CVE-2022-31623: Medium severity mariadb server vulnerability
MariaDB Server before 10.7 is vulnerable to Denial of Service. In extra/mariabackup/dscompress.cc, when an error occurs (i.e., going to the err label) while executing the method createworkerthreads, the held lock thd->ctrlmutex is not released correctly, which allows local users to trigger a denial of service due to the deadlock.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-31623?
CVE-2022-31623 is a vulnerability in MariaDB Server before 10.7 that allows local users to trigger a denial of service (DoS) attack.
How severe is CVE-2022-31623?
CVE-2022-31623 has a severity rating of 5.5, which is considered medium.
Which software versions are affected by CVE-2022-31623?
CVE-2022-31623 affects MariaDB versions 10.2.42 to 10.7.2.
How can I fix CVE-2022-31623?
To fix CVE-2022-31623, you should update MariaDB Server to version 10.7.2.
Where can I find more information about CVE-2022-31623?
You can find more information about CVE-2022-31623 on the GitHub page for MariaDB server and the NetApp security advisory.