CVE-2022-38791: Medium severity MariaDB MariaDB vulnerability
In MariaDB before 10.9.2, compresswrite in extra/mariabackup/dscompress.cc does not release datamutex upon a stream write failure, which allows local users to trigger a deadlock.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2022-38791.
What is the severity level of CVE-2022-38791?
The severity level of CVE-2022-38791 is medium (5.5).
Which software versions are affected by CVE-2022-38791?
The software versions affected by CVE-2022-38791 include MariaDB versions 10.3.0 to 10.3.36, 10.4.0 to 10.4.26, 10.5.0 to 10.5.17, 10.6.0 to 10.6.9, 10.7.0 to 10.7.5, 10.8.0 to 10.8.4, and 10.9.1.
What is the description of CVE-2022-38791?
CVE-2022-38791 is a vulnerability in MariaDB that allows local users to trigger a deadlock by exploiting a failure in the compress_write function.
Where can I find more information about CVE-2022-38791?
More information about CVE-2022-38791 can be found at the following references: [Reference 1](https://jira.mariadb.org/browse/MDEV-28719), [Reference 2](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WCOEGSVMIEXDZHBOSV6WVF7FAVRBR2JE/), [Reference 3](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WTVAONAZXJFGHAJ4RP2OF3EAMQCOTDSQ/)