First published: Tue Apr 12 2022(Updated: )
An issue in the component Item_subselect::init_expr_cache_tracker of MariaDB Server v10.6 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mariadb Mariadb | >=10.2.0<10.2.44 | |
Mariadb Mariadb | >=10.3.0<10.3.35 | |
Mariadb Mariadb | >=10.4.0<10.4.25 | |
Mariadb Mariadb | >=10.5.0<10.5.16 | |
Mariadb Mariadb | >=10.6.0<10.6.8 | |
Mariadb Mariadb | >=10.7.0<10.7.4 | |
Mariadb Mariadb | >=10.8.0<10.8.3 | |
Debian Debian Linux | =10.0 | |
redhat/mariadb | <10.8.3 | 10.8.3 |
redhat/mariadb | <10.7.4 | 10.7.4 |
redhat/mariadb | <10.6.8 | 10.6.8 |
redhat/mariadb | <10.5.16 | 10.5.16 |
redhat/mariadb | <10.4.25 | 10.4.25 |
redhat/mariadb | <10.3.35 | 10.3.35 |
redhat/mariadb | <10.2.44 | 10.2.44 |
debian/mariadb-10.5 | 1:10.5.23-0+deb11u1 1:10.5.26-0+deb11u2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-27384 is a vulnerability in the component Item_subselect::init_expr_cache_tracker of MariaDB Server v10.6 and below, which allows attackers to cause a Denial of Service (DoS) through specially crafted SQL statements.
CVE-2022-27384 affects MariaDB Server versions 10.2.0 to 10.2.44, 10.3.0 to 10.3.35, 10.4.0 to 10.4.25, 10.5.0 to 10.5.16, and 10.6.0 to 10.6.8.
CVE-2022-27384 has a severity score of 7.5, which is considered high.
To fix CVE-2022-27384, upgrade to MariaDB Server version 10.8.3 or apply the appropriate patch provided by your operating system or software vendor.
You can find more information about CVE-2022-27384 on the official MariaDB Jira page (https://jira.mariadb.org/browse/MDEV-26047), the Debian LTS announcement (https://lists.debian.org/debian-lts-announce/2022/09/msg00023.html), and the NetApp security advisory (https://security.netapp.com/advisory/ntap-20220519-0006/).