CVE-2021-46669

medium
Published 2022-08-09 Β· Modified 2022-08-10
CVSS v3
β€”
CVSS v4 NEW
β€”
not yet in upstream
VIR risk
5.5

Description

Moderate: galera, mariadb, and mysql-selinux security, bug fix, and enhancement update

Predictions

Exploit likelihood
20%
Patch ETA
β€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata β€” Red Hat Inc. Β· View original β†— Β· Open-Errata-API

Description mariadb: MariaDB through 10.5.9 allows attackers to trigger a convert_const_to_int use-after-free when the BIGINT data type is used Red Hat statement Mitigation for this issue is not available, please update the affected package. CVSS v3: 6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H) Errata / fixed releases ProductPackageAdvisoryReleased Red Hat Enterprise Linux…

Workaround

for this issue is not available, please update the affected package.

Description

mariadb: MariaDB through 10.5.9 allows attackers to trigger a convert_const_to_int use-after-free when the BIGINT data type is used

Red Hat statement

Mitigation for this issue is not available, please update the affected package.

CVSS v3: 6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Enterprise Linux 8mariadb:10.5-8060020220614163302.ad008a3aRHSA-2022:58262022-08-02T00:00:00Z
Red Hat Enterprise Linux 8mariadb:10.3-8060020220715055054.ad008a3aRHSA-2022:64432022-09-13T00:00:00Z
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Supportmariadb:10.5-8040020231006044227.522a0ee4RHSA-2023:68212023-11-08T00:00:00Z
Red Hat Enterprise Linux 8.4 Telecommunications Update Servicemariadb:10.5-8040020231006044227.522a0ee4RHSA-2023:68212023-11-08T00:00:00Z
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutionsmariadb:10.5-8040020231006044227.522a0ee4RHSA-2023:68212023-11-08T00:00:00Z
Red Hat Enterprise Linux 9mariadb-3:10.5.16-2.el9_0RHSA-2022:59482022-08-09T00:00:00Z
Red Hat Software Collections for Red Hat Enterprise Linux 7rh-mariadb105-mariadb-3:10.5.16-2.el7RHSA-2022:57592022-07-28T00:00:00Z
Red Hat Software Collections for Red Hat Enterprise Linux 7rh-mariadb103-mariadb-3:10.3.35-1.el7RHSA-2022:63062022-09-01T00:00:00Z

Package state

ProductPackageState
Red Hat Enterprise Linux 7mariadbOut of support scope
Red Hat OpenStack Platform 13 (Queens)mariadbOut of support scope

Apply commands

bash fix
Apply RHSA-2022:5826 for Red Hat Enterprise Linux 8
yum update -y mariadb:10
# or:
dnf upgrade -y mariadb:10

OS impact

OSVersionStatusFixed in
redhat rhel9fixed
rockylinux rocky8fixed
rockylinux rocky9fixed
debian debianbullseyefixed1:10.5.18-0+deb11u1
almalinux almalinux9fixedmariadb-devel-10.5.16-2.el9_0.aarch64.rpm

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.