CVE-2022-27383: Use After Free
Last updated 24 July 2024
Other sources
MariaDB Server v10.6 and below was discovered to contain an use-after-free in the component mystrcasecmp8bit, which is exploited via specially crafted SQL statements.
— Launchpad
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-27383?
CVE-2022-27383 is a use-after-free vulnerability in MariaDB Server v10.6 and below, specifically in the my_strcasecmp_8bit component, which can be exploited via specially crafted SQL statements.
How severe is CVE-2022-27383?
CVE-2022-27383 has a severity score of 7.5, which is considered high.
Which versions of MariaDB Server are affected by CVE-2022-27383?
MariaDB Server versions 10.2.0 - 10.2.44, 10.3.0 - 10.3.35, 10.4.0 - 10.4.25, 10.5.0 - 10.5.16, and 10.6.0 - 10.6.8 are all affected by CVE-2022-27383.
How can CVE-2022-27383 be fixed?
To fix CVE-2022-27383, users should update their MariaDB Server to version 10.8.3.
Where can I find more information about CVE-2022-27383?
You can find more information about CVE-2022-27383 at the following references: [Link 1](https://jira.mariadb.org/browse/MDEV-26323), [Link 2](https://lists.debian.org/debian-lts-announce/2022/09/msg00023.html), [Link 3](https://security.netapp.com/advisory/ntap-20220519-0006/).