CVE-2022-27451: High severity mariadb server vulnerability
Published Apr 14, 2022
·Updated
Last updated 24 July 2024
Other sources
MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/fieldconv.cc.
— Launchpad
Affected Software
9 affected componentsFixes available
redhat/mariadb<10.7.4
10.7.4
redhat/mariadb<10.6.8
10.6.8
redhat/mariadb<10.5.16
10.5.16
redhat/mariadb<10.4.25
10.4.25
MariaDB MariaDB>=10.4.0<10.4.25
MariaDB MariaDB>=10.5.0<10.5.16
MariaDB MariaDB>=10.6.0<10.6.8
MariaDB MariaDB>=10.7.0<10.7.4
debian/mariadb-10.5
1:10.5.23-0+deb11u11:10.5.28-0+deb11u1
Remediation
Patch Available
Event History
Apr 14, 2022
CVE Published
via MITRE·12:57 PM
Data Sourced
via MITRE·12:57 PM
Description
Apr 16, 2024
Data Sourced
via Launchpad·02:06 PM
Description
Sep 19, 2024
Data Sourced
via Ubuntu·02:30 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
CVE-2022-27451
2
What is the severity of CVE-2022-27451?
The severity of CVE-2022-27451 is high with a score of 7.5.
3
What is the affected software for CVE-2022-27451?
The affected software is MariaDB Server version 10.9 and below.
4
How can I fix CVE-2022-27451?
Upgrade to MariaDB Server version 10.7.4 or apply the appropriate patch provided by the vendor.
5
Where can I find more information about CVE-2022-27451?
You can find more information about CVE-2022-27451 at the following references: [Reference 1](https://jira.mariadb.org/browse/MDEV-28094), [Reference 2](https://security.netapp.com/advisory/ntap-20220526-0006/), [Reference 3](https://github.com/MariaDB/server/commit/8c34eab9688b4face54f15f89f5d62bdfd93b8a7).