CVE Vulnerabilities

CVE-2023-52970

Insecure Automated Optimizations

Published: Mar 08, 2025 | Modified: Nov 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
4.9 MODERATE
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

MariaDB Server 10.4 through 10.5., 10.6 through 10.6., 10.7 through 10.11., 11.0 through 11.0., and 11.1 through 11.4.* crashes in Item_direct_view_ref::derived_field_transformer_for_where.

Weakness

The product uses a mechanism that automatically optimizes code, e.g. to improve a characteristic such as performance, but the optimizations can have an unintended side effect that might violate an intended security assumption.

Affected Software

NameVendorStart VersionEnd Version
Red Hat Enterprise Linux 10RedHatmariadb10.11-3:10.11.15-1.el10_1*
Red Hat Enterprise Linux 8RedHatmariadb:10.5-8100020251001104911.489197e6*
Red Hat Enterprise Linux 9RedHatgalera-0:26.4.22-1.el9_6*
Red Hat Enterprise Linux 9RedHatmariadb-3:10.5.29-2.el9_6*
Red Hat Enterprise Linux 9RedHatmariadb:10.11-9070020251202135752.rhel9*
MariadbUbuntuesm-apps/noble*
MariadbUbuntunoble*
MariadbUbuntuoracular*
MariadbUbuntuplucky*
Mariadb-10.6Ubuntuesm-apps/jammy*
Mariadb-10.6Ubuntujammy*
Mariadb-10.6Ubuntuupstream*

References