CVE Vulnerabilities

CVE-2021-46659

Published: Jan 29, 2022 | Modified: Nov 21, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
5.5 LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

MariaDB before 10.7.2 allows an application crash because it does not recognize that SELECT_LEX::nest_level is local to each VIEW.

Affected Software

NameVendorStart VersionEnd Version
MariadbMariadb5.5.0 (including)10.2.42 (excluding)
MariadbMariadb10.3.0 (including)10.3.33 (excluding)
MariadbMariadb10.4.0 (including)10.4.23 (excluding)
MariadbMariadb10.5.0 (including)10.5.14 (excluding)
MariadbMariadb10.6.0 (including)10.6.6 (excluding)
MariadbMariadb10.7.0 (including)10.7.2 (excluding)
Red Hat Enterprise Linux 8RedHatmariadb:10.5-8060020220614163302.ad008a3a*
Red Hat Enterprise Linux 8RedHatmariadb:10.3-8060020220715055054.ad008a3a*
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportRedHatmariadb:10.5-8040020231006044227.522a0ee4*
Red Hat Enterprise Linux 8.4 Telecommunications Update ServiceRedHatmariadb:10.5-8040020231006044227.522a0ee4*
Red Hat Enterprise Linux 8.4 Update Services for SAP SolutionsRedHatmariadb:10.5-8040020231006044227.522a0ee4*
Red Hat Enterprise Linux 9RedHatmariadb-3:10.5.16-2.el9_0*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHatrh-mariadb105-mariadb-3:10.5.16-2.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHatrh-mariadb103-mariadb-3:10.3.35-1.el7*
Mariadb-10.3Ubuntuesm-apps/focal*
Mariadb-10.3Ubuntufocal*
Mariadb-10.3Ubuntutrusty*
Mariadb-10.3Ubuntuxenial*
Mariadb-10.5Ubuntuimpish*
Mariadb-10.5Ubuntutrusty*
Mariadb-10.5Ubuntuxenial*
Mariadb-10.6Ubuntukinetic*
Mariadb-10.6Ubuntulunar*
Mariadb-10.6Ubuntutrusty*
Mariadb-10.6Ubuntuxenial*

References