Bug 2075691 (CVE-2022-27445)
| Summary: | CVE-2022-27445 mariadb: assertion failure in compare_order_elements | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | Sage McTaggart <amctagga> | 
| Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> | 
| Status: | CLOSED ERRATA | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | caswilli, damien.ciabrini, databases-maint, dciabrin, eglynn, gzaronik, hhorak, jjoyce, jorton, kaycoth, lhh, ljavorsk, mbayer, mburns, mkocka, mmuzila, mschorm, SpikeFedora, spower | 
| Target Milestone: | --- | Keywords: | Security | 
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | mariadb 10.8.3, mariadb 10.7.4, mariadb 10.6.8, mariadb 10.5.16, mariadb 10.4.25, mariadb 10.3.35, mariadb 10.2.44 | Doc Type: | If docs needed, set a value | 
| Doc Text: | A flaw was found in the MariaDB Server. It contains a segmentation fault via the component, sql/sql_window.cc, impacting availability. | Story Points: | --- | 
| Clone Of: | Environment: | ||
| Last Closed: | 2022-11-26 03:24:22 UTC | Type: | --- | 
| Regression: | --- | Mount Type: | --- | 
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2083246, 2083249, 2089977, 2089980, 2090192, 2090831, 2090832, 2090833, 2090834, 2090839, 2090845, 2096275, 2096280, 2101779, 2107052, 2107074 | ||
| Bug Blocks: | 2075026 | ||
| 
        
          Description
        
        
          Sage McTaggart
        
        
        
            
        
        
          2022-04-14 21:49:57 UTC
        
       MDEV-28081 is duplicated by MDEV-19398: https://jira.mariadb.org/browse/MDEV-19398. Upstream commits: https://github.com/MariaDB/server/commit/ba4927e520190bbad763bb5260ae154f29a61231 https://github.com/MariaDB/server/commit/624cb9735e737ca3392957e2db2171c2957cf282 Created mariadb tracking bugs for this issue: Affects: fedora-all [bug 2090831] Created mariadb:10.5/mariadb tracking bugs for this issue: Affects: fedora-all [bug 2090832] Created mariadb:10.3/mariadb tracking bugs for this issue: Affects: fedora-all [bug 2090833] Created mariadb:10.4/mariadb tracking bugs for this issue: Affects: fedora-all [bug 2090834] Created mariadb:10.6/mariadb tracking bugs for this issue: Affects: fedora-all [bug 2090839] Created mariadb:10.7/mariadb tracking bugs for this issue: Affects: fedora-all [bug 2090845] This issue has been addressed in the following products: Red Hat Software Collections for Red Hat Enterprise Linux 7 Via RHSA-2022:5759 https://access.redhat.com/errata/RHSA-2022:5759 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2022:5826 https://access.redhat.com/errata/RHSA-2022:5826 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2022:5948 https://access.redhat.com/errata/RHSA-2022:5948 This issue has been addressed in the following products: Red Hat Software Collections for Red Hat Enterprise Linux 7 Via RHSA-2022:6306 https://access.redhat.com/errata/RHSA-2022:6306 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2022:6443 https://access.redhat.com/errata/RHSA-2022:6443 This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2022-27445 |