mariadb: server crash in Item_func_in::cleanup/Item::cleanup_processor
Published Jul 1, 2022
7.5
HIGHCVSS 3.1
EPSS 2.02%
Description
MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component Item_func_in::cleanup/Item::cleanup_processor.
Affected products
No data.
Configuration 1
- ≥ 10.2.0 · < 10.2.44
- ≥ 10.3.0 · < 10.3.35
- ≥ 10.4.0 · < 10.4.25
- ≥ 10.5.0 · < 10.5.16
- ≥ 10.6.0 · < 10.6.8
- ≥ 10.7.0 · < 10.7.4
Configuration 2
- 10.0
No data.
Red Hat Enterprise Linux 8
mariadb:10.3-8060020220715055054.ad008a3a
Fixed · RHSA-2022:6443
Red Hat Enterprise Linux 8
mariadb:10.5-8060020220614163302.ad008a3a
Fixed · RHSA-2022:5826
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
mariadb:10.5-8040020231006044227.522a0ee4
Fixed · RHSA-2023:6821
Red Hat Enterprise Linux 8.4 Telecommunications Update Service
mariadb:10.5-8040020231006044227.522a0ee4
Fixed · RHSA-2023:6821
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions
mariadb:10.5-8040020231006044227.522a0ee4
Fixed · RHSA-2023:6821
Red Hat Enterprise Linux 9
galera-0:26.4.11-1.el9_0
Fixed · RHSA-2022:5948
Red Hat Enterprise Linux 9
mariadb-3:10.5.16-2.el9_0
Fixed · RHSA-2022:5948
Red Hat Enterprise Linux 9
mysql-selinux-0:1.0.5-1.el9_0
Fixed · RHSA-2022:5948
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-mariadb103-mariadb-3:10.3.35-1.el7
Fixed · RHSA-2022:6306
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-mariadb105-mariadb-3:10.5.16-2.el7
Fixed · RHSA-2022:5759
Red Hat Enterprise Linux 7
mariadb
Out of support scope
Red Hat OpenStack Platform 13 (Queens)
mariadb
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | mariadb:10.3-8060020220715055054.ad008a3a | Fixed | RHSA-2022:6443 |
| Red Hat Enterprise Linux 8 | mariadb:10.5-8060020220614163302.ad008a3a | Fixed | RHSA-2022:5826 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | mariadb:10.5-8040020231006044227.522a0ee4 | Fixed | RHSA-2023:6821 |
| Red Hat Enterprise Linux 8.4 Telecommunications Update Service | mariadb:10.5-8040020231006044227.522a0ee4 | Fixed | RHSA-2023:6821 |
| Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions | mariadb:10.5-8040020231006044227.522a0ee4 | Fixed | RHSA-2023:6821 |
| Red Hat Enterprise Linux 9 | galera-0:26.4.11-1.el9_0 | Fixed | RHSA-2022:5948 |
| Red Hat Enterprise Linux 9 | mariadb-3:10.5.16-2.el9_0 | Fixed | RHSA-2022:5948 |
| Red Hat Enterprise Linux 9 | mysql-selinux-0:1.0.5-1.el9_0 | Fixed | RHSA-2022:5948 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-mariadb103-mariadb-3:10.3.35-1.el7 | Fixed | RHSA-2022:6306 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-mariadb105-mariadb-3:10.5.16-2.el7 | Fixed | RHSA-2022:5759 |
| Red Hat Enterprise Linux 7 | mariadb | Out of support scope | n/a |
| Red Hat OpenStack Platform 13 (Queens) | mariadb | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (7)
- https://access.redhat.com/security/cve/CVE-2022-32085 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2104431 Issue Tracking
- https://jira.mariadb.org/browse/MDEV-26407 x_refsource_MISCExploitIssue TrackingThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/09/msg00023.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-32085
- https://security.netapp.com/advisory/ntap-20220818-0005/ x_refsource_CONFIRMThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-32085
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-32085 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2104431 | Issue Tracking | |
| https://jira.mariadb.org/browse/MDEV-26407 | x_refsource_MISCExploitIssue TrackingThird Party Advisory | |
| https://lists.debian.org/debian-lts-announce/2022/09/msg00023.html | mailing-listx_refsource_MLISTMailing ListThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-32085 | ||
| https://security.netapp.com/advisory/ntap-20220818-0005/ | x_refsource_CONFIRMThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2022-32085 |
Change history (0)
No recorded changes yet.