First published: Thu Apr 14 2022(Updated: )
Last updated 24 July 2024
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mariadb Mariadb | >=10.3.0<10.3.35 | |
Mariadb Mariadb | >=10.4.0<10.4.25 | |
Mariadb Mariadb | >=10.5.0<10.5.16 | |
Mariadb Mariadb | >=10.6.0<10.6.8 | |
Mariadb Mariadb | >=10.7.0<10.7.4 | |
Debian Debian Linux | =10.0 | |
redhat/mariadb | <10.7.4 | 10.7.4 |
redhat/mariadb | <10.6.8 | 10.6.8 |
redhat/mariadb | <10.5.16 | 10.5.16 |
redhat/mariadb | <10.4.25 | 10.4.25 |
redhat/mariadb | <10.3.35 | 10.3.35 |
debian/mariadb-10.5 | 1:10.5.23-0+deb11u1 1:10.5.26-0+deb11u2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-27448 is a vulnerability in MariaDB Server v10.9 and below that can be exploited via 'node->pcur->rel_pos == BTR_PCUR_ON' at /row/row0mysql.cc.
CVE-2022-27448 has a severity rating of 7.5 (high).
CVE-2022-27448 affects MariaDB versions 10.3.0 to 10.3.35, 10.4.0 to 10.4.25, 10.5.0 to 10.5.16, 10.6.0 to 10.6.8, and 10.7.0 to 10.7.4.
To fix CVE-2022-27448, you should upgrade MariaDB to versions 10.3.36, 10.4.26, 10.5.17, 10.6.9, or 10.7.5.
You can find more information about CVE-2022-27448 at the following references: [1] [2] [3].