CVE Vulnerabilities

CVE-2022-47015

NULL Pointer Dereference

Published: Jan 20, 2023 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
6.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM

MariaDB Server before 10.3.34 thru 10.9.3 is vulnerable to Denial of Service. It is possible for function spider_db_mbase::print_warnings to dereference a null pointer.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

Name Vendor Start Version End Version
Mariadb Mariadb 10.3.0 (including) 10.3.39 (excluding)
Mariadb Mariadb 10.4.0 (including) 10.4.29 (excluding)
Mariadb Mariadb 10.5.0 (including) 10.5.20 (excluding)
Mariadb Mariadb 10.6.0 (including) 10.6.13 (excluding)
Mariadb Mariadb 10.8.0 (including) 10.8.8 (excluding)
Mariadb Mariadb 10.9.0 (including) 10.9.6 (excluding)
Mariadb Mariadb 10.10.0 (including) 10.10.4 (excluding)
Mariadb Mariadb 10.11.0 (including) 10.11.3 (excluding)
Red Hat Enterprise Linux 8 RedHat mariadb:10.3-8080020230814130040.63b34585 *
Red Hat Enterprise Linux 8 RedHat mariadb:10.5-8080020231003163755.63b34585 *
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support RedHat mariadb:10.5-8040020231006044227.522a0ee4 *
Red Hat Enterprise Linux 8.4 Telecommunications Update Service RedHat mariadb:10.5-8040020231006044227.522a0ee4 *
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions RedHat mariadb:10.5-8040020231006044227.522a0ee4 *
Red Hat Enterprise Linux 8.6 Extended Update Support RedHat mariadb:10.5-8060020231005052631.ad008a3a *
Red Hat Enterprise Linux 9 RedHat mariadb-3:10.5.22-1.el9_2 *
Red Hat Enterprise Linux 9.0 Extended Update Support RedHat galera-0:26.4.14-1.el9_0 *
Red Hat Enterprise Linux 9.0 Extended Update Support RedHat mariadb-3:10.5.22-1.el9_0 *
Red Hat Software Collections for Red Hat Enterprise Linux 7 RedHat rh-mariadb105-mariadb-3:10.5.22-1.el7 *
Mariadb-10.3 Ubuntu esm-apps/focal *
Mariadb-10.3 Ubuntu focal *
Mariadb-10.6 Ubuntu esm-apps/jammy *
Mariadb-10.6 Ubuntu jammy *
Mariadb-10.6 Ubuntu kinetic *
Mariadb-10.6 Ubuntu lunar *

Potential Mitigations

References