MariaDB through 10.5.9 allows an application crash in find_field_in_tables and find_order_in_list via an unused common table expression (CTE). https://jira.mariadb.org/browse/MDEV-25766
Created mariadb tracking bugs for this issue: Affects: fedora-all [bug 2055743] Created mariadb:10.3/mariadb tracking bugs for this issue: Affects: fedora-all [bug 2055744] Created mariadb:10.4/mariadb tracking bugs for this issue: Affects: fedora-all [bug 2055745] Created mariadb:10.5/mariadb tracking bugs for this issue: Affects: fedora-all [bug 2055746] Created mariadb:10.6/mariadb tracking bugs for this issue: Affects: fedora-all [bug 2055747] Created mariadb:10.7/mariadb tracking bugs for this issue: Affects: fedora-all [bug 2055748]
Upstream commit: https://github.com/MariaDB/server/commit/0168d1eda30dad4b517659422e347175eb89e923
This issue has been addressed in the following products: Red Hat Software Collections for Red Hat Enterprise Linux 7 Via RHSA-2022:5759 https://access.redhat.com/errata/RHSA-2022:5759
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2022:5826 https://access.redhat.com/errata/RHSA-2022:5826
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2022:5948 https://access.redhat.com/errata/RHSA-2022:5948
This issue has been addressed in the following products: Red Hat Software Collections for Red Hat Enterprise Linux 7 Via RHSA-2022:6306 https://access.redhat.com/errata/RHSA-2022:6306
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2022:6443 https://access.redhat.com/errata/RHSA-2022:6443
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2021-46661