mariadb: server crash at Item_subselect::init_expr_cache_tracker
Published Jul 1, 2022
7.5
HIGHCVSS 3.1
EPSS 2.01%
Description
MariaDB v10.2 to v10.6.1 was discovered to contain a segmentation fault via the component Item_subselect::init_expr_cache_tracker.
Affected products
No data.
Configuration 1
- ≥ 10.2.0 · < 10.2.44
- ≥ 10.3.0 · < 10.3.35
- ≥ 10.4.0 · < 10.4.25
- ≥ 10.5.0 · < 10.5.16
- ≥ 10.6.0 · < 10.6.8
- ≥ 10.7.0 · < 10.7.4
Configuration 2
- 10.0
No data.
Red Hat Enterprise Linux 8
mariadb:10.3-8060020220715055054.ad008a3a
Fixed · RHSA-2022:6443
Red Hat Enterprise Linux 8
mariadb:10.5-8060020220614163302.ad008a3a
Fixed · RHSA-2022:5826
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
mariadb:10.5-8040020231006044227.522a0ee4
Fixed · RHSA-2023:6821
Red Hat Enterprise Linux 8.4 Telecommunications Update Service
mariadb:10.5-8040020231006044227.522a0ee4
Fixed · RHSA-2023:6821
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions
mariadb:10.5-8040020231006044227.522a0ee4
Fixed · RHSA-2023:6821
Red Hat Enterprise Linux 9
galera-0:26.4.11-1.el9_0
Fixed · RHSA-2022:5948
Red Hat Enterprise Linux 9
mariadb-3:10.5.16-2.el9_0
Fixed · RHSA-2022:5948
Red Hat Enterprise Linux 9
mysql-selinux-0:1.0.5-1.el9_0
Fixed · RHSA-2022:5948
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-mariadb103-mariadb-3:10.3.35-1.el7
Fixed · RHSA-2022:6306
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-mariadb105-mariadb-3:10.5.16-2.el7
Fixed · RHSA-2022:5759
Red Hat Enterprise Linux 7
mariadb
Out of support scope
Red Hat OpenStack Platform 13 (Queens)
mariadb
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | mariadb:10.3-8060020220715055054.ad008a3a | Fixed | RHSA-2022:6443 |
| Red Hat Enterprise Linux 8 | mariadb:10.5-8060020220614163302.ad008a3a | Fixed | RHSA-2022:5826 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | mariadb:10.5-8040020231006044227.522a0ee4 | Fixed | RHSA-2023:6821 |
| Red Hat Enterprise Linux 8.4 Telecommunications Update Service | mariadb:10.5-8040020231006044227.522a0ee4 | Fixed | RHSA-2023:6821 |
| Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions | mariadb:10.5-8040020231006044227.522a0ee4 | Fixed | RHSA-2023:6821 |
| Red Hat Enterprise Linux 9 | galera-0:26.4.11-1.el9_0 | Fixed | RHSA-2022:5948 |
| Red Hat Enterprise Linux 9 | mariadb-3:10.5.16-2.el9_0 | Fixed | RHSA-2022:5948 |
| Red Hat Enterprise Linux 9 | mysql-selinux-0:1.0.5-1.el9_0 | Fixed | RHSA-2022:5948 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-mariadb103-mariadb-3:10.3.35-1.el7 | Fixed | RHSA-2022:6306 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-mariadb105-mariadb-3:10.5.16-2.el7 | Fixed | RHSA-2022:5759 |
| Red Hat Enterprise Linux 7 | mariadb | Out of support scope | n/a |
| Red Hat OpenStack Platform 13 (Queens) | mariadb | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (7)
- https://access.redhat.com/security/cve/CVE-2022-32083 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2104425 Issue Tracking
- https://jira.mariadb.org/browse/MDEV-26047 x_refsource_MISCExploitIssue TrackingThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/09/msg00023.html mailing-listx_refsource_MLISTMailing List
- https://nvd.nist.gov/vuln/detail/CVE-2022-32083
- https://security.netapp.com/advisory/ntap-20220826-0006/ x_refsource_CONFIRMThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-32083
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-32083 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2104425 | Issue Tracking | |
| https://jira.mariadb.org/browse/MDEV-26047 | x_refsource_MISCExploitIssue TrackingThird Party Advisory | |
| https://lists.debian.org/debian-lts-announce/2022/09/msg00023.html | mailing-listx_refsource_MLISTMailing List | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-32083 | ||
| https://security.netapp.com/advisory/ntap-20220826-0006/ | x_refsource_CONFIRMThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2022-32083 |
Change history (0)
No recorded changes yet.