CVE-2022-27457: Use After Free
Last updated 24 July 2024
Other sources
MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component mymbwclatin1 at /strings/ctype-latin1.c.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-27457?
CVE-2022-27457 is a vulnerability discovered in MariaDB Server versions 10.6.3 and below, which allows for an use-after-free in the component my_mb_wc_latin1 at /strings/ctype-latin1.c.
What is the severity of CVE-2022-27457?
CVE-2022-27457 has a severity score of 7.5 (high).
Which software versions are affected by CVE-2022-27457?
MariaDB Server versions 10.4.0 to 10.4.25, 10.5.0 to 10.5.16, and 10.6.0 to 10.6.8 are affected by CVE-2022-27457.
How can I fix CVE-2022-27457?
To fix CVE-2022-27457, upgrade your MariaDB Server installation to version 10.7.4 or later.
Where can I find more information about CVE-2022-27457?
You can find more information about CVE-2022-27457 at the following references: [1] Jira issue: https://jira.mariadb.org/browse/MDEV-28098 [2] NetApp advisory: https://security.netapp.com/advisory/ntap-20220526-0007/ [3] MariaDB GitHub commit: https://github.com/MariaDB/server/commit/af810407f78b7f792a9bb8c47c8c532eb3b3a758