CVE-2022-27457 – mariadb: incorrect key in "dup value" error after long unique
https://notcve.org/view.php?id=CVE-2022-27457
MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component my_mb_wc_latin1 at /strings/ctype-latin1.c. Se ha detectado que MariaDB Server versiones v10.6.3 y anteriores, contienen un uso de memoria previamente liberada en el componente my_mb_wc_latin1 en /strings/ctype-latin1.c A flaw was found in the MariaDB Server. It contains a use-after-free in the component, my_mb_wc_latin1 at /strings/ctype-latin1.c, affecting availability. • https://jira.mariadb.org/browse/MDEV-28098 https://security.netapp.com/advisory/ntap-20220526-0007 https://access.redhat.com/security/cve/CVE-2022-27457 https://bugzilla.redhat.com/show_bug.cgi?id=2075699 • CWE-416: Use After Free •
CVE-2022-27456 – mariadb: assertion failure in VDec::VDec at /sql/sql_type.cc
https://notcve.org/view.php?id=CVE-2022-27456
MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component VDec::VDec at /sql/sql_type.cc. Se ha detectado que MariaDB Server versiones v10.6.3 y anteriores, contienen un uso de memoria previamente liberada en el componente VDec::VDec en /sql/sql_type.cc A flaw was found in the MariaDB Server. It contains a use-after-free in the component, VDec::VDec at /sql/sql_type.cc, affecting availability. • https://jira.mariadb.org/browse/MDEV-28093 https://lists.debian.org/debian-lts-announce/2022/09/msg00023.html https://security.netapp.com/advisory/ntap-20220526-0007 https://access.redhat.com/security/cve/CVE-2022-27456 https://bugzilla.redhat.com/show_bug.cgi?id=2075697 • CWE-416: Use After Free CWE-617: Reachable Assertion •
CVE-2022-27455 – mariadb: use-after-free when WHERE has subquery with an outer reference in HAVING
https://notcve.org/view.php?id=CVE-2022-27455
MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component my_wildcmp_8bit_impl at /strings/ctype-simple.c. Se ha detectado que MariaDB Server versiones v10.6.3 y anteriores, contienen un uso de memoria previamente liberada en el componente my_wildcmp_8bit_impl en el archivo /strings/ctype-simple.c A flaw was found in the MariaDB Server. It contains a use-after-free in the component, my_wildcmp_8bit_impl at /strings/ctype-simple.c, affecting availability. • https://jira.mariadb.org/browse/MDEV-28097 https://security.netapp.com/advisory/ntap-20220526-0007 https://access.redhat.com/security/cve/CVE-2022-27455 https://bugzilla.redhat.com/show_bug.cgi?id=2075701 • CWE-416: Use After Free •
CVE-2022-27452 – mariadb: assertion failure in sql/item_cmpfunc.cc
https://notcve.org/view.php?id=CVE-2022-27452
MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/item_cmpfunc.cc. Se ha detectado que MariaDB Server versiones v10.9 y anteriores, contienen un fallo de segmentación por medio del componente sql/item_cmpfunc.cc A flaw was found in the MariaDB Server. It contains a segmentation fault via the component, sql/item_cmpfunc.cc, affecting availability. • https://jira.mariadb.org/browse/MDEV-28090 https://lists.debian.org/debian-lts-announce/2022/09/msg00023.html https://security.netapp.com/advisory/ntap-20220526-0006 https://access.redhat.com/security/cve/CVE-2022-27452 https://bugzilla.redhat.com/show_bug.cgi?id=2076145 • CWE-617: Reachable Assertion •
CVE-2022-27451 – mariadb: crash via window function in expression in ORDER BY
https://notcve.org/view.php?id=CVE-2022-27451
MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/field_conv.cc. Se ha detectado que MariaDB Server versiones v10.9 y anteriores, contienen un fallo de segmentación por medio del componente sql/field_conv.cc A flaw was found in the MariaDB Server. It contains a segmentation fault via the component, sql/field_conv.cc, affecting availability. • https://jira.mariadb.org/browse/MDEV-28094 https://security.netapp.com/advisory/ntap-20220526-0006 https://access.redhat.com/security/cve/CVE-2022-27451 https://bugzilla.redhat.com/show_bug.cgi?id=2076144 • CWE-1173: Improper Use of Validation Framework •