First published: Tue Apr 12 2022(Updated: )
Last updated 24 July 2024
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mariadb Mariadb | >=10.4.0<10.4.25 | |
Mariadb Mariadb | >=10.5.0<10.5.16 | |
Mariadb Mariadb | >=10.6.0<10.6.8 | |
Mariadb Mariadb | >=10.7.0<10.7.4 | |
redhat/mariadb | <10.9.1 | 10.9.1 |
redhat/mariadb | <10.8.3 | 10.8.3 |
redhat/mariadb | <10.7.4 | 10.7.4 |
redhat/mariadb | <10.6.8 | 10.6.8 |
redhat/mariadb | <10.5.16 | 10.5.16 |
redhat/mariadb | <10.4.25 | 10.4.25 |
debian/mariadb-10.5 | 1:10.5.23-0+deb11u1 1:10.5.26-0+deb11u2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-27382 is a vulnerability discovered in MariaDB Server v10.7 and below that allows for a segmentation fault via the component Item_field::used_tables/update_depend_map_for_order.
The severity of CVE-2022-27382 is high, with a CVSS score of 7.5.
MariaDB Server v10.4.0 to v10.7.4 are affected by CVE-2022-27382.
To fix CVE-2022-27382, update your MariaDB Server to version 10.7.4 or higher.
You can find more information about CVE-2022-27382 in the references provided: https://jira.mariadb.org/browse/MDEV-26402, https://security.netapp.com/advisory/ntap-20220526-0004/, https://github.com/MariaDB/server/commit/807945f2eb5fa22e6f233cc17b85a2e141efe2c8