First published: Thu Apr 14 2022(Updated: )
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-27447. Reason: This candidate is a reservation duplicate of CVE-2022-27447. Notes: All CVE users should reference CVE-2022-27447 instead of this candidate.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mariadb Mariadb | >=10.3.0<10.3.35 | |
Mariadb Mariadb | >=10.4.0<10.4.25 | |
Mariadb Mariadb | >=10.5.0<10.5.16 | |
Mariadb Mariadb | >=10.6.0<10.6.8 | |
Mariadb Mariadb | >=10.7.0<10.7.4 | |
Debian Debian Linux | =10.0 | |
redhat/mariadb | <10.7.4 | 10.7.4 |
redhat/mariadb | <10.6.8 | 10.6.8 |
redhat/mariadb | <10.5.16 | 10.5.16 |
redhat/mariadb | <10.4.25 | 10.4.25 |
redhat/mariadb | <10.3.35 | 10.3.35 |
ubuntu/mariadb-10.3 | <1:10.3.37-0ubuntu0.20.04.1 | 1:10.3.37-0ubuntu0.20.04.1 |
ubuntu/mariadb-10.6 | <1:10.6.11-0ubuntu0.22.04.1 | 1:10.6.11-0ubuntu0.22.04.1 |
ubuntu/mariadb-10.6 | <1:10.6.8-1 | 1:10.6.8-1 |
debian/mariadb-10.3 | <=1:10.3.34-0+deb10u1 | 1:10.3.39-0+deb10u2 |
debian/mariadb-10.5 | 1:10.5.23-0+deb11u1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-27458 is a vulnerability in MariaDB Server v10.6.3 and below that allows for a use-after-free in the component Binary_string::free_buffer().
The severity of CVE-2022-27458 is high with a CVSS score of 7.5.
MariaDB versions 10.3.0 to 10.3.35, 10.4.0 to 10.4.25, 10.5.0 to 10.5.16, and 10.6.0 to 10.6.8 are affected by CVE-2022-27458.
To fix the CVE-2022-27458 vulnerability, update your MariaDB Server to version 10.7.4 or apply the appropriate patches provided by your software vendor.
You can find more information about CVE-2022-27458 on the following references: [link1], [link2], [link3].