CVE-2022-27386
mariadb: server crashes in query_arena::set_query_arena upon SELECT from view
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
MariaDB Server v10.7 and below was discovered to contain a segmentation fault via the component sql/sql_class.cc.
Se ha detectado que MariaDB Server versiones v10.7 y anteriores, contienen un fallo de segmentación por medio del componente sql/sql_class.cc
A flaw was found in the MariaDB Server. It contains a segmentation fault via the component, sql/sql_class.cc, impacting availability.
Several security issues were discovered in MariaDB and this update includes new upstream MariaDB versions to fix these issues. MariaDB has been updated to 10.3.37 in Ubuntu 20.04 LTS and to 10.6.11 in Ubuntu 22.04 LTS and Ubuntu 22.10. In addition to security fixes, the updated packages contain bug fixes, new features, and possibly incompatible changes.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-03-21 CVE Reserved
- 2022-04-12 CVE Published
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- 2026-01-16 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (5)
| URL | Tag | Source |
|---|---|---|
| https://lists.debian.org/debian-lts-announce/2022/09/msg00023.html | Mailing List |
|
| https://security.netapp.com/advisory/ntap-20220526-0004 | Third Party Advisory |
|
| URL | Date | SRC |
|---|---|---|
| https://jira.mariadb.org/browse/MDEV-26406 | 2024-08-03 |
| URL | Date | SRC |
|---|
| URL | Date | SRC |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-27386 | 2023-11-08 | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2075005 | 2023-11-08 |
Affected Vendors, Products, and Versions
| Vendor | Product | Version | Other | Status | ||||||
|---|---|---|---|---|---|---|---|---|---|---|
| Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
| Mariadb Search vendor "Mariadb" | Mariadb Search vendor "Mariadb" for product "Mariadb" | >= 10.2.0 < 10.2.44 Search vendor "Mariadb" for product "Mariadb" and version " >= 10.2.0 < 10.2.44" | - |
Affected
| ||||||
| Mariadb Search vendor "Mariadb" | Mariadb Search vendor "Mariadb" for product "Mariadb" | >= 10.3.0 < 10.3.35 Search vendor "Mariadb" for product "Mariadb" and version " >= 10.3.0 < 10.3.35" | - |
Affected
| ||||||
| Mariadb Search vendor "Mariadb" | Mariadb Search vendor "Mariadb" for product "Mariadb" | >= 10.4.0 < 10.4.25 Search vendor "Mariadb" for product "Mariadb" and version " >= 10.4.0 < 10.4.25" | - |
Affected
| ||||||
| Mariadb Search vendor "Mariadb" | Mariadb Search vendor "Mariadb" for product "Mariadb" | >= 10.5.0 < 10.5.16 Search vendor "Mariadb" for product "Mariadb" and version " >= 10.5.0 < 10.5.16" | - |
Affected
| ||||||
| Mariadb Search vendor "Mariadb" | Mariadb Search vendor "Mariadb" for product "Mariadb" | >= 10.6.0 < 10.6.8 Search vendor "Mariadb" for product "Mariadb" and version " >= 10.6.0 < 10.6.8" | - |
Affected
| ||||||
| Mariadb Search vendor "Mariadb" | Mariadb Search vendor "Mariadb" for product "Mariadb" | >= 10.7.0 < 10.7.4 Search vendor "Mariadb" for product "Mariadb" and version " >= 10.7.0 < 10.7.4" | - |
Affected
| ||||||
| Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 10.0 Search vendor "Debian" for product "Debian Linux" and version "10.0" | - |
Affected
| ||||||
