CVE-2022-27384: SQL Injection
An issue in the component Itemsubselect::initexprcachetracker of MariaDB Server v10.6 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-27384?
CVE-2022-27384 is a vulnerability in the component Item_subselect::init_expr_cache_tracker of MariaDB Server v10.6 and below, which allows attackers to cause a Denial of Service (DoS) through specially crafted SQL statements.
Which software versions are affected by CVE-2022-27384?
CVE-2022-27384 affects MariaDB Server versions 10.2.0 to 10.2.44, 10.3.0 to 10.3.35, 10.4.0 to 10.4.25, 10.5.0 to 10.5.16, and 10.6.0 to 10.6.8.
What is the severity of CVE-2022-27384?
CVE-2022-27384 has a severity score of 7.5, which is considered high.
How can I fix CVE-2022-27384?
To fix CVE-2022-27384, upgrade to MariaDB Server version 10.8.3 or apply the appropriate patch provided by your operating system or software vendor.
Where can I find more information about CVE-2022-27384?
You can find more information about CVE-2022-27384 on the official MariaDB Jira page (https://jira.mariadb.org/browse/MDEV-26047), the Debian LTS announcement (https://lists.debian.org/debian-lts-announce/2022/09/msg00023.html), and the NetApp security advisory (https://security.netapp.com/advisory/ntap-20220519-0006/).