CVE Vulnerabilities

CVE-2021-46661

Published: Feb 01, 2022 | Modified: Nov 21, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
5.5 LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

MariaDB through 10.5.9 allows an application crash in find_field_in_tables and find_order_in_list via an unused common table expression (CTE).

Affected Software

NameVendorStart VersionEnd Version
MariadbMariadb10.2.0 (including)10.2.43 (excluding)
MariadbMariadb10.3.0 (including)10.3.34 (excluding)
MariadbMariadb10.4.0 (including)10.4.24 (excluding)
MariadbMariadb10.5.0 (including)10.5.15 (excluding)
MariadbMariadb10.6.0 (including)10.6.7 (excluding)
MariadbMariadb10.7.0 (including)10.7.3 (excluding)
Red Hat Enterprise Linux 8RedHatmariadb:10.5-8060020220614163302.ad008a3a*
Red Hat Enterprise Linux 8RedHatmariadb:10.3-8060020220715055054.ad008a3a*
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportRedHatmariadb:10.5-8040020231006044227.522a0ee4*
Red Hat Enterprise Linux 8.4 Telecommunications Update ServiceRedHatmariadb:10.5-8040020231006044227.522a0ee4*
Red Hat Enterprise Linux 8.4 Update Services for SAP SolutionsRedHatmariadb:10.5-8040020231006044227.522a0ee4*
Red Hat Enterprise Linux 9RedHatmariadb-3:10.5.16-2.el9_0*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHatrh-mariadb105-mariadb-3:10.5.16-2.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHatrh-mariadb103-mariadb-3:10.3.35-1.el7*
Mariadb-10.3Ubuntuesm-apps/focal*
Mariadb-10.3Ubuntufocal*
Mariadb-10.3Ubuntutrusty*
Mariadb-10.3Ubuntuxenial*
Mariadb-10.5Ubuntuimpish*
Mariadb-10.5Ubuntutrusty*
Mariadb-10.5Ubuntuxenial*
Mariadb-10.6Ubuntuesm-apps/jammy*
Mariadb-10.6Ubuntujammy*
Mariadb-10.6Ubuntukinetic*
Mariadb-10.6Ubuntulunar*
Mariadb-10.6Ubuntutrusty*
Mariadb-10.6Ubuntuxenial*

References