Описание
An issue was discovered in MariaDB Server before 11.4.10, 11.5.x through 11.8.x before 11.8.6, and 12.x before 12.2.2. If the caching_sha2_password authentication plugin is installed, and some user accounts are configured to use it, a large packet can crash the server because sha256_crypt_r uses alloca.
A flaw was found in MariaDB Server. When the caching_sha2_password authentication plugin is installed and used by some user accounts, a low-privileged authenticated user can send a specially crafted large packet. This can cause the server to crash due to an issue with the sha256_crypt_r function's use of alloca, a function for allocating memory on the stack. This vulnerability leads to a Denial of Service (DoS), making the database server unavailable.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | mariadb10.11 | Fix deferred | ||
| Red Hat Enterprise Linux 10 | mariadb11.8 | Fix deferred | ||
| Red Hat Enterprise Linux 7 | mariadb | Out of support scope | ||
| Red Hat Enterprise Linux 8 | mariadb:10.11/mariadb | Fix deferred | ||
| Red Hat Enterprise Linux 8 | mariadb:10.3/mariadb | Fix deferred | ||
| Red Hat Enterprise Linux 8 | mariadb:10.5/mariadb | Fix deferred | ||
| Red Hat Enterprise Linux 9 | mariadb | Fix deferred | ||
| Red Hat Enterprise Linux 9 | mariadb:10.11/mariadb | Fix deferred | ||
| Red Hat Enterprise Linux 9 | mariadb:11.8/mariadb | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
An issue was discovered in MariaDB Server before 11.4.10, 11.5.x through 11.8.x before 11.8.6, and 12.x before 12.2.2. If the caching_sha2_password authentication plugin is installed, and some user accounts are configured to use it, a large packet can crash the server because sha256_crypt_r uses alloca.
An issue was discovered in MariaDB Server before 11.4.10, 11.5.x through 11.8.x before 11.8.6, and 12.x before 12.2.2. If the caching_sha2_password authentication plugin is installed, and some user accounts are configured to use it, a large packet can crash the server because sha256_crypt_r uses alloca.
An issue was discovered in MariaDB Server before 11.4.10, 11.5.x throu ...
An issue was discovered in MariaDB Server before 11.4.10, 11.5.x through 11.8.x before 11.8.6, and 12.x before 12.2.2. If the caching_sha2_password authentication plugin is installed, and some user accounts are configured to use it, a large packet can crash the server because sha256_crypt_r uses alloca.
EPSS
6.5 Medium
CVSS3