An update for mariadb is now available for openEuler-20.03-LTS-SP1,openEuler-20.03-LTS-SP3 and openEuler-22.03-LTS
Security Advisory
openeuler-security@openeuler.org
openEuler security committee
openEuler-SA-2022-1681
Final
1.0
1.0
2022-05-28
Initial
2022-05-28
2022-05-28
openEuler SA Tool V1.0
2022-05-28
mariadb security update
An update for mariadb is now available for openEuler-20.03-LTS-SP1,openEuler-20.03-LTS-SP3 and openEuler-22.03-LTS.
MariaDB is a community developed fork from MySQL - a multi-user, multi-threaded SQL database server. It is a client/server implementation consisting of a server daemon (mariadbd) and many different client programs and libraries. The base package contains the standard MariaDB/MySQL client programs and utilities.
Security Fix(es):
An issue in the component Arg_comparator::compare_real_fixed of MariaDB Server v10.6.2 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.(CVE-2022-27379)
MariaDB Server v10.7 and below was discovered to contain a segmentation fault via the component sql/sql_class.cc.(CVE-2022-27386)
MariaDB Server v10.7 and below was discovered to contain a global buffer overflow in the component decimal_bin_size, which is exploited via specially crafted SQL statements.(CVE-2022-27387)
An issue in the component Item_subselect::init_expr_cache_tracker of MariaDB Server v10.6 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.(CVE-2022-27384)
An issue in the component my_decimal::operator= of MariaDB Server v10.6.3 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.(CVE-2022-27380)
MariaDB Server v10.6 and below was discovered to contain an use-after-free in the component my_strcasecmp_8bit, which is exploited via specially crafted SQL statements.(CVE-2022-27383)
An issue in the component Field::set_default of MariaDB Server v10.6 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.(CVE-2022-27381)
MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component Item_func_in::cleanup(), which is exploited via specially crafted SQL statements.(CVE-2022-27377)
An issue in the component Create_tmp_table::finalize of MariaDB Server v10.7 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.(CVE-2022-27378)
MariaDB Server v10.6.5 and below was discovered to contain an use-after-free in the component Item_args::walk_arg, which is exploited via specially crafted SQL statements.(CVE-2022-27376)
MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/item_cmpfunc.cc.(CVE-2022-27452)
MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component Binary_string::free_buffer() at /sql/sql_string.h.(CVE-2022-27458)
MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component VDec::VDec at /sql/sql_type.cc.(CVE-2022-27456)
MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/sql_window.cc.(CVE-2022-27445)
MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/item_func.cc:148.(CVE-2022-27449)
There is an Assertion failure in MariaDB Server v10.9 and below via 'node->pcur->rel_pos == BTR_PCUR_ON' at /row/row0mysql.cc.(CVE-2022-27448)
MariaDB Server v10.9 and below was discovered to contain a use-after-free via the component Binary_string::free_buffer() at /sql/sql_string.h.(CVE-2022-27447)
An issue in the component Used_tables_and_const_cache::used_tables_and_const_cache_join of MariaDB Server v10.7 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.(CVE-2022-27385)
MariaDB Server v10.7 and below was discovered to contain a segmentation fault via the component Item_field::used_tables/update_depend_map_for_order.(CVE-2022-27382)
MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/field_conv.cc.(CVE-2022-27451)
MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component my_mb_wc_latin1 at /strings/ctype-latin1.c.(CVE-2022-27457)
MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/item_cmpfunc.h.(CVE-2022-27446)
MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/item_subselect.cc.(CVE-2022-27444)
MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component my_wildcmp_8bit_impl at /strings/ctype-simple.c.(CVE-2022-27455)
An update for mariadb is now available for openEuler-20.03-LTS-SP1,openEuler-20.03-LTS-SP3 and openEuler-22.03-LTS.
openEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.
High
mariadb
https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2022-1681
https://www.openeuler.org/en/security/cve/detail.html?id=CVE-2022-27379
https://www.openeuler.org/en/security/cve/detail.html?id=CVE-2022-27386
https://www.openeuler.org/en/security/cve/detail.html?id=CVE-2022-27387
https://www.openeuler.org/en/security/cve/detail.html?id=CVE-2022-27384
https://www.openeuler.org/en/security/cve/detail.html?id=CVE-2022-27380
https://www.openeuler.org/en/security/cve/detail.html?id=CVE-2022-27383
https://www.openeuler.org/en/security/cve/detail.html?id=CVE-2022-27381
https://www.openeuler.org/en/security/cve/detail.html?id=CVE-2022-27377
https://www.openeuler.org/en/security/cve/detail.html?id=CVE-2022-27378
https://www.openeuler.org/en/security/cve/detail.html?id=CVE-2022-27376
https://www.openeuler.org/en/security/cve/detail.html?id=CVE-2022-27452
https://www.openeuler.org/en/security/cve/detail.html?id=CVE-2022-27458
https://www.openeuler.org/en/security/cve/detail.html?id=CVE-2022-27456
https://www.openeuler.org/en/security/cve/detail.html?id=CVE-2022-27445
https://www.openeuler.org/en/security/cve/detail.html?id=CVE-2022-27449
https://www.openeuler.org/en/security/cve/detail.html?id=CVE-2022-27448
https://www.openeuler.org/en/security/cve/detail.html?id=CVE-2022-27447
https://www.openeuler.org/en/security/cve/detail.html?id=CVE-2022-27385
https://www.openeuler.org/en/security/cve/detail.html?id=CVE-2022-27382
https://www.openeuler.org/en/security/cve/detail.html?id=CVE-2022-27451
https://www.openeuler.org/en/security/cve/detail.html?id=CVE-2022-27457
https://www.openeuler.org/en/security/cve/detail.html?id=CVE-2022-27446
https://www.openeuler.org/en/security/cve/detail.html?id=CVE-2022-27444
https://www.openeuler.org/en/security/cve/detail.html?id=CVE-2022-27455
https://nvd.nist.gov/vuln/detail/CVE-2022-27379
https://nvd.nist.gov/vuln/detail/CVE-2022-27386
https://nvd.nist.gov/vuln/detail/CVE-2022-27387
https://nvd.nist.gov/vuln/detail/CVE-2022-27384
https://nvd.nist.gov/vuln/detail/CVE-2022-27380
https://nvd.nist.gov/vuln/detail/CVE-2022-27383
https://nvd.nist.gov/vuln/detail/CVE-2022-27381
https://nvd.nist.gov/vuln/detail/CVE-2022-27377
https://nvd.nist.gov/vuln/detail/CVE-2022-27378
https://nvd.nist.gov/vuln/detail/CVE-2022-27376
https://nvd.nist.gov/vuln/detail/CVE-2022-27452
https://nvd.nist.gov/vuln/detail/CVE-2022-27458
https://nvd.nist.gov/vuln/detail/CVE-2022-27456
https://nvd.nist.gov/vuln/detail/CVE-2022-27445
https://nvd.nist.gov/vuln/detail/CVE-2022-27449
https://nvd.nist.gov/vuln/detail/CVE-2022-27448
https://nvd.nist.gov/vuln/detail/CVE-2022-27447
https://nvd.nist.gov/vuln/detail/CVE-2022-27385
https://nvd.nist.gov/vuln/detail/CVE-2022-27382
https://nvd.nist.gov/vuln/detail/CVE-2022-27451
https://nvd.nist.gov/vuln/detail/CVE-2022-27457
https://nvd.nist.gov/vuln/detail/CVE-2022-27446
https://nvd.nist.gov/vuln/detail/CVE-2022-27444
https://nvd.nist.gov/vuln/detail/CVE-2022-27455
openEuler-20.03-LTS-SP1
openEuler-20.03-LTS-SP3
openEuler-22.03-LTS
mariadb-server-10.3.35-1.oe1.aarch64.rpm
mariadb-server-galera-10.3.35-1.oe1.aarch64.rpm
mariadb-gssapi-server-10.3.35-1.oe1.aarch64.rpm
mariadb-10.3.35-1.oe1.aarch64.rpm
mariadb-embedded-devel-10.3.35-1.oe1.aarch64.rpm
mariadb-debugsource-10.3.35-1.oe1.aarch64.rpm
mariadb-test-10.3.35-1.oe1.aarch64.rpm
mariadb-devel-10.3.35-1.oe1.aarch64.rpm
mariadb-oqgraph-engine-10.3.35-1.oe1.aarch64.rpm
mariadb-errmessage-10.3.35-1.oe1.aarch64.rpm
mariadb-cracklib-10.3.35-1.oe1.aarch64.rpm
mariadb-debuginfo-10.3.35-1.oe1.aarch64.rpm
mariadb-embedded-10.3.35-1.oe1.aarch64.rpm
mariadb-backup-10.3.35-1.oe1.aarch64.rpm
mariadb-common-10.3.35-1.oe1.aarch64.rpm
mariadb-backup-10.3.35-1.oe1.aarch64.rpm
mariadb-cracklib-10.3.35-1.oe1.aarch64.rpm
mariadb-common-10.3.35-1.oe1.aarch64.rpm
mariadb-embedded-10.3.35-1.oe1.aarch64.rpm
mariadb-oqgraph-engine-10.3.35-1.oe1.aarch64.rpm
mariadb-server-galera-10.3.35-1.oe1.aarch64.rpm
mariadb-errmessage-10.3.35-1.oe1.aarch64.rpm
mariadb-10.3.35-1.oe1.aarch64.rpm
mariadb-debuginfo-10.3.35-1.oe1.aarch64.rpm
mariadb-devel-10.3.35-1.oe1.aarch64.rpm
mariadb-server-10.3.35-1.oe1.aarch64.rpm
mariadb-test-10.3.35-1.oe1.aarch64.rpm
mariadb-debugsource-10.3.35-1.oe1.aarch64.rpm
mariadb-gssapi-server-10.3.35-1.oe1.aarch64.rpm
mariadb-embedded-devel-10.3.35-1.oe1.aarch64.rpm
mariadb-config-10.5.16-1.oe2203.aarch64.rpm
mariadb-test-10.5.16-1.oe2203.aarch64.rpm
mariadb-backup-10.5.16-1.oe2203.aarch64.rpm
mariadb-debugsource-10.5.16-1.oe2203.aarch64.rpm
mariadb-embedded-devel-10.5.16-1.oe2203.aarch64.rpm
mariadb-rocksdb-engine-10.5.16-1.oe2203.aarch64.rpm
mariadb-server-galera-10.5.16-1.oe2203.aarch64.rpm
mariadb-server-utils-10.5.16-1.oe2203.aarch64.rpm
mariadb-10.5.16-1.oe2203.aarch64.rpm
mariadb-pam-10.5.16-1.oe2203.aarch64.rpm
mariadb-embedded-10.5.16-1.oe2203.aarch64.rpm
mariadb-errmsg-10.5.16-1.oe2203.aarch64.rpm
mariadb-server-10.5.16-1.oe2203.aarch64.rpm
mariadb-debuginfo-10.5.16-1.oe2203.aarch64.rpm
mariadb-devel-10.5.16-1.oe2203.aarch64.rpm
mariadb-gssapi-server-10.5.16-1.oe2203.aarch64.rpm
mariadb-common-10.5.16-1.oe2203.aarch64.rpm
mariadb-oqgraph-engine-10.5.16-1.oe2203.aarch64.rpm
mariadb-10.3.35-1.oe1.src.rpm
mariadb-10.3.35-1.oe1.src.rpm
mariadb-10.5.16-1.oe2203.src.rpm
mariadb-errmessage-10.3.35-1.oe1.x86_64.rpm
mariadb-test-10.3.35-1.oe1.x86_64.rpm
mariadb-debugsource-10.3.35-1.oe1.x86_64.rpm
mariadb-embedded-devel-10.3.35-1.oe1.x86_64.rpm
mariadb-backup-10.3.35-1.oe1.x86_64.rpm
mariadb-10.3.35-1.oe1.x86_64.rpm
mariadb-server-10.3.35-1.oe1.x86_64.rpm
mariadb-gssapi-server-10.3.35-1.oe1.x86_64.rpm
mariadb-server-galera-10.3.35-1.oe1.x86_64.rpm
mariadb-debuginfo-10.3.35-1.oe1.x86_64.rpm
mariadb-oqgraph-engine-10.3.35-1.oe1.x86_64.rpm
mariadb-common-10.3.35-1.oe1.x86_64.rpm
mariadb-embedded-10.3.35-1.oe1.x86_64.rpm
mariadb-cracklib-10.3.35-1.oe1.x86_64.rpm
mariadb-devel-10.3.35-1.oe1.x86_64.rpm
mariadb-10.3.35-1.oe1.x86_64.rpm
mariadb-cracklib-10.3.35-1.oe1.x86_64.rpm
mariadb-server-10.3.35-1.oe1.x86_64.rpm
mariadb-oqgraph-engine-10.3.35-1.oe1.x86_64.rpm
mariadb-gssapi-server-10.3.35-1.oe1.x86_64.rpm
mariadb-test-10.3.35-1.oe1.x86_64.rpm
mariadb-errmessage-10.3.35-1.oe1.x86_64.rpm
mariadb-debuginfo-10.3.35-1.oe1.x86_64.rpm
mariadb-devel-10.3.35-1.oe1.x86_64.rpm
mariadb-server-galera-10.3.35-1.oe1.x86_64.rpm
mariadb-backup-10.3.35-1.oe1.x86_64.rpm
mariadb-embedded-devel-10.3.35-1.oe1.x86_64.rpm
mariadb-embedded-10.3.35-1.oe1.x86_64.rpm
mariadb-common-10.3.35-1.oe1.x86_64.rpm
mariadb-debugsource-10.3.35-1.oe1.x86_64.rpm
mariadb-devel-10.5.16-1.oe2203.x86_64.rpm
mariadb-debuginfo-10.5.16-1.oe2203.x86_64.rpm
mariadb-server-10.5.16-1.oe2203.x86_64.rpm
mariadb-oqgraph-engine-10.5.16-1.oe2203.x86_64.rpm
mariadb-common-10.5.16-1.oe2203.x86_64.rpm
mariadb-gssapi-server-10.5.16-1.oe2203.x86_64.rpm
mariadb-test-10.5.16-1.oe2203.x86_64.rpm
mariadb-server-galera-10.5.16-1.oe2203.x86_64.rpm
mariadb-debugsource-10.5.16-1.oe2203.x86_64.rpm
mariadb-backup-10.5.16-1.oe2203.x86_64.rpm
mariadb-config-10.5.16-1.oe2203.x86_64.rpm
mariadb-server-utils-10.5.16-1.oe2203.x86_64.rpm
mariadb-embedded-devel-10.5.16-1.oe2203.x86_64.rpm
mariadb-embedded-10.5.16-1.oe2203.x86_64.rpm
mariadb-errmsg-10.5.16-1.oe2203.x86_64.rpm
mariadb-pam-10.5.16-1.oe2203.x86_64.rpm
mariadb-10.5.16-1.oe2203.x86_64.rpm
An issue in the component Arg_comparator::compare_real_fixed of MariaDB Server v10.6.2 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.
2022-05-28
CVE-2022-27379
openEuler-20.03-LTS-SP1
openEuler-20.03-LTS-SP3
openEuler-22.03-LTS
High
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
mariadb security update
2022-05-28
https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2022-1681
MariaDB Server v10.7 and below was discovered to contain a segmentation fault via the component sql/sql_class.cc.
2022-05-28
CVE-2022-27386
openEuler-20.03-LTS-SP1
openEuler-20.03-LTS-SP3
openEuler-22.03-LTS
High
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
mariadb security update
2022-05-28
https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2022-1681
MariaDB Server v10.7 and below was discovered to contain a global buffer overflow in the component decimal_bin_size, which is exploited via specially crafted SQL statements.
2022-05-28
CVE-2022-27387
openEuler-20.03-LTS-SP1
openEuler-20.03-LTS-SP3
openEuler-22.03-LTS
High
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
mariadb security update
2022-05-28
https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2022-1681
An issue in the component Item_subselect::init_expr_cache_tracker of MariaDB Server v10.6 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.
2022-05-28
CVE-2022-27384
openEuler-20.03-LTS-SP1
openEuler-20.03-LTS-SP3
openEuler-22.03-LTS
High
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
mariadb security update
2022-05-28
https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2022-1681
An issue in the component my_decimal::operator= of MariaDB Server v10.6.3 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.
2022-05-28
CVE-2022-27380
openEuler-20.03-LTS-SP1
openEuler-20.03-LTS-SP3
openEuler-22.03-LTS
High
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
mariadb security update
2022-05-28
https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2022-1681
MariaDB Server v10.6 and below was discovered to contain an use-after-free in the component my_strcasecmp_8bit, which is exploited via specially crafted SQL statements.
2022-05-28
CVE-2022-27383
openEuler-20.03-LTS-SP1
openEuler-20.03-LTS-SP3
openEuler-22.03-LTS
High
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
mariadb security update
2022-05-28
https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2022-1681
An issue in the component Field::set_default of MariaDB Server v10.6 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.
2022-05-28
CVE-2022-27381
openEuler-20.03-LTS-SP1
openEuler-20.03-LTS-SP3
openEuler-22.03-LTS
High
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
mariadb security update
2022-05-28
https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2022-1681
MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component Item_func_in::cleanup(), which is exploited via specially crafted SQL statements.
2022-05-28
CVE-2022-27377
openEuler-20.03-LTS-SP1
openEuler-20.03-LTS-SP3
openEuler-22.03-LTS
High
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
mariadb security update
2022-05-28
https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2022-1681
An issue in the component Create_tmp_table::finalize of MariaDB Server v10.7 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.
2022-05-28
CVE-2022-27378
openEuler-20.03-LTS-SP1
openEuler-20.03-LTS-SP3
openEuler-22.03-LTS
High
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
mariadb security update
2022-05-28
https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2022-1681
MariaDB Server v10.6.5 and below was discovered to contain an use-after-free in the component Item_args::walk_arg, which is exploited via specially crafted SQL statements.
2022-05-28
CVE-2022-27376
openEuler-20.03-LTS-SP1
openEuler-20.03-LTS-SP3
openEuler-22.03-LTS
High
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
mariadb security update
2022-05-28
https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2022-1681
MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/item_cmpfunc.cc.
2022-05-28
CVE-2022-27452
openEuler-20.03-LTS-SP1
openEuler-20.03-LTS-SP3
openEuler-22.03-LTS
High
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
mariadb security update
2022-05-28
https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2022-1681
MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component Binary_string::free_buffer() at /sql/sql_string.h.
2022-05-28
CVE-2022-27458
openEuler-20.03-LTS-SP1
openEuler-20.03-LTS-SP3
openEuler-22.03-LTS
High
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
mariadb security update
2022-05-28
https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2022-1681
MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component VDec::VDec at /sql/sql_type.cc.
2022-05-28
CVE-2022-27456
openEuler-20.03-LTS-SP1
openEuler-20.03-LTS-SP3
openEuler-22.03-LTS
High
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
mariadb security update
2022-05-28
https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2022-1681
MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/sql_window.cc.
2022-05-28
CVE-2022-27445
openEuler-20.03-LTS-SP1
openEuler-20.03-LTS-SP3
openEuler-22.03-LTS
High
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
mariadb security update
2022-05-28
https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2022-1681
MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/item_func.cc:148.
2022-05-28
CVE-2022-27449
openEuler-20.03-LTS-SP1
openEuler-20.03-LTS-SP3
openEuler-22.03-LTS
High
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
mariadb security update
2022-05-28
https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2022-1681
There is an Assertion failure in MariaDB Server v10.9 and below via 'node->pcur->rel_pos == BTR_PCUR_ON' at /row/row0mysql.cc.
2022-05-28
CVE-2022-27448
openEuler-20.03-LTS-SP1
openEuler-20.03-LTS-SP3
openEuler-22.03-LTS
High
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
mariadb security update
2022-05-28
https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2022-1681
MariaDB Server v10.9 and below was discovered to contain a use-after-free via the component Binary_string::free_buffer() at /sql/sql_string.h.
2022-05-28
CVE-2022-27447
openEuler-20.03-LTS-SP1
openEuler-20.03-LTS-SP3
openEuler-22.03-LTS
High
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
mariadb security update
2022-05-28
https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2022-1681
An issue in the component Used_tables_and_const_cache::used_tables_and_const_cache_join of MariaDB Server v10.7 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.
2022-05-28
CVE-2022-27385
openEuler-22.03-LTS
High
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
mariadb security update
2022-05-28
https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2022-1681
MariaDB Server v10.7 and below was discovered to contain a segmentation fault via the component Item_field::used_tables/update_depend_map_for_order.
2022-05-28
CVE-2022-27382
openEuler-22.03-LTS
High
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
mariadb security update
2022-05-28
https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2022-1681
MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/field_conv.cc.
2022-05-28
CVE-2022-27451
openEuler-22.03-LTS
High
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
mariadb security update
2022-05-28
https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2022-1681
MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component my_mb_wc_latin1 at /strings/ctype-latin1.c.
2022-05-28
CVE-2022-27457
openEuler-22.03-LTS
High
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
mariadb security update
2022-05-28
https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2022-1681
MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/item_cmpfunc.h.
2022-05-28
CVE-2022-27446
openEuler-22.03-LTS
High
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
mariadb security update
2022-05-28
https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2022-1681
MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/item_subselect.cc.
2022-05-28
CVE-2022-27444
openEuler-22.03-LTS
High
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
mariadb security update
2022-05-28
https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2022-1681
MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component my_wildcmp_8bit_impl at /strings/ctype-simple.c.
2022-05-28
CVE-2022-27455
openEuler-22.03-LTS
High
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
mariadb security update
2022-05-28
https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2022-1681