CVE-2022-27458: Use After Free
REJECT DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-27447. Reason: This candidate is a reservation duplicate of CVE-2022-27447. Notes: All CVE users should reference CVE-2022-27447 instead of this candidate.
Other sources
CVE(s):
MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component Binarystring::freebuffer() at /sql/sqlstring.h.
https://jira.mariadb.org/browse/MDEV-28099
— Red Hat
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-27447. Reason: This candidate is a reservation duplicate of CVE-2022-27447. Notes: All CVE users should reference CVE-2022-27447 instead of this candidate.
— NVD
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-27458?
CVE-2022-27458 is a vulnerability in MariaDB Server v10.6.3 and below that allows for a use-after-free in the component Binary_string::free_buffer().
What is the severity of CVE-2022-27458?
The severity of CVE-2022-27458 is high with a CVSS score of 7.5.
Which software versions are affected by CVE-2022-27458?
MariaDB versions 10.3.0 to 10.3.35, 10.4.0 to 10.4.25, 10.5.0 to 10.5.16, and 10.6.0 to 10.6.8 are affected by CVE-2022-27458.
How can I fix the CVE-2022-27458 vulnerability?
To fix the CVE-2022-27458 vulnerability, update your MariaDB Server to version 10.7.4 or apply the appropriate patches provided by your software vendor.
Where can I find more information about CVE-2022-27458?
You can find more information about CVE-2022-27458 on the following references: [link1], [link2], [link3].