CVE-2022-27455: Use After Free
Last updated 24 July 2024
Other sources
MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component mywildcmp8bitimpl at /strings/ctype-simple.c.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2022-27455?
The severity of CVE-2022-27455 is high with a severity value of 7.5 (CVSS 3.1).
Which versions of MariaDB Server are affected by CVE-2022-27455?
MariaDB Server versions 10.4.0 to 10.4.25, 10.5.0 to 10.5.16, and 10.6.0 to 10.6.8 are affected by CVE-2022-27455.
What is the component affected by CVE-2022-27455?
CVE-2022-27455 affects the my_wildcmp_8bit_impl component in MariaDB Server.
How can I fix CVE-2022-27455?
To fix CVE-2022-27455, update MariaDB Server to version 10.7.4, 10.6.8, or 10.5.16, depending on the currently installed version.
Is there any additional reference information for CVE-2022-27455?
Yes, you can find additional reference information for CVE-2022-27455 at the following links: [Link 1](https://jira.mariadb.org/browse/MDEV-28097), [Link 2](https://security.netapp.com/advisory/ntap-20220526-0007/), [Link 3](https://github.com/MariaDB/server/commit/0beed9b5e933f0ff79b3bb346524f7a451d14e38)