CVE Vulnerabilities

CVE-2021-46658

Published: Jan 29, 2022 | Modified: Nov 21, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
5.5 LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

save_window_function_values in MariaDB before 10.6.3 allows an application crash because of incorrect handling of with_window_func=true for a subquery.

Affected Software

NameVendorStart VersionEnd Version
MariadbMariadb10.2.0 (including)10.2.40 (excluding)
MariadbMariadb10.3.0 (including)10.3.31 (excluding)
MariadbMariadb10.4.0 (including)10.4.21 (excluding)
MariadbMariadb10.5.0 (including)10.5.12 (excluding)
MariadbMariadb10.6.0 (including)10.6.3 (excluding)
Red Hat Enterprise Linux 8RedHatmariadb:10.3-8050020220204122328.c5368500*
Red Hat Enterprise Linux 8RedHatmariadb:10.5-8050020220204122540.c5368500*
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportRedHatmariadb:10.5-8040020231006044227.522a0ee4*
Red Hat Enterprise Linux 8.4 Extended Update SupportRedHatmariadb:10.3-8040020220429075504.522a0ee4*
Red Hat Enterprise Linux 8.4 Telecommunications Update ServiceRedHatmariadb:10.5-8040020231006044227.522a0ee4*
Red Hat Enterprise Linux 8.4 Update Services for SAP SolutionsRedHatmariadb:10.5-8040020231006044227.522a0ee4*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHatrh-mariadb105-galera-0:26.4.9-3.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHatrh-mariadb105-mariadb-3:10.5.13-1.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHatrh-mariadb103-galera-0:25.3.34-4.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHatrh-mariadb103-mariadb-3:10.3.32-2.el7*
Mariadb-10.3Ubuntufocal*
Mariadb-10.3Ubuntutrusty*
Mariadb-10.3Ubuntuxenial*
Mariadb-10.5Ubuntutrusty*
Mariadb-10.5Ubuntuupstream*
Mariadb-10.5Ubuntuxenial*
Mariadb-10.6Ubuntutrusty*
Mariadb-10.6Ubuntuxenial*

References