CVE Vulnerabilities

CVE-2022-47015

NULL Pointer Dereference

Published: Jan 20, 2023 | Modified: Jun 06, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
6.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM

MariaDB Server before 10.3.34 thru 10.9.3 is vulnerable to Denial of Service. It is possible for function spider_db_mbase::print_warnings to dereference a null pointer.

Weakness

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

Affected Software

Name Vendor Start Version End Version
Mariadb Mariadb 10.3.0 (including) 10.3.39 (excluding)
Mariadb Mariadb 10.4.0 (including) 10.4.29 (excluding)
Mariadb Mariadb 10.5.0 (including) 10.5.20 (excluding)
Mariadb Mariadb 10.6.0 (including) 10.6.13 (excluding)
Mariadb Mariadb 10.8.0 (including) 10.8.8 (excluding)
Mariadb Mariadb 10.9.0 (including) 10.9.6 (excluding)
Mariadb Mariadb 10.10.0 (including) 10.10.4 (excluding)
Mariadb Mariadb 10.11.0 (including) 10.11.3 (excluding)
Red Hat Enterprise Linux 8 RedHat mariadb:10.3-8080020230814130040.63b34585 *
Red Hat Enterprise Linux 8 RedHat mariadb:10.5-8080020231003163755.63b34585 *
Red Hat Enterprise Linux 9 RedHat mariadb-3:10.5.22-1.el9_2 *
Red Hat Software Collections for Red Hat Enterprise Linux 7 RedHat rh-mariadb105-mariadb-3:10.5.22-1.el7 *
Mariadb-10.3 Ubuntu focal *
Mariadb-10.6 Ubuntu jammy *
Mariadb-10.6 Ubuntu kinetic *
Mariadb-10.6 Ubuntu lunar *

Potential Mitigations

References