[ALSA-2022:5826] Moderate: mariadb:10.5 security, bug fix, and enhancement update
Type:
security
Severity:
moderate
Release date:
2022-08-05
Description:
MariaDB is a multi-user, multi-threaded SQL database server that is binary compatible with MySQL. The following packages have been upgraded to a later upstream version: galera (26.4.11), mariadb (10.5.16). Security Fix(es): * mariadb: MariaDB through 10.5.9 allows attackers to trigger a convert_const_to_int use-after-free when the BIGINT data type is used (CVE-2021-46669) * mariadb: lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer (CVE-2022-24048) * mariadb: lack of validating the existence of an object prior to performing operations on the object (CVE-2022-24050) * mariadb: lack of proper validation of a user-supplied string before using it as a format specifier (CVE-2022-24051) * mariadb: CONNECT Storage Engine Heap-based Buffer Overflow Privilege Escalation Vulnerability (CVE-2022-24052) * mariadb: assertion failure in Item_args::walk_arg (CVE-2022-27376) * mariadb: use-after-poison when complex conversion is involved in blob (CVE-2022-27377) * mariadb: crash in create_tmp_table::finalize (CVE-2022-27378) * mariadb: crash in component arg_comparator::compare_real_fixed (CVE-2022-27379) * mariadb: crash at my_decimal::operator= (CVE-2022-27380) * mariadb: crash at Field::set_default via specially crafted SQL statements (CVE-2022-27381) * mariadb: assertion failure via component Item_field::used_tables/update_depend_map_for_order (CVE-2022-27382) * mariadb: use-after-poison in my_strcasecmp_8bit() of ctype-simple.c (CVE-2022-27383) * mariadb: via component Item_subselect::init_expr_cache_tracker (CVE-2022-27384) * mariadb: crash in query_arena::set_query_arena upon SELECT from view (CVE-2022-27386) * mariadb: assertion failures in decimal_bin_size (CVE-2022-27387) * mariadb: crash when using HAVING with NOT EXIST predicate in an equality (CVE-2022-27444) * mariadb: assertion failure in compare_order_elements (CVE-2022-27445) * mariadb: crash when using HAVING with IS NULL predicate in an equality (CVE-2022-27446) * mariadb: use-after-poison in Binary_string::free_buffer (CVE-2022-27447) * mariadb: crash in multi-update and implicit grouping (CVE-2022-27448) * mariadb: assertion failure in sql/item_func.cc (CVE-2022-27449) * mariadb: crash via window function in expression in ORDER BY (CVE-2022-27451) * mariadb: assertion failure in sql/item_cmpfunc.cc (CVE-2022-27452) * mariadb: use-after-free when WHERE has subquery with an outer reference in HAVING (CVE-2022-27455) * mariadb: assertion failure in VDec::VDec at /sql/sql_type.cc (CVE-2022-27456) * mariadb: incorrect key in "dup value" error after long unique (CVE-2022-27457) * mariadb: use-after-poison in Binary_string::free_buffer (CVE-2022-27458) * mariadb: improper locking due to the unreleased lock in extra/mariabackup/ds_compress.cc (CVE-2022-31622) * mariadb: improper locking due to the unreleased lock in extra/mariabackup/ds_compress.cc (CVE-2022-31623) * mariadb: Crash executing query with VIEW, aggregate and subquery (CVE-2021-46659) * mariadb: MariaDB allows an application crash in find_field_in_tables and find_order_in_list via an unused common table expression (CTE) (CVE-2021-46661) * mariadb: MariaDB through 10.5.13 allows a ha_maria::extra application crash via certain SELECT statements (CVE-2021-46663) * mariadb: crash in sub_select_postjoin_aggr for a NULL value of aggr (CVE-2021-46664) * mariadb: crash because of incorrect used_tables expectations (CVE-2021-46665) * mariadb: crash via certain long SELECT DISTINCT statements (CVE-2021-46668) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Bug Fix(es): * Don't use less parallelism if not necessary (BZ#2096934) * Links in galera package description are bad (BZ#2096935) * [Tracker] Rebase to Galera 26.4.11 (BZ#2096936)
Updated packages listed below:
Architecture Package Checksum
aarch64 mariadb-10.5.16-2.module_el8.6.0+3072+3c630e87.aarch64.rpm 29bed3418faa66d0a622c8ed94b7c9c54c688222f67faee80afefe5c81445442
aarch64 mariadb-embedded-devel-10.5.16-2.module_el8.6.0+3072+3c630e87.aarch64.rpm 4df90e7882581bbb36a4c398d1425795ae385eb84b55017046210a10d58af7d9
aarch64 mariadb-errmsg-10.5.16-2.module_el8.6.0+3072+3c630e87.aarch64.rpm 5448d998b910352a900ea11e1346fb8834b8e8db1fc06f093ebd240c0608e8ee
aarch64 mariadb-common-10.5.16-2.module_el8.6.0+3072+3c630e87.aarch64.rpm 646017f783cb7986291b200bf704897023c07a7162298e7940b804aca5197203
aarch64 mariadb-server-galera-10.5.16-2.module_el8.6.0+3072+3c630e87.aarch64.rpm 75d8083c56199b09c0f136d6176db86330673d9803dc47d1ee4a8c8d7aac6805
aarch64 mariadb-backup-10.5.16-2.module_el8.6.0+3072+3c630e87.aarch64.rpm 84372627d1e60a1370ab1c39459baa62c4db22ee9f28797d45a47e1791a1ecc2
aarch64 mariadb-gssapi-server-10.5.16-2.module_el8.6.0+3072+3c630e87.aarch64.rpm 8c9e5fe1b550486df28b4eba08f3255d6874660e3f4f6de7938ec9f5d11cd441
aarch64 mariadb-pam-10.5.16-2.module_el8.6.0+3072+3c630e87.aarch64.rpm 8f29574b0aa6d1841e14c0e9f934c9cb1fd1c7710c839a2d49ea97dce282bf18
aarch64 mariadb-server-utils-10.5.16-2.module_el8.6.0+3072+3c630e87.aarch64.rpm a59ece9430695af61a83479ceae68138ba5c4a3df3a6d43320c8b2b88c515816
aarch64 mariadb-test-10.5.16-2.module_el8.6.0+3072+3c630e87.aarch64.rpm af599770138777159ff2b3d2a54eb7d520a8b8649ca623d227baee8c05ad9d0b
aarch64 mariadb-server-10.5.16-2.module_el8.6.0+3072+3c630e87.aarch64.rpm ba8a69da71bc9bcfcf557b7329936627ab010e091842bc701cbd87f29888a6c5
aarch64 mariadb-oqgraph-engine-10.5.16-2.module_el8.6.0+3072+3c630e87.aarch64.rpm ccabe72ce7e43ca326e5bad2241f26da0e1857e01efd3bd7917659937ab3ce47
aarch64 mariadb-devel-10.5.16-2.module_el8.6.0+3072+3c630e87.aarch64.rpm cefa4ed68071d11d3ee2f38f148ba1dfe7c0c61211e9141cf5274ac128fc3115
aarch64 Judy-1.0.5-18.module_el8.6.0+3072+3c630e87.aarch64.rpm e0c89719ccfe15cb70854634b958d288e851351ea5bba7fb9f7fdd50989c8e8d
aarch64 galera-26.4.11-1.module_el8.6.0+3072+3c630e87.aarch64.rpm f1eae95af5cffa71f274cb4b4d56573f19260a35311a4b0dc3aa83de684429fc
aarch64 mariadb-embedded-10.5.16-2.module_el8.6.0+3072+3c630e87.aarch64.rpm f64892c27e7f1be125e7323869fac7f76f24de385ce1e2af0ea21796c6b04f20
ppc64le mariadb-common-10.5.16-2.module_el8.6.0+3072+3c630e87.ppc64le.rpm 00763f7eb4294f5df46681ee8800b4772e230f325a1a11f2b1af12a0d3e99a3a
ppc64le galera-26.4.11-1.module_el8.6.0+3072+3c630e87.ppc64le.rpm 05a4db97cae0e7272f36879a0e30e6ad2059e003e3b4a45872923dd1432d04f5
ppc64le mariadb-server-10.5.16-2.module_el8.6.0+3072+3c630e87.ppc64le.rpm 07ed8c28861488f7f2ee664a018e0d8ab4a6a61d8ac3bdc75fa3a7ed496d16b5
ppc64le mariadb-errmsg-10.5.16-2.module_el8.6.0+3072+3c630e87.ppc64le.rpm 14d215792a0000b620efc37b09cfc1a086d6c8f9bea2ff672faad6e2db37d85d
ppc64le mariadb-oqgraph-engine-10.5.16-2.module_el8.6.0+3072+3c630e87.ppc64le.rpm 473bd16ae020eb3723da96ff107b963883311946288fe87b2b66b320650d181f
ppc64le mariadb-gssapi-server-10.5.16-2.module_el8.6.0+3072+3c630e87.ppc64le.rpm 5892fe3021fb4baccfa5796b826290e9bc231a4e8fcfe03b69b4f12ab353761b
ppc64le Judy-1.0.5-18.module_el8.6.0+3072+3c630e87.ppc64le.rpm 61e33a89b0b98fba1a137266b47690afb7d6d11b650734648c0855994c5ea423
ppc64le mariadb-backup-10.5.16-2.module_el8.6.0+3072+3c630e87.ppc64le.rpm 6ac4a69a70f231c14a0992950f1e0a52ac5be978a21be508ccd0b56be16dc449
ppc64le mariadb-embedded-devel-10.5.16-2.module_el8.6.0+3072+3c630e87.ppc64le.rpm 7104fec4dbb27731c10592947329d7796c5c91f7bd990dbb8e3ff375602bf32b
ppc64le mariadb-test-10.5.16-2.module_el8.6.0+3072+3c630e87.ppc64le.rpm 9f0542f07c770f6932924eca11617b2599e50df4110e984961a0d77ff2ace297
ppc64le mariadb-server-utils-10.5.16-2.module_el8.6.0+3072+3c630e87.ppc64le.rpm ab6c5ac0d84963c424474ff49d0c87917f583ebebf281102097e012ad438081d
ppc64le mariadb-embedded-10.5.16-2.module_el8.6.0+3072+3c630e87.ppc64le.rpm c162bb4ec4a68d5f17f29a3e9278e6c35ba67031540151d77dfd4bc1c8d19590
ppc64le mariadb-server-galera-10.5.16-2.module_el8.6.0+3072+3c630e87.ppc64le.rpm cb30720cd4d692976e5782195631f77da17e0d45052ddcc9619f9ff5798f2e64
ppc64le mariadb-devel-10.5.16-2.module_el8.6.0+3072+3c630e87.ppc64le.rpm d5c3afef1ae468b161e32b10728e42b038d588f007a6531fb7f145c7948e97c3
ppc64le mariadb-pam-10.5.16-2.module_el8.6.0+3072+3c630e87.ppc64le.rpm dae183a2bbe0d079a9a5f4b102c8f451775763c1c1cb7d52410d39cc7baadf4e
ppc64le mariadb-10.5.16-2.module_el8.6.0+3072+3c630e87.ppc64le.rpm ee56db5cf083d126a54b3463bee7a61594baaf5ce15ca476502cff04ee85ac6a
x86_64 mariadb-oqgraph-engine-10.5.16-2.module_el8.6.0+3072+3c630e87.x86_64.rpm 0181062dc80da42a7eb880ddbdde8b0279dae796fe68ed7d86ca6cb7998bfc86
x86_64 mariadb-backup-10.5.16-2.module_el8.6.0+3072+3c630e87.x86_64.rpm 1f699416aa8904b1e4c276edf4c69e6c9cacff0bc9f58c1e3e58e13d48b8b4e3
x86_64 mariadb-server-10.5.16-2.module_el8.6.0+3072+3c630e87.x86_64.rpm 445657bbcac758892ed309e5514ceab82b291d1facf1976c66753a3be6cbd452
x86_64 galera-26.4.11-1.module_el8.6.0+3072+3c630e87.x86_64.rpm 4f709c3e932a821cdb24b2ea491f92ae07be3dc675dbcc548a973bd53dba68a2
x86_64 mariadb-server-utils-10.5.16-2.module_el8.6.0+3072+3c630e87.x86_64.rpm 502bfcd0b243069146869afe0bd493a4efc4efdc81d177bfbc6aa9b57f224fe9
x86_64 mariadb-embedded-10.5.16-2.module_el8.6.0+3072+3c630e87.x86_64.rpm 676cd6b14b5b14ef78707ab21ce24b44c2fb56e7ba779be36fb45f19dc86aaf1
x86_64 mariadb-common-10.5.16-2.module_el8.6.0+3072+3c630e87.x86_64.rpm 8d3d5019536effa38ada76ad7e48104f011d489013cb0ba15e241e83116be196
x86_64 Judy-1.0.5-18.module_el8.6.0+3072+3c630e87.x86_64.rpm ad0644e015a6d87a82c891ce0a1bb5ac32419e5f3ef2abbd72fc2b2d1e7a90f7
x86_64 mariadb-test-10.5.16-2.module_el8.6.0+3072+3c630e87.x86_64.rpm affd5fec55b4fbd7c38b421c73e942b7f342c093307630f3ee4ce64ed62286a0
x86_64 mariadb-errmsg-10.5.16-2.module_el8.6.0+3072+3c630e87.x86_64.rpm b4aa809c8cd6e4815dcbf0647247f90a81da14ba097eb93f8e44d40874c6b198
x86_64 mariadb-10.5.16-2.module_el8.6.0+3072+3c630e87.x86_64.rpm c0c7dbb62e6f301ff4c6690171589fc5cb7f912f2c87c877ea4e6cff9f7f4df1
x86_64 mariadb-embedded-devel-10.5.16-2.module_el8.6.0+3072+3c630e87.x86_64.rpm c38ecbff1ba3a54abb422e402afb03b3d011369c87096068bdfb3c3e25908a13
x86_64 mariadb-gssapi-server-10.5.16-2.module_el8.6.0+3072+3c630e87.x86_64.rpm c622696d4d13ae56aba43b84579a5025f425e504c888bd431d392e9f13134816
x86_64 mariadb-devel-10.5.16-2.module_el8.6.0+3072+3c630e87.x86_64.rpm d5cd24b9bbd468952250fb8ea998d83c5a821669296023eac3cc2e9b6b0133b9
x86_64 mariadb-pam-10.5.16-2.module_el8.6.0+3072+3c630e87.x86_64.rpm f2dc246c77da94477b5312eecc350aef844f00e2123108513d2a8d4de0488afc
x86_64 mariadb-server-galera-10.5.16-2.module_el8.6.0+3072+3c630e87.x86_64.rpm f9e93856aaf569fa08b3ea649b7bb7b09caba361bed33f26e5cee0ec05233175
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.