CVE-2022-44011: Buffer Overflow
An issue was discovered in ClickHouse before 22.9.1.2603. An authenticated user (with the ability to load data) could cause a heap buffer overflow and crash the server by inserting a malformed CapnProto object. The fixed versions are 22.9.1.2603, 22.8.2.11, 22.7.4.16, 22.6.6.16, and 22.3.12.19.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-44011?
CVE-2022-44011 is considered a critical vulnerability due to the potential for authenticated users to crash the server.
How do I fix CVE-2022-44011?
To fix CVE-2022-44011, upgrade your ClickHouse installation to version 22.9.1.2603 or any of the other fixed versions listed.
What type of vulnerability is CVE-2022-44011?
CVE-2022-44011 is a heap buffer overflow vulnerability that can lead to server crashes.
Who is affected by CVE-2022-44011?
Authenticated users with the ability to load data into ClickHouse versions prior to the fixed releases are at risk with CVE-2022-44011.
What are the affected versions of ClickHouse in CVE-2022-44011?
CVE-2022-44011 affects ClickHouse versions before 22.9.1.2603, including multiple prior versions.