CVE-2021-46668
Published: August 31, 2023Last modified: August 31, 2023
Description
MariaDB through 10.5.9 allows an application crash via certain long SELECT DISTINCT statements that improperly interact with storage-engine resource limitations for temporary data structures.
Severity score breakdown
| Parameter | Value | 
|---|---|
| Base score | 5.5 | 
| Attack Vector | LOCAL | 
| Attack complexity | LOW | 
| Privileges required | LOW | 
| User interaction | NONE | 
| Scope | UNCHANGED | 
| Confidentiality | NONE | 
| Integrity impact | NONE | 
| Availability impact | HIGH | 
| Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H | 
Status
| Product | Release | Package | Status | 
|---|---|---|---|
| Alpaquita Linux | 23 LTS | mariadb | Not affected (10.6.14-r0) | 
| Stream | mariadb | Not affected (10.11.5-r1) | 
References
- https://jira.mariadb.org/browse/MDEV-25787
 - https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DKJRBYJAQCOPHSED43A3HUPNKQLDTFGD/
 - https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EZFZVMJL5UDTOZMARLXQIMG3BTG6UNYW/
 - https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NJ4KDAGF3H4D4BDTHRAM6ZEAJJWWMRUO/
 - https://lists.fedoraproject.org/archives/list/[email protected]/message/DKJRBYJAQCOPHSED43A3HUPNKQLDTFGD/
 - https://lists.fedoraproject.org/archives/list/[email protected]/message/EZFZVMJL5UDTOZMARLXQIMG3BTG6UNYW/
 - https://lists.fedoraproject.org/archives/list/[email protected]/message/NJ4KDAGF3H4D4BDTHRAM6ZEAJJWWMRUO/
 - https://mariadb.com/kb/en/security/
 - https://security.netapp.com/advisory/ntap-20220221-0002/