Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-31621

Опубликовано: 08 сент. 2021
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

MariaDB Server before 10.7 is vulnerable to Denial of Service. In extra/mariabackup/ds_xbstream.cc, when an error occurs (stream_ctxt->dest_file == NULL) while executing the method xbstream_open, the held lock is not released correctly, which allows local users to trigger a denial of service due to the deadlock. Note: The vendor argues this is just an improper locking bug and not a vulnerability with adverse effects.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7mariadbOut of support scope
Red Hat Enterprise Linux 9mariadbNot affected
Red Hat OpenStack Platform 13 (Queens)mariadbOut of support scope
Red Hat Enterprise Linux 8mariadbFixedRHSA-2022:155626.04.2022
Red Hat Enterprise Linux 8mariadbFixedRHSA-2022:155726.04.2022
Red Hat Enterprise Linux 8.4 Extended Update SupportmariadbFixedRHSA-2022:481831.05.2022
Red Hat Software Collections for Red Hat Enterprise Linux 7rh-mariadb105-galeraFixedRHSA-2022:100722.03.2022
Red Hat Software Collections for Red Hat Enterprise Linux 7rh-mariadb105-mariadbFixedRHSA-2022:100722.03.2022
Red Hat Software Collections for Red Hat Enterprise Linux 7rh-mariadb103-galeraFixedRHSA-2022:101022.03.2022
Red Hat Software Collections for Red Hat Enterprise Linux 7rh-mariadb103-mariadbFixedRHSA-2022:101022.03.2022

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-667
https://bugzilla.redhat.com/show_bug.cgi?id=2092353mariadb: improper locking due to unreleased lock in the ds_xbstream.cc

EPSS

Процентиль: 6%
0.00029
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 3 лет назад

** DISPUTED ** MariaDB Server before 10.7 is vulnerable to Denial of Service. In extra/mariabackup/ds_xbstream.cc, when an error occurs (stream_ctxt->dest_file == NULL) while executing the method xbstream_open, the held lock is not released correctly, which allows local users to trigger a denial of service due to the deadlock. Note: The vendor argues this is just an improper locking bug and not a vulnerability with adverse effects.

CVSS3: 5.5
nvd
около 3 лет назад

MariaDB Server before 10.7 is vulnerable to Denial of Service. In extra/mariabackup/ds_xbstream.cc, when an error occurs (stream_ctxt->dest_file == NULL) while executing the method xbstream_open, the held lock is not released correctly, which allows local users to trigger a denial of service due to the deadlock. Note: The vendor argues this is just an improper locking bug and not a vulnerability with adverse effects.

CVSS3: 5.5
msrc
около 3 лет назад

Описание отсутствует

CVSS3: 5.5
debian
около 3 лет назад

MariaDB Server before 10.7 is vulnerable to Denial of Service. In extr ...

CVSS3: 5.5
github
около 3 лет назад

MariaDB Server before 10.7 is vulnerable to Denial of Service. In extra/mariabackup/ds_xbstream.cc, when an error occurs (stream_ctxt->dest_file == NULL) while executing the method xbstream_open, the held lock is not released correctly, which allows local users to trigger a denial of service due to the deadlock.

EPSS

Процентиль: 6%
0.00029
Низкий

5.5 Medium

CVSS3