Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-31624

Опубликовано: 07 сент. 2021
Источник: redhat
CVSS3: 5.5

Описание

MariaDB Server before 10.7 is vulnerable to Denial of Service. While executing the plugin/server_audit/server_audit.c method log_statement_ex, the held lock lock_bigbuffer is not released correctly, which allows local users to trigger a denial of service due to the deadlock.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7mariadbOut of support scope
Red Hat Enterprise Linux 9mariadbNot affected
Red Hat OpenStack Platform 13 (Queens)mariadbOut of support scope
Red Hat Enterprise Linux 8mariadbFixedRHSA-2022:155626.04.2022
Red Hat Enterprise Linux 8mariadbFixedRHSA-2022:155726.04.2022
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportmariadbFixedRHSA-2023:682108.11.2023
Red Hat Enterprise Linux 8.4 Extended Update SupportmariadbFixedRHSA-2022:481831.05.2022
Red Hat Enterprise Linux 8.4 Telecommunications Update ServicemariadbFixedRHSA-2023:682108.11.2023
Red Hat Enterprise Linux 8.4 Update Services for SAP SolutionsmariadbFixedRHSA-2023:682108.11.2023
Red Hat Software Collections for Red Hat Enterprise Linux 7rh-mariadb105-galeraFixedRHSA-2022:100722.03.2022

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-404
https://bugzilla.redhat.com/show_bug.cgi?id=2092362mariadb: DoS due to improper locking due to unreleased lock in plugin/server_audit/server_audit.c

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 4 года назад

MariaDB Server before 10.7 is vulnerable to Denial of Service. While executing the plugin/server_audit/server_audit.c method log_statement_ex, the held lock lock_bigbuffer is not released correctly, which allows local users to trigger a denial of service due to the deadlock.

CVSS3: 5.5
nvd
почти 4 года назад

MariaDB Server before 10.7 is vulnerable to Denial of Service. While executing the plugin/server_audit/server_audit.c method log_statement_ex, the held lock lock_bigbuffer is not released correctly, which allows local users to trigger a denial of service due to the deadlock.

CVSS3: 5.5
msrc
почти 4 года назад

MariaDB Server before 10.7 is vulnerable to Denial of Service. While executing the plugin/server_audit/server_audit.c method log_statement_ex the held lock lock_bigbuffer is not released correctly which allows local users to trigger a denial of service due to the deadlock.

CVSS3: 5.5
debian
почти 4 года назад

MariaDB Server before 10.7 is vulnerable to Denial of Service. While e ...

CVSS3: 5.5
github
почти 4 года назад

MariaDB Server before 10.7 is vulnerable to Denial of Service. While executing the plugin/server_audit/server_audit.c method log_statement_ex, the held lock lock_bigbuffer is not released correctly, which allows local users to trigger a denial of service due to the deadlock.

5.5 Medium

CVSS3