CVE Vulnerabilities

CVE-2021-46662

Published: Feb 01, 2022 | Modified: Apr 13, 2022
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
5.5 LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM

MariaDB through 10.5.9 allows a set_var.cc application crash via certain uses of an UPDATE statement in conjunction with a nested subquery.

Affected Software

Name Vendor Start Version End Version
Mariadb Mariadb 10.3.0 (including) 10.3.32 (excluding)
Mariadb Mariadb 10.4.0 (including) 10.4.22 (excluding)
Mariadb Mariadb 10.5.0 (including) 10.5.13 (excluding)
Mariadb Mariadb 10.6.0 (including) 10.6.5 (excluding)
Red Hat Enterprise Linux 8 RedHat mariadb:10.3-8050020220204122328.c5368500 *
Red Hat Enterprise Linux 8 RedHat mariadb:10.5-8050020220204122540.c5368500 *
Red Hat Enterprise Linux 8.4 Extended Update Support RedHat mariadb:10.3-8040020220429075504.522a0ee4 *
Red Hat Software Collections for Red Hat Enterprise Linux 7 RedHat rh-mariadb105-galera-0:26.4.9-3.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7 RedHat rh-mariadb105-mariadb-3:10.5.13-1.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7 RedHat rh-mariadb103-galera-0:25.3.34-4.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7 RedHat rh-mariadb103-mariadb-3:10.3.32-2.el7 *
Mariadb-10.3 Ubuntu focal *
Mariadb-10.3 Ubuntu trusty *
Mariadb-10.3 Ubuntu xenial *
Mariadb-10.5 Ubuntu impish *
Mariadb-10.5 Ubuntu trusty *
Mariadb-10.5 Ubuntu xenial *
Mariadb-10.6 Ubuntu kinetic *
Mariadb-10.6 Ubuntu lunar *
Mariadb-10.6 Ubuntu trusty *
Mariadb-10.6 Ubuntu upstream *
Mariadb-10.6 Ubuntu xenial *

References