.0 to 10.5.16, and 10.6.0 to 10.6.8 are affected by CVE-2022-27377.
How can CVE-2022-27377 be exploited?
CVE-2022-27377 can be exploited through specially crafted SQL statements that trigger a use-after-free vulnerability in the MariaDB Server component Item_func_in::cleanup().
Are there any remedies or patches available for CVE-2022-27377?
Yes, patches are available for CVE-2022-27377. It is recommended to update to MariaDB Server version 10.7.4, 10.6.8, 10.5.16, 10.4.25, or 10.3.35 to mitigate this vulnerability.