CVE-2023-52970: Medium severity MariaDB Server vulnerability
MariaDB Server 10.4 through 10.5., 10.6 through 10.6., 10.7 through 10.11., 11.0 through 11.0., and 11.1 through 11.4. crashes in Itemdirectviewref::derivedfieldtransformerforwhere.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.6.24-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.11.15-1
Event History
Frequently Asked Questions
What is the severity of CVE-2023-52970?
CVE-2023-52970 has been classified with high severity due to the potential crash of the MariaDB server.
How can I fix CVE-2023-52970?
To address CVE-2023-52970, upgrade your MariaDB server to version 10.6.12 or higher, 10.11.4 or higher, or 11.0.7 or higher.
Which versions of MariaDB are affected by CVE-2023-52970?
CVE-2023-52970 affects MariaDB Server versions 10.4 to 10.5.*, 10.6.*, 10.7 to 10.11.*, 11.0.*, and 11.1 to 11.4.*.
What symptoms indicate a vulnerability to CVE-2023-52970?
Symptoms of CVE-2023-52970 include unexpected crashes in the MariaDB server when executing certain queries.
Who is impacted by CVE-2023-52970?
Organizations using affected versions of MariaDB Server for their databases may experience downtime and data accessibility issues due to CVE-2023-52970.