Описание
In MariaDB before 10.9.2, compress_write in extra/mariabackup/ds_compress.cc does not release data_mutex upon a stream write failure, which allows local users to trigger a deadlock.
Пакеты
Пакет | Статус | Версия исправления | Релиз | Тип |
---|---|---|---|---|
mariadb-10.6 | fixed | 1:10.6.9-1 | package | |
mariadb-10.5 | removed | package | ||
mariadb-10.5 | fixed | 1:10.5.18-0+deb11u1 | bullseye | package |
mariadb-10.3 | removed | package |
Примечания
MariaDB bug: https://jira.mariadb.org/browse/MDEV-28719
MariaDB fixed in 10.3.36, 10.5.17, 10.6.9
MariaDB commit https://github.com/MariaDB/server/commit/91d5fffa0796b8208c3d6633c8f296da8914af4d (mariadb-10.3.36)
MariaDB related to previous commit incompletly fixing the issue https://github.com/MariaDB/server/commit/863c3eda872b19f70ce6045119bf621584e1312d (mariadb-10.3.36)
MariaDB bug for incomplete fix: https://jira.mariadb.org/browse/MDEV-28689
MariaDB duplicate bug for incomplete fix: https://jira.mariadb.org/browse/MDEV-28690
EPSS
Связанные уязвимости
In MariaDB before 10.9.2, compress_write in extra/mariabackup/ds_compress.cc does not release data_mutex upon a stream write failure, which allows local users to trigger a deadlock.
In MariaDB before 10.9.2, compress_write in extra/mariabackup/ds_compress.cc does not release data_mutex upon a stream write failure, which allows local users to trigger a deadlock.
In MariaDB before 10.9.2, compress_write in extra/mariabackup/ds_compress.cc does not release data_mutex upon a stream write failure, which allows local users to trigger a deadlock.
EPSS