CVE Vulnerabilities

CVE-2023-52970

Insecure Automated Optimizations

Published: Mar 08, 2025 | Modified: Mar 08, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
4.9 MODERATE
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM

MariaDB Server 10.4 through 10.5., 10.6 through 10.6., 10.7 through 10.11., 11.0 through 11.0., and 11.1 through 11.4.* crashes in Item_direct_view_ref::derived_field_transformer_for_where.

Weakness

The product uses a mechanism that automatically optimizes code, e.g. to improve a characteristic such as performance, but the optimizations can have an unintended side effect that might violate an intended security assumption.

Affected Software

Name Vendor Start Version End Version
Mariadb Ubuntu esm-apps/noble *
Mariadb Ubuntu noble *
Mariadb Ubuntu plucky *
Mariadb-10.6 Ubuntu esm-apps/jammy *
Mariadb-10.6 Ubuntu jammy *
Mariadb-10.6 Ubuntu upstream *

References